Skip to content
UK web hosting, domain names, email, website security and online services.

Review Imunify360 malware quarantine and false positives Print

  • security, hosting, malware, imunify360
  • 0

Understand why a file was detected before restoring it, and never restore a file merely because the website currently needs it.

Applies to: Website security, malware and Imunify360

A clean malware scan does not prove an application is secure. Effective recovery combines containment, credential rotation, patching, file and database review, and monitoring for reinfection.

Before you start

  • Sign in to the Customer Portal and open the affected hosting service.
  • Take a current backup before changing website files, databases, DNS or application configuration.

Work through these checks

  1. Open the Imunify360 malware view and record the file path, detection name, first-seen time and action taken.
  2. Compare the file with a trusted release or known-good backup and inspect surrounding recent changes.
  3. Determine whether the file is generated, customised, abandoned or part of a compromised application.
  4. For a genuine infection, replace it with a clean package and investigate users, credentials and persistence rather than restoring the quarantined copy.
  5. For a suspected false positive, preserve the file securely and submit the required evidence through support or the security tool’s review process.
  6. Restore only after a false-positive decision or verified clean replacement, then run a complete scan and test the application.
  7. Monitor for the same signature or file path returning, which can indicate an unresolved backdoor or deployment source.

Confirm the result

  • The affected site is patched, credentials are rotated and no unauthorised file, user, scheduled task or redirect remains.
  • A fresh scan and follow-up monitoring show no immediate reinfection while the website continues to function normally.

Common problems

SymptomLikely causeWhat to do
Malware reappears after files are cleaned.A vulnerable application, stolen credential, malicious database entry or scheduled task remains.Contain the site, patch all code, rotate every related credential and inspect users, cron, database and access logs before restoring traffic.
A legitimate file is quarantined.The scanner detected a suspicious pattern or an obfuscated component that requires review.Do not restore it blindly; compare it with a trusted vendor copy and submit the file path and detection name for false-positive review.

When to contact Tudor Internet

Open a ticket through the Customer Portal when the checks above do not resolve the issue, when an action is unavailable for your service, or when continuing could risk data loss or service interruption. Include the following so the request can be investigated efficiently:

  • The affected domain and SiteWorx account
  • The exact error text and time
  • The last change made
  • Relevant log lines with passwords and personal data removed
Do not send passwords, private keys, full payment-card details, one-time authentication codes or unredacted identity documents in an ordinary support reply.

Related articles

Last reviewed: 2026-07-18.


Was this answer helpful?

« Back