Skip to content

Resolve a malware finding

Use Threat & Malware Detection in cPFence v4+ to resolve a recorded malware finding. Support users need access to the server and scan history, plus permission for each file action. A finding does not mean its file was quarantined successfully.

  1. Choose the affected server in Server scope, then open Scan Summary.
  2. Find the scan in Recent scans and open Details.
  3. Check the file’s Path, Signature, and Action. Compare its original path with the affected website before changing anything.
  4. Choose an available action for that row. Controls depend on the finding’s state and your permissions.
Action What it does
Quarantine Moves the detected file into quarantine, retaining bytes for supported recovery.
Delete Permanently removes the detected file without quarantine recovery.
Restore Returns stored quarantine bytes to the original path.
Trust exact file Suppresses future detections at the restored file’s exact path.
  1. Choose Quarantine or Delete on the intended finding.
  2. Read the confirmation’s path and server.
  3. Choose Confirm quarantine or Delete permanently, or Cancel to leave the file unchanged.
  4. Read the per-file result and refresh the scan record. Confirm the site’s normal operation afterward.

An error or interrupted action is not proof that the file stayed unchanged. Inspect the recorded result and current file state before using Retry quarantine or Retry delete. A changed file at the original path requires a fresh review.

Follow identify and restore quarantined files to preview stored content and check its original path. An existing destination or missing payload can prevent recovery.

Quarantine list showing search, original-path and status columns and Preview controls for stored files.

Use the quarantine list to identify stored content before recovery. Identifying values and paths are blurred. Select the image for full size; use browser Back to return.

Restore without trust can leave Restored — action required. If you later verify that content is clean, use Trust exact file on the finding and read its confirmation. Remove an unnecessary exception through the exclusion controls.

4. Record a file already removed outside cPFence

Section titled “4. Record a file already removed outside cPFence”

If the action reports that the detected file is no longer present and offers Mark fixed, first verify your external remediation. Choose Mark fixed and read the confirmation: the server checks that the file is still absent and preserves scan history.

Mark fixed records resolution; it does not clean a file or establish that the entire website is safe. If the check fails, inspect the reported condition rather than retrying blindly. Run an appropriate follow-up scan after remediation.