Skip to content

Run a rootkit scan and review history

In cPFence v4+, Threat & Malware Detection → Rootkit Scans shows retained system-check results. Findings are advisory; a rootkit check does not automatically remove suspicious software. Support users need target-server access and history/finding permissions; starting a check also needs scan permission.

  1. Open Rootkit Scans and choose Local or one secondary server in server scope.
  2. Read the latest check’s status and message, then choose Summary period: Last month, Last week, Last 24 hours or All time.
  3. Review Completed, Findings and Incomplete. Filter Recent rootkit scans by Status and Started since, then Apply filters; Clear all resets the filters.
  4. Use Previous and Next, then open Details for the intended check.

Select a summary card to filter the records; select it again to clear that card’s filter. Incomplete includes interrupted checks.

Rootkit Scans showing an Interrupted latest check, period totals, status and date filters, and retained scan history.

The retained latest check is Interrupted; it has not established a completed clean result. Identifying values are concealed. Select the image for full size; use browser Back to return.

Status choices include Completed, No findings, Findings, Incomplete, Running and Interrupted. In details, inspect Status, Server, Started, Finished, Duration, Findings and any Recorded problem.

Only findings eligible for cPFence alerts are shown. A Running or Interrupted check has not established a completed clean result.

Rootkit scan details showing Interrupted status, zero findings and a recorded interruption problem.

An interrupted check with zero findings is not an all-clear. Identifying values are concealed; this is a retained result. Select the image for full size; use browser Back to return.

Starting a check needs a connected target with an eligible license. See the shared scan prerequisites and server scope.

  1. Choose the intended server and select Run rootkit scan.
  2. In Confirm rootkit scan, review Selected server, Action and options and Target servers. If the target changed, refresh and review it again.

Confirm rootkit scan with one selected server and the advisory rootkit-check action.

This action runs only the rootkit check and leaves automatic monitoring settings unchanged. Identifying values are concealed; the review was cancelled without running a check. Select the image for full size; use browser Back to return.
  1. Choose Cancel to leave without starting, or Run rootkit scan to submit the check.
  2. Read the output. After the request finishes, refresh Rootkit Scans and open the recorded result.

This runs only the rootkit check on the selected server. It does not change automatic monitoring settings. Use daily rootkit and IP reputation settings to configure scheduling or inspect service output.

Use Copy output for a private record, Cancel to request cancellation, then Back and Refresh to check retained history; cancellation alone does not establish the final check status. Finished describes the request, not a guarantee of a clean server. For Needs attention or interruption, inspect the recorded problem before retrying. Investigate advisory findings before deleting software or changing access. Use malware scans for a separate website malware investigation.