Problem Description
- You receive an email indicating Imunify has detected malware
- You see an alert in Plesk indicating Imunify has detected malware, or under Imunify in Plesk you see found malware
Problem Resolution
If you have our Managed Troubleshooting or Hands-On Support level, you can have us take a look at this to determine the cause, and with Hands-On Support we'll resolve anything related to this alert. Simply open a ticket!
If you have our DIY support level or wish to troubleshoot it yourself, read on.
As great as our security solutions are, they're not infallible - false positive do occur wherein something is identified as a problem that truly is not. In order to determine if the file Imunify is concerned about is legitimately a problem, you must open the file that is in question and see if it looks to have been modified or contains sketchy looking code. If you see anything unusual, your best bet is to replace the file with the core file from a fresh download of the software, when possible.
If the file is the same as a core file from the plugin or theme, or WordPress itself, please let us know so we can report it to Imunify devs as a false positive.
Known false positive: if you see a file named something like wp-content/deleteme.3ac60781344f4e41adf14972b5b436b5.php - specifically it says 'deleteme' in the name and it ends with .php, this has been created by our 1-click web apps utility in order to automatically log you into the site. It is supposed to automatically remove those files, however if it has trouble accessing your site, it may be unable to do so. Imunify will see that as a malicious file as it is indeed designed to create a backdoor into your website. Even though it's sanctioned, it's not a bad idea for Imunify to remove them when found, and so we do not exempt the files from its scanner.