Act quickly to limit damage. First, change every password: cPanel, FTP, email, database, and any CMS admin accounts from your client area and cPanel.
- Run a scan with Imunify360 in cPanel to detect and clean infected files.
- Update your CMS, themes, and plugins to the latest versions, and remove anything unused.
- Restore from a clean backup if you have one from before the infection.
- Check for unknown admin users, scheduled cron jobs, and modified
.htaccessfiles.
If you can't fully clean it or aren't sure, open a ticket right away and describe what you've seen. Our team can scan your account, isolate malicious files, and advise on next steps. After cleanup, keep everything patched to prevent reinfection.