Arsal • Location • Starter

How to Fix Website Malware Redirects in cPanel

Client Problem: The website automatically redirects visitors to unauthorized spam or malware sites, or displays a security warning.

Cause: Compromised files, weak credentials, or vulnerable plugins have injected malicious rewrite rules, scripts, or altered database URLs.

Technical Solution Steps:

  1. Log in to cPanel: Access your cPanel account using your credentials.

  2. Clean .htaccess:  Go to the files section then Open File Manager > public_html, edit .htaccess, and delete unauthorized RewriteRule commands.


  3. Clean Injected Files: Edit index.php and theme files (header.php, functions.php) to remove obfuscated code or eval() functions.


  4. Fix Database URLs: Go to the databases section then Open phpMyAdmin then select your database then go to the > wp_options table and reset siteurl and home to your original domain.


  5. Scan and Reset: Run Imunify360 / Virus Scanner to remove backdoors and reset all account passwords.

    To perform a quick and free online malware scan on your website, visit
    Free Website malware scanner