Malware on hosting rarely announces itself. The site may look normal to visitors while hidden web shells or backdoors send spam, steal data, or await commands from hackers. cPGuard Malware Scanner is the system AsiaGB runs on every server to automatically detect and remove these threats.
cPGuard combines two methods: Signature-based scanning (known malware pattern database) and an AI Scanner (machine learning that spots abnormal code patterns) — catching both known and previously unseen malware.
Types of malware cPGuard detects
- PHP Web Shells — PHP files that give hackers remote command execution, often disguised as image files or named like system files
- Backdoors — hidden code that preserves access even after password changes
- Malicious Injections — dangerous code injected into legitimate PHP or JS files, such as redirect scripts in header.php
- Symlink Attacks — symbolic links used to read files across hosting accounts
- Cryptominers — scripts that use server CPU to mine cryptocurrency without the owner's knowledge
- Phishing Pages — fake bank or service pages uploaded without authorisation
How cPGuard scans
1. Signature-Based Detection
Compares files against a database of millions of known malware patterns, updated automatically from the cloud. Highly effective against known malware families.
2. AI Scanner (Machine Learning)
Uses machine learning models to analyse code structure and behaviour — detecting malware that has never been seen before or that has been obfuscated to evade signatures.
3. Real-time File Monitoring
Monitors file changes in real time, alerting immediately when files are created, modified, or deleted in suspicious locations — especially new PHP files appearing in directories that shouldn't have them.
Auto-Cleanup process
- Auto-Clean Injection — removes malicious code from a file while preserving legitimate content
- Restore CMS Core — for modified WordPress, Joomla or OpenCart core files, cPGuard downloads the clean original from the official CDN and replaces the infected file
- Quarantine — moves suspicious files out of the web root for review before deletion
- Alert Only — notifies admin without removing, allowing manual review first
Note: Auto-Cleanup helps significantly, but for heavily infected sites always restore from a clean backup as well — some malware places payloads in multiple locations simultaneously.
Database Scanner for WordPress
Beyond file scanning, cPGuard includes a Database Scanner that inspects MySQL tables directly — critical for WordPress, since many malware types inject into the database rather than editing PHP files: spam links in post content, redirect scripts in wp_options, malicious JS in widgets, or hidden admin accounts in wp_users.
Reports and alerts
cPGuard sends a daily security report to admin email summarising scan results, files found, and cleanup status. Immediate alerts fire when malware requiring urgent action is detected — so you never miss a critical event even without logging into the panel.
Frequently Asked Questions
How often does cPGuard Malware Scanner run?
Scans run automatically daily and weekly on a schedule. There is also real-time file monitoring (File Watch) that alerts immediately when a file is modified or created in a suspicious location.
How does Auto-Cleanup work?
cPGuard attempts to remove malicious code from infected files without deleting the entire file. For CMS core files (WordPress, Joomla, OpenCart), cPGuard downloads a clean original from CDN and replaces the infected file.
Does the malware scanner impact server CPU?
Impact is minimal. cPGuard is designed for low resource consumption; scans are scheduled during low-load periods and the signature database updates from the cloud without heavy downloads on the server.
Can cPGuard clean an already-infected site?
Yes in many cases — for file injections and CMS core files, cPGuard handles auto-cleanup. Some deep or complex malware may require support intervention. Always restore from a clean backup alongside any cleanup.
Can cPGuard scan the WordPress database?
Yes — a separate Database Scanner module detects malicious code injected into MySQL tables, such as spam link injections or redirect scripts in wp_options.
AsiaGB Hosting Scans for Malware with cPGuard Daily
AsiaGB runs cPGuard Malware Scanner on every server, scanning automatically and alerting you when suspicious files are found — on SSD from 500 THB/year.
See Hosting Plans