All Products
Search
Document Center

Security Center:Virus detection and removal

Last Updated:Jul 15, 2026

When servers are attacked by ransomware, cryptomining programs, or other malicious software, your business operations may be disrupted and data faces the risk of loss. The virus detection and removal feature helps you quickly discover and remove various malicious threats through deep scanning and precise cleanup, so you can restore normal operations.

Overview

The virus detection and removal feature integrates Alibaba Cloud's machine learning detection engine and a real-time virus signature database. It scans persistent startup items, active processes, kernel modules, and sensitive directories to detect and locate virus file paths, effectively identifying and handling various threats.

Core capabilities

  • Detection scope: Covers key scan items such as processes, startup items, scheduled tasks, and sensitive directories.

  • Handling methods: Supports automatic quarantine, deep scan and removal, whitelist management, and other remediation actions.

  • Scan methods: Supports immediate scan and periodic scan.

Use cases

  • Regular security checks: Perform scheduled security inspections and threat cleanup.

  • Emergency response: Rapid response and forensics after a security incident.

  • Compliance hardening: Meet compliance audit requirements and strengthen system security.

Supported virus types and scan items

  • Virus types: Ransomware, cryptomining programs, DDoS trojans, trojans, backdoors, malicious programs, high-risk programs, worms, suspicious programs, and self-mutating trojans.

  • Scan items: Active processes, hidden processes, Docker processes, kernel modules, installed programs, dynamic library hijacking, services, scheduled tasks, startup items, and sensitive directories.

Applicable scope

  • Subscription: Anti-virus, Advanced, Enterprise, or Ultimate (If your current edition does not support this feature, upgrade).

    Note

    The protection edition of the server must be set to the edition you purchased. For more information, see Bind a server protection edition.

  • Pay-as-you-go: Host and Container Security pay-as-you-go is activated (If not activated, purchase).

    Note

    The server protection level must be set to Antivirus, Host Protection, or Host and Container Security. For more information, see Bind a server protection level.

Scan for viruses

Virus scanning supports two methods: immediate scan and periodic scan.

  1. Log on to the console

    Log on to the Security Center console. In the left-side navigation pane, choose Protection Configuration > Host Protection > Virus Detection and Removal. In the upper-left corner of the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.

  2. Service authorization

    If you use this feature for the first time, the system may prompt you to authorize a service-linked role for Security Center. Click Authorize Now and follow the instructions.

    Note

    After authorization, Security Center automatically creates the AliyunServiceRoleForSas service-linked role. For more information, see service-linked roles for Security Center.

    Important

    Authorize an engineer to troubleshoot on your server: If you cannot access a computer to perform the operation, you can purchase an emergency response service so that an Alibaba Cloud security engineer can assist you remotely. High-risk operations (such as deep scan and removal) require a snapshot backup before authorization. Operations are not allowed without a snapshot. If you do not know the server password, you can reset the instance password in the ECS console. Note that the engineer cannot create a snapshot on your behalf; you must create the snapshot yourself before submitting the authorization.

  3. Select a scan method

    • Scan Now: Click Scan Now or Scan Again for temporary or urgent scan tasks.

    • Periodic Scan: Click Scan Settings in the upper-right corner to configure an automated scan policy for routine inspections.

  4. Configure parameters

    Configure the scan parameters as described in the following table, and then click OK or Next to start the task.

    Parameter

    Description

    Scan Cycle

    Configure the execution interval and time window for periodic scans. This parameter applies only to Scheduled Scan tasks.

    Scan Mode

    Specify the detection scope for the scan task.

    • Quick Scan: Automatically detects active processes, startup items, sensitive directories, and other high-risk items. This usually takes about 10 minutes, depending on server performance and the number of files.

    • Custom Directory Scan: Scans specified directories. Enter multiple absolute paths, with each path on a new line. Custom directory scans or full-asset scans take significantly longer, depending on the scan scope and file count.

      Important
      • A single task scans up to 30,000 files. Exceeding this limit may cause a timeout or result in some files not being scanned.

      • The maximum size for a single file is 10 MB.

    Memory Check

    Detects malicious code in memory-resident files and hidden processes.

    Note

    This feature increases resource consumption and scan time. We recommend enabling it during off-peak hours or when you suspect advanced threats.

    Scan Scope

    Specify the target assets to scan.

    • All Assets: Scans all servers that meet the edition requirements.

    • By Asset: Specify individual assets.

    • By Group: Scans all assets in the selected group. New assets added to the group are automatically included.

    • By VPC: Scans all assets in the selected VPC. New assets added to the VPC are automatically included.

  5. View task progress

    (Optional) Virus Detection and Removal page, in the upper-right corner, click Task Management to view the status and progress of your scan tasks.

    If the task status remains unchanged for an extended period, this is normal (scan duration depends on the number of servers and file scale). Wait for the scan to complete. Do not repeatedly click Immediate Scan to start a new task.

Handle virus alerts

After a scan completes, handle detected virus alerts promptly to ensure server security.

Important
  • Alerts from this feature sync bidirectionally with the Security Alert module. Handle alerts in either module.

  • The virus detection and removal feature is used only to detect and clean malicious files. After virus removal, if no risks are confirmed, it generally does not trigger a ban. If you still experience access issues after removal, we recommend checking security group rules, internal server firewalls, and other potential causes.

Pre-remediation checklist

Before choosing a response method, log on to the server to verify the suspicious file and assess the potential impact on your services.

  1. Confirm file information: Check the file path, signature, and hash to verify whether it is malicious. This prevents accidental removal of critical files.

  2. Check processes and ownership: Determine whether the file is used by critical services such as nginx or mysql.

  3. Assess business impact: Confirm whether the file is part of a business application and whether removing it will affect running services.

Choose a handling method

In the alert list, find the target alert and click Handle to select an action based on your assessment. Click the arrow to the left of an alert to view details such as the virus file path.

The expanded details also include Malicious File MD5 and Process ID.

Handling method

Use case

Deep Cleanup

The file is confirmed malicious, especially persistent threats like ransomware or cryptomining programs.

Add to Whitelist

The alert is a confirmed false positive that you want to suppress permanently.

Warning

No new alerts are generated for whitelisted items. Use with caution.

Ignore

The alert is a confirmed false positive or acceptable risk, such as authorized penetration testing or maintenance window activity.

Manually Handled

You already removed the threat manually.

Deep Cleanup (Recommended)

Deep Cleanup is a specialized remediation capability developed by the Security Center security team after in-depth analysis and testing of persistent, stubborn viruses.

  • Process:

    • Kill malicious processes: Terminates running malicious processes.

    • Quarantine malicious files: Moves virus files to quarantine. To restore or download quarantined files, see Manage quarantined files.

    • Remove persistence mechanisms: Analyzes and removes persistence methods such as cron jobs and malicious download sources. AI-enhanced to continuously improve detection.

  • Result:

    • Status update: The alert status changes to "Resolved".

    • Create snapshot: If you select Automatically Create Snapshot and Fix Risk, a snapshot of the server's system disk is created as a data backup.

      • Creating and retaining snapshots incurs fees from the snapshot service (pay-as-you-go by default). For pricing details, see Snapshot billing or contact your sales manager.

      • If you select Skip Snapshot and Fix, you risk service interruptions if business-critical files are accidentally deleted. You cannot restore them from a snapshot.

      • After deep scan and removal, if Security Center confirms the virus is eliminated (for example, no cryptomining activity or malicious processes are detected), the system automatically updates the alert status or cancels related active alerts. We recommend continuing to monitor the server after cleanup to confirm the threat does not recur.

Add to Whitelist

  • Result:

    • Status update: The current alert's status is updated to "Whitelisted".

    • Subsequent impact: If the same type of alert occurs again, the system does not generate a new alert. Instead, it updates the last occurrence time.

      What is a "same type of alert"?

      A "same type of alert" refers to a threat with highly consistent characteristics. Examples:

      • Virus alerts: Same asset, same virus file path, and same virus file MD5.

      • Unusual logons: Same asset and same logon IP address.

  • Risk notice:

    Whitelisting removes the file from security monitoring. Use with caution. To remove a whitelist entry, see How do I remove an item from a whitelist?.

Ignore

  • Result:

    • Status update: The current alert's status is updated to "Ignored".

    • Subsequent impact: Does not affect future detection. If the same threat reappears, a new alert is generated.

  • Risk notice:

    • "Ignore" is an alert status management action and does not resolve the underlying security issue.

    • Only ignore an alert after confirming it is a false positive or accepting the associated risk, to avoid missing real attacks.

Manually Handled

  • Result:

    • Status update: The current alert's status is updated to "Handled".

    • Subsequent impact: Does not affect future detection. If the threat persists, new alerts may be generated.

  • Risk notice:

    • "Manually Handled" is an alert management action that you can use to close a security event.

    • Complete all remediation and hardening before using this action. Otherwise, the threat may recur.

Manage quarantined files

To restore or download malicious files quarantined by Deep Cleanup, note that they are retained for up to 30 days. After this period, the system automatically deletes them.

  1. On the Virus Detection and Removal page, click Quarantined Files in the upper-right corner.

  2. Find the target file and click Restore or Download in the Actions column.

    • Restore: Returns the file to its original path. Use only if the file was quarantined by mistake.

    • Download: Downloads the file to your local computer for further analysis.

Apply in production

Enable alert notifications

Configure alert notifications on the System Settings > Notification Settings page to notify responsible personnel by email, SMS, or DingTalk when high-risk threats are detected. For more information, see Notification Settings.

In the Security Alerts notification configuration area, complete the following settings:

  • Notification Time: Select 24 Hours or 8:00 - 20:00.

  • Alert Severity: Select Urgent, Suspicious, or Reminder as needed.

  • Notification Method: Select SMS, Email, or Internal Message as needed.

Performance optimization and incident response

  • Performance optimization:

    • For low-specification servers (for example, 1-core CPU and 1 GB of memory), run a Quick Scan during off-peak hours and disable Memory Check to reduce resource consumption.

    • For large-scale scans, run in batches or exclude large log and backup directories in Scan Settings to reduce scan time.

  • Emergency response process:

    1. Immediate isolation: After detecting a high-risk threat, use security group rules to block abnormal ports or restrict access to only your office IP to prevent attackers from continuing to control the server.

    2. Forensics backup: Create a snapshot for the server and back up key logs such as /var/log/secure and /var/log/cron.

    3. Deep scan and removal: Use the Deep Scan and Removal feature in Security Center to remove malicious processes, webshells, and persistence mechanisms, including Crontab scheduled tasks, SSH public keys ~/.ssh/authorized_keys, and dynamic library hijacking.

    4. Vulnerability remediation: Scan and fix system and application vulnerabilities. Change all weak passwords to strong passwords.

    5. Security hardening: Enable Malicious Host Behavior Prevention for proactive interception (see Malicious Host Behavior Prevention for details). Restrict remote logon IPs and open only necessary ports.

    6. Continuous monitoring: Continuously monitor the server status to confirm that the threat does not recur.

  • Root cause remediation:

    If the server is repeatedly infected or the virus has penetrated deep into the system, take the following measures:

    • Back up your business data and then reset the system disk. In the ECS console, find the corresponding instance and select Initialize Disk from All Operations (the instance must be stopped).

    • Before redeploying your business, complete security hardening first (change passwords, close unnecessary ports, and install the latest patches).

    • Create regular snapshot backups for quick recovery if the system is compromised.

Security hardening recommendations

To protect your servers from future attacks, implement the following hardening measures to increase the difficulty for attackers.

  • Enable Malicious Host Behavior Prevention

    Enable this feature on the Protection Configuration > Host Protection > Malicious Host Behavior Prevention page. It proactively blocks malicious behaviors of common viruses including trojans, ransomware, cryptomining programs, and DDoS trojans. For more information, see Malicious Host Behavior Prevention.

  • Server security hardening

    • Upgrade Security Center Edition: The Enterprise and Ultimate editions support the virus automatic isolation (i.e., automatic virus detection and removal) feature, providing you with precise defense capabilities and supporting more security detection items.

    • Tighten Access Control: Open only necessary business ports (such as 80 and 443), and configure strict IP whitelist access policies for management ports (such as 22 and 3389) and database ports (such as 3306).

      Note

      For Alibaba Cloud ECS servers, see Manage security groups for operations.

    • Set Complex Server Passwords: Set complex passwords containing uppercase letters, lowercase letters, numbers, and special symbols for servers and applications.

    • Upgrade Software: Promptly update your application software to the latest official version to avoid using outdated versions that are no longer maintained or have known security vulnerabilities.

    • Regular Backups: Create a regular snapshot policy for important data and server system disks.

      Note

      For Alibaba Cloud ECS servers, see Create policy for operations.

    • Fix Vulnerabilities Promptly: Regularly use the Security Center Vulnerability Management feature to promptly patch system and application vulnerabilities.

    • Reset Server System (Use with Caution).

      If the virus intrusion is deep and involves underlying system components, it is strongly recommended that you reset the server system after backing up important data. Follow these steps:

      1. Create a snapshot to back up important data on the server. For more information, see Manually create a single snapshot.

      2. Initialize the server operating system. For more information, see Re-initialize system disk (reset OS).

      3. Create a cloud disk from the snapshot. For more information, see Create a data disk from a snapshot.

      4. Attach the cloud disk to the server after reinstalling the system. For more information, see Attach a data disk.

  • Emergency response for SSH weak password intrusion

    If your server is intruded due to an SSH weak password, we recommend that you immediately perform the following actions:

    1. Change the password: Immediately change the root password to a complex password that includes uppercase and lowercase letters, numbers, and special characters. Change it regularly.

    2. Check for backdoors: Check for abnormal processes, unknown accounts, suspicious scheduled tasks, and SSH public keys. Remove any traces of intrusion.

    3. Block the attacker: Block the attacker's source IP in the security group. Restrict SSH and remote desktop access to trusted IPs only.

    4. Complete cleanup: If you cannot confirm the scope of the intrusion, we recommend backing up your business data, initializing the system disk, and redeploying your business. In the ECS console, find the corresponding instance, click the instance name, and select Initialize Disk from All Operations in the upper-right corner (the instance must be stopped).

Quotas and limits

  • Protection capability limits

    • No real-time protection: Does not support automatic detection and blocking of threats when files are created, modified, accessed, or executed. If you need proactive defense, enable "Host Protection Settings".

    • No virus tracing: Does not support tracing the exact source of a virus (for example, the third-party software that introduced the virus). We recommend using the attack tracing feature of Security Alert for investigation.

  • Full-disk scan limits: By default, scanning focuses on high-risk areas only. Full-disk scanning of all files on a server is not supported. If you need full-disk scanning, enable Agentless detection.

  • Custom directory scan limits

    • File count limit: A single task scans up to 30,000 files. Exceeding this limit may cause a timeout or result in some files not being scanned.

    • File size limit: The maximum size for a single file is 10 MB.

    • Execution time limit: A single task times out after 2 hours by default. Files that exceed this limit are skipped.

Tutorials

FAQ

Whitelist and ignore questions

  • How do I remove an item from a whitelist?

    The Virus detection and removal module does not support removing whitelist items. Navigate to Detection and Response > Alert, find the handled alert, and remove it from the whitelist. For more information, see Remove an alert from the whitelist.

    Note

    If you purchased the Agentic SOC service, choose Agentic SOC > Alert.

  • What is the difference between adding to a whitelist and ignoring an alert?

    Comparison item

    Add to Whitelist

    Ignore

    Use case

    Confirmed false positive, and you want to permanently stop receiving these alerts.

    Temporary or sporadic false positive, or a known and acceptable risk.

    Impact scope

    Alerts with matching characteristics (same asset + same file path + same MD5) are no longer generated. Only the last occurrence time is updated.

    Applies only to the current alert. If the same threat reappears, a new alert is generated.

    Reversible

    You can cancel the whitelist entry in the handled list under Detection and Response > Alert.

    No reversal needed. Ignoring an alert does not affect future detection; the system continues to monitor for the same threat.

Virus detection and alert handling questions

  • What is the difference between Virus detection and removal and Security Alert?

    • Virus detection and removal is a feature module focused on detecting and removing malicious files, providing deep scanning and specialized remediation capabilities.

    • Security Alert is a unified alert center that consolidates all security events, including viruses, unusual logons, network attacks, and vulnerabilities.

    Important
    • Alerts from this feature sync bidirectionally with the Security Alert module. Handle alerts in either module.

    • The virus detection and removal feature is used only to detect and clean malicious files. After virus removal, if no risks are confirmed, it generally does not trigger a ban. If you still experience access issues after removal, we recommend checking security group rules, internal server firewalls, and other potential causes.

  • Why do viruses reappear after remediation?

    Common causes:

    • The root cause is not resolved: Weak passwords or unpatched vulnerabilities allow attackers to regain access.

    • Incomplete cleanup: Hidden backdoors or persistence mechanisms were not fully removed.

    • Contaminated data source: Data restored from an infected backup or image.

    Solution:

    • Follow the security hardening recommendations to strengthen your security posture.

    • After remediation, restart the server and its applications to terminate malicious processes lingering in memory.

      Warning
      • Restarting a server causes a brief service interruption. Websites, applications, and dependent services become inaccessible. Perform this operation during off-peak hours.

      • Some applications may require a manual restart if they are not configured for auto-start or depend on specific environment variables. Evaluate the restart plan in advance, especially for services such as message queues.

  • How do I handle multiple alerts at a time?

    • Virus alerts generated by the Protection Configuration > Host Protection > Virus Detection and Removal module support batch handling.

      1. On the Virus detection and removal page, select the alerts that you want to handle by clicking the checkbox on the left.

      2. In the lower-left corner, click the Batch Handle button and select an appropriate response method.

    • The Detection and Response > Alert module supports batch whitelisting and batch ignoring.

      1. On the Security Alert page, select the alerts that you want to handle by clicking the checkbox on the left.

      2. In the lower-left corner, click Ignore Once or Add to Whitelist.

  • What do I do if an alert indicates that a file does not exist?

    The virus may have been removed by another method or deleted its own traces. Click "Ignore" or "Manually Handled" to dismiss the alert.

  • Why do virus alerts continue to be sent after the virus is removed?

    Security Center retains historical threat records (retention period is about 1 year). Even if the virus file has been cleared, the historical alert records remain. If you do not perform actions such as "Ignore" or "Manually Handled" on the alerts, the system may continue to send notifications.

    Solution:

    • After confirming the virus is cleared, perform Ignore or Manually Handled on the relevant alerts in the alert list.

    • If you still receive abnormal logon alerts for an old IP after changing the public IP, confirm that the alert time is before the IP change. You can safely ignore it and synchronize the latest asset information.

  • Why do old alerts still appear after I reinstall the operating system?

    After you reinstall the operating system, Security Center may retain previous scan results and alert records. To obtain the latest security status and clear old alerts, manually trigger a scan by clicking Immediate Scan or Rescan. After the scan is complete, the system updates detection results based on the new system environment. Old inactive alerts are cleaned up or their status is updated.

  • How do I troubleshoot a persistent backdoor (virus keeps reappearing or cannot be removed)?

    If a virus keeps reappearing or cannot be completely removed, a persistent backdoor may exist. We recommend checking the following items one by one:

    • Scheduled tasks: Check crontab (Linux) or Task Scheduler (Windows) to confirm whether any suspicious scheduled tasks exist.

    • Startup items: Check startup items (Linux: /etc/init.d/, systemd services; Windows: registry startup items) to confirm whether any suspicious programs exist.

    • SSH public keys: Check the ~/.ssh/authorized_keys file to confirm whether any unknown SSH public keys exist.

    • Hidden files: Some virus files may be located in hidden system directories (for example, the Windows Recycle Bin $Recycle.Bin directory). To view them, enable the display of hidden files and system files as an administrator. The Security Center agent scans at a low level to obtain file paths and is not restricted by file system visibility.

  • Does virus detection and removal support the Alibaba Cloud app on mobile devices?

    No. The virus detection and removal and security alert handling features are available only through the Security Center web console. The Alibaba Cloud mobile app does not support virus detection, removal, or alert handling.

Scan and task execution questions

  • What do I do if a scan task fails or times out?

    • Task timeout: Usually caused by a custom scan directory that is too large. Solutions:

      • Split large scans into multiple Custom Directory Scan tasks targeting high-risk directories such as /tmp, /var/tmp, and /root.

      • Exclude large log or data directories in the scan configuration.

      • Run scans during off-peak hours.

    • Task failure:

      1. Check agent status: Verify that the Security Center agent (AliYunDun) is running and online.

      2. Check network connectivity: Test whether the server can reach the Security Center endpoint.

      3. Check system resources: Ensure /tmp has at least 1 GB free disk space and that CPU and memory are not exhausted.

      4. View agent logs: The log path on a Linux server is /usr/local/aegis/aegis_client/aegis_10_*/log/aegis.log.

  • What do I do if virus remediation fails?

    Refresh the page and retry. If it still fails, click "Manually Handled" and delete the file manually. If deletion fails with "Operation not permitted", the file may have the i (immutable) attribute. Run chattr -i <file> to remove it, then delete the file.

System compatibility and tool configuration questions

  • Where can I check the virus signature database version?

    View the virus signature database update time on the Overview page. The cloud-based virus signature database is updated automatically in real time; no manual action is required.

    The right side of the Overview page also displays the Cloud Scan Time (Latest Time).

  • Why does the virus detection and removal page occasionally show an error page (no rescan button)?

    This is usually caused by insufficient RAM account permissions. If you use this feature for the first time, the system may prompt you to authorize a service-linked role for Security Center. Click Authorize Now (the blue authorization button) on the page to complete the authorization and use the feature normally.

    If you have already authorized but still see the error page, confirm that the current RAM account has full access permissions for Security Center. If necessary, contact the primary account administrator to grant the required permissions.

  • Can I install third-party antivirus software (360/Huorong)?

    Yes, but compatibility issues may occur. We recommend adding the Security Center agent processes and directories (see Agent processes) to the third-party software's whitelist to prevent false positives.

    For Windows servers that continuously receive virus alerts, we recommend using third-party antivirus software for a full-disk scan as a supplementary troubleshooting method. We recommend 360 Antivirus Speed Edition or Huorong Antivirus for a full scan. We also recommend checking the internal server firewall configuration (such as Windows Firewall, iptables, or firewalld) to rule out access issues caused by firewall rules.

  • What do I do if the page does not respond after I click Authorize Now?

    If the page keeps spinning or does not respond after you click Authorize Now, this may be caused by network fluctuation or browser cache. We recommend refreshing the page and re-entering the Virus Detection and Removal console to check the authorization status. If it still fails, try clearing the browser cache, using incognito (private browsing) mode, or switching to a different browser.

  • What do I do if the Virus Detection and Removal page shows 0 assets or indicates that no paid edition is bound?

    If the Virus Detection and Removal page shows 0 assets or indicates that no paid edition is bound, troubleshoot as follows:

    • Protection Configuration: Ensure that the target server is bound to a paid protection version or level.

    • Agent status check: Ensure that the Security Center agent on the target server is online and the version is normal. If the agent is offline, reinstall or restart the agent.

  • What do I do if only "Add to Whitelist" and "Ignore" options are available when handling an alert?

    Some alerts may only show "Add to Whitelist" and "Ignore" options, missing "Kill Process" and "Virus Detection and Removal" options. This is usually because the malicious process is still running and the system cannot handle it directly.

    Solution: First select "Kill Process" (if available), then refresh the page and retry to get the complete set of handling options. If this does not resolve the issue, refer to the "virus remediation failed" troubleshooting steps above to handle it manually, then click "Manually Handled".