Malicious activity found on your account


Recommended Posts

Just ordered a 2-year commitment and within hours, before anything was done / uploaded, I get six (6) e-mail notices (roughly the same time):


Our systems performed a routine malware/virus scan on your account and unfortunately located infected/malicious files. We've automatically moved the infected files(s) out of your public_html directory into a safe, quarantined directory. Below is the file our scanners were able to locate:

(quarantined to /home/hawkinfected/cxsuser/<mydomain>/jameson-limpkin.php.1460163030_1) ClamAV detected virus = [Php.Trojan.WSO-1]

All of them are Php.Trojan.WSO-1, various names obviously.  Now, when I got my first confirmation / account info e-mail, I followed the instructions to change my cPanel pw, and I did to a solid pw (letters, numbers, symbols, etc).  What gives?  Heck, when I go to my site, it's still blank - I've not setup WordPress or anything yet.  How is this happening so quickly, and why do I feel like I've made a terrible error in judgement?

Link to comment
Share on other sites

The emails you're getting are from our automated file scanner which looks for known malware/infections in files you're attempting to upload. As indicated a handful of your files are being detected as malicious or having some malicious code in them.

If you contact our support team we can manually review the results from your account to see if it's a false-positive but in most cases the scanner is accurate and the files do actually contain infected code.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.