A scanner found something.
WHAT IT MEANS
Either our server-side scanning or ImunifyAV identified files matching known malicious signatures.
FIRST
Open a ticket so we can tell you what was found and where.
Run ImunifyAV yourself from cPanel, scanning the whole home directory rather than only the website folder. Backdoors are frequently placed elsewhere.
WHAT TO DO
Take a copy of the current state before changing anything
Change every password: hosting, database, application administrators, FTP, email
Clean, preferably by restoring a backup from before the infection Update everything immediately afterwards
IF YOU HAVE NO CLEAN BACKUP
Replace core files with fresh official copies, replace every plugin and theme with fresh downloads, and remove anything unaccounted for.
FALSE POSITIVES
They happen. If a file is flagged that you believe is legitimate, tell us rather than deleting it.
Download a backup before deleting anything.
CLOSING THE ENTRY POINT
Out-of-date software and nulled themes or plugins account for most compromises.
A cleaned but unhardened site is compromised again within days.