Hi, I have here an urgent issue: after installing following modules http://drupal.org/project/colors and http://drupal.org/project/fullcalendar I got informed, by my web hosting company about malicious files found under my account:
{HEX}php.exe.globals.388 :
/home/jlucamab/public_html/ProfShop4U.be/belgie/sites/all/modules/fullcalend
ar/includes/fullcalendar.drush.inc
"This files are being abused by crackers/hackers to install malicious scripts
on your account. "
I checked my files and saw that my public_html is empty now.
Is this normal? Any precedents? The installed modules come from the Drupal site .. I presumed it will be safe.

Thanks a lot!
Luc

Comments

nevets’s picture

I would ask them for details, where is there information from?

Sounds like they cleared out your public_html folder.

ColdSun’s picture

Is it shared hosting? Perhaps another client in their environment was compromised.