If you run imunifyAV than better exclude /usr/local/ispconfig/server/lib/classes/system.inc.php or whole /usr/local/ispconfig Since around 1 week ImunifyAV detects the file as backdoor (false postitive) and if you clean it (clean all) than you end up in a 0 byte file.