i have files infected by JS:Illredir-B trojan (i use Avast).
there is a javascript code appended to every index.php and index.html under every domain of my custmer. i have experienced that with my previous provider and i know this happened because somehow my customers ftp username and password were compromised. ( i changed passwords and i still can see unsuccessfull login attemps with that username in the logs. )
i did a scan with clamav and avg to see which files were infected but none of them could find anything. i dont know if there is a parameter i should use.
what can you suggest?
you can check one of the infected domains : http://sistre.net
(note: i couldnt install Avast on my CentOS , it depends on libexpat.so.1 and i couldnt find a way to solve it.)
there is a javascript code appended to every index.php and index.html under every domain of my custmer. i have experienced that with my previous provider and i know this happened because somehow my customers ftp username and password were compromised. ( i changed passwords and i still can see unsuccessfull login attemps with that username in the logs. )
i did a scan with clamav and avg to see which files were infected but none of them could find anything. i dont know if there is a parameter i should use.
what can you suggest?
you can check one of the infected domains : http://sistre.net
(note: i couldnt install Avast on my CentOS , it depends on libexpat.so.1 and i couldnt find a way to solve it.)
Last edited: