My whole hosting account affected with js:redirector-dc?

Discussion in 'Site & Server Administration' started by teckinik, Aug 23, 2010.

  1. #1
    I didn't know that viruses can enter hosting account and affect all websites. Right now I am extremely tense so can anyone suggest remedy for this problem?
     
    teckinik, Aug 23, 2010 IP
  2. madaboutlinux

    madaboutlinux Member

    Messages:
    250
    Likes Received:
    7
    Best Answers:
    2
    Trophy Points:
    43
    #2
    Do you have a Shared account OR you have your own Dedicated server?

    If you are on Shared hosting, it's good to inform the hosting company and have them check the logs. They can tell you exactly how the code was injected, from which IP and what needs to be done to avoid it in the future.

    If you have a Dedicated server, I would say have someone look into it for you.
     
    madaboutlinux, Aug 23, 2010 IP
  3. RonBrown

    RonBrown Well-Known Member

    Messages:
    934
    Likes Received:
    55
    Best Answers:
    4
    Trophy Points:
    105
    #3
    On a poorly set-up server they can. Each web site should operate in isolation from one another, and a compromized web site should not affect other web sites on the same server. I appreciate you want to get your problem fixed ASAP, but I'd consider moving hosts after this as it shouldn't happen. If you're managing your own VPS or dedicated then you need to get professional help on how to secure your server and web sites properly.
     
    RonBrown, Aug 23, 2010 IP
  4. Rackshack

    Rackshack Peon

    Messages:
    54
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #4
    How many sites do you have all together?
     
    Rackshack, Aug 23, 2010 IP
  5. alan_smithee

    alan_smithee Active Member

    Messages:
    873
    Likes Received:
    15
    Best Answers:
    0
    Trophy Points:
    60
    #5
    i have same trouble before, your host probably got infected from within your computer due to spyware/malware that stole all you ftp/ssh credentials

    so best way to deal with it is to disconnect your computer from the internet first and make thorough malware scan on it or reinstall its whole system.
    then while you're at it, change all your ftp and/or ssh passwords using another computer (don't use your infected computer)

    last thing to do is to manually remove the trojan codes from your index.html files
     
    alan_smithee, Aug 23, 2010 IP