Question: |
Hello,please take me Back again into the tariff a PRO. Yesterday I switched on VPS1 and the site was celebrated as the virus in Yandex. I want to return to the PROS as soon as possible, because we are losing money and customers! |
Answer: |
Hello. It is possible that you are confused is not related things. The site could not become \"viral\" because of the change of rate, but to create the load from which you linked to CHD he could well. if you decide the problem with the viruses and nagruzkoi then you may be able to change the rate |
Question: |
the fact is that before moving on VPS1, all was well! virus in the website, plus we`ve added a backup. but after the transition to VPS1 Yandex us immediately as the virus has been tagged! |
Answer: |
the fact that your site was infected prior to the transition to the UPU, there are no other facts. Antivirus found on your account webshell, hack tool, date download of Vesela much earlier than you changed the rate. |
Question: |
wow, don`t tell me what to do? how to remove that? sorry for the initial emotions! |
Question: |
tell file shell please. |
Answer: |
two anti-virus found nothing /home/vdrssd]# clamscan -ir ./ ; avgscan -u ./
----------- SCAN SUMMARY ----------- Known viruses: 3097812 Engine version: 0.98 Scanned directories: 937 Scanned files: 13509 files Infected: 0 Data scanned: 254.61 MB Data read: 201.47 MB (ratio 1.26:1) Time: 47.665 sec (0 m 47 s) AVG command line Anti-Virus scanner Copyright (c) 2013 AVG Technologies CZ
Virus database version: 3684/7051 Virus database release date: Sat, 01 Feb 2014 08:19:00 +0200
Files scanned : 14164(13564) Infections found : 0(0) PUPs found : 0 Files healed : 0 Warnings reported : 0 reported Errors : 0 So it`s not a virus and malware insertion on the website http://sitecheck2.sucuri.net/results/u4ebagermania.ru today you changed the files? we see that the date at the today file start with a change of all passwords |
Question: |
I`ve uploaded a backup of the site. where exactly need to change passwords, please tell me. |
Answer: |
please note the date of the log 2013-06-09.log:/home/vdrssd/public_html/mod.php: PHP.Shell-38 FOUND the viruses you had have long what version of engine are you using ? how to store passwords? how long has it been updated? |
Answer: |
http://vms.drweb.com/online Dr. web also nothing found on the website. pohoje your site is now clean. you need to urgently change all passwords and obratitsya on Yandex with a request to unblock the site. |
Question: |
well, thank you. we have already done it. what passwords you need to change? |
Question: |
Engine version 9.7, it will be a year already. Passwords are not stored in the mind in fact. |
Answer: |
all passwords to change, Parral billing, panel, site admin, user password database, to see if extra users, check out the new updates to the engine, the engine has not been updated for a year not in his favor. install the additional modules of protection for your engine, which you can ask the developer |
Question: |
thanks Eugene. |
Answer: |
ok
|