hi
Has anyone come across this before.
I have a VPS with hostwind and I suddently noticed when clicking on a search result of one of my sites on google I was redirected to a malware site, It turns out my .htaccess file has been modified to redirect google traffic to a 3rd party malware site.
I have uploaded the old correct .htaccess files and just a few hours later they were reverted back to the ones with malicious code.
I have set read only permissions on the .htaccess file to no avail.
Reset the root password
Reset the account password (ftp and account)
Deleted any 3rd party plugins
It looks like their is some malicious plugin or theme being used to modify the .htaccess file, is there any way to find out which one it is as I have over 30 domains on this account.
thanks
Has anyone come across this before.
I have a VPS with hostwind and I suddently noticed when clicking on a search result of one of my sites on google I was redirected to a malware site, It turns out my .htaccess file has been modified to redirect google traffic to a 3rd party malware site.
I have uploaded the old correct .htaccess files and just a few hours later they were reverted back to the ones with malicious code.
I have set read only permissions on the .htaccess file to no avail.
Reset the root password
Reset the account password (ftp and account)
Deleted any 3rd party plugins
It looks like their is some malicious plugin or theme being used to modify the .htaccess file, is there any way to find out which one it is as I have over 30 domains on this account.
thanks