I posted a http://www.blackhatworld.com/blackhat-seo/blogging/435817-malicious-scripts-installed-my-site-how-do-i-fix.html a few days ago about my site being hacked and having malicious scripts installed on it, but now I am wondering if my host is lying/scamming me. They sent me a list of infected pages/files and I went in to fix them and realized that most of the pages didn't seem to exist (list posted on other thread). So I emailed support and told them the files did not exist within my file manager and received a response stating that it looked like the files had been removed. I responded and told them I had not removed any files. They responded with this:
A COMPLETELY different list of files. I'm not saying that it is not possible, but how likely is it that the files with malicious script would change within two days? It made me suspicious so I emailed back to support telling them that I had fixed the issues (did not change a single thing) on these pages and asked them to scan again. I received this response:
These were on the second list but what happened to the rest that were supposedly infected? I also found out recently that they stopped accepting adult content and websites are being suspended for it. Although I was not notified. I am wondering if this has anything to do with my situation as some of my sites are adult related. I wonder if they are just stringing me along and still collecting my monthly payment. I do plan on switching hosts, but I want to make sure I do not have any malicious scripts in my files before I transfer them to a new host.
Any advice? Is it possible that my sites are not infected but they are just lying to me about it? Why does the list of files keep changing. Should I just transfer to a better host and have them scan the files and then go from there to fix it? I am getting very frustrated with all of this. I just want to get things resolved and get my sites back online. Thank you!
Dear customer,
Here is the list of files in your account that contain malicious code used for hacking purposes, please either delete them OR scan and cure with your antiviral software:
public_html/website.com/wp-conf.php
public_html/website.com/myposte/img/postale.jpg
public_html/website.com/myposte/img/logoposte_home.jpg
public_html/password_forgotten.php
public_html/tiny_mce/plugins/spellchecker/config.php
website2.com/wp-content/uploads/2011/05/wp-conf.php
public_html/website2.com/create.php
public_html/website2.com/wp-admin/includes/fantalisticz.php
public_html/c101.php
public_html/account_password.php
public_html/data/db/contact.db.php
public_html/ymm_autoinstaller/index.php
public_html/includes/functions/database.php
public_html/includes/functions/password_funcs.php
public_html/includes/database_tables.php
public_html/includes/languages/espanol/index.php
public_html/includes/languages/espanol/images/gifimg.php
public_html/includes/languages/espanol/images/image.php
public_html/includes/languages/espanol/password_forgotten.php
public_html/includes/languages/espanol/account_password.php
public_html/includes/languages/english/images/gifimg.php
public_html/includes/languages/english/images/image.php
public_html/includes/languages/english/password_forgotten.php
public_html/includes/languages/english/account_password.php
public_html/includes/languages/frensh/images/gifimg.php
public_html/includes/languages/frensh/images/image.php
public_html/includes/languages/german/index.php
public_html/includes/languages/german/images/gifimg.php
public_html/includes/languages/german/images/image.php
public_html/includes/languages/german/password_forgotten.php
public_html/includes/languages/german/account_password.php
public_html/includes/configure.php
A COMPLETELY different list of files. I'm not saying that it is not possible, but how likely is it that the files with malicious script would change within two days? It made me suspicious so I emailed back to support telling them that I had fixed the issues (did not change a single thing) on these pages and asked them to scan again. I received this response:
Hi,
You still have infected files. Here is the result of the scan:
===================================
malware detect scan report for xxxxxx.justhost.com:
SCAN ID: 05xxxxx-xxxxx-xxxx
TIME: May 2 12:52:35 -0500
PATH: ./
TOTAL FILES: 9536
TOTAL HITS: 8
TOTAL CLEANED: 0
NOTE: quarantine disabled; set quar_hits=1 in conf.maldet or run 'maldet -q 05xxxxx-xxxxx-xxxx' to quarantine results
FILE HIT LIST:
{CAV}HTMl.IFrame-33 : ./password_forgotten.php
{CAV}HTMl.IFrame-33 : ./account_password.php
{CAV}HTMl.IFrame-33 : ./ymm_autoinstaller/index.php
{CAV}HTMl.IFrame-33 : ./includes/functions/database.php
{CAV}HTMl.IFrame-33 : ./includes/database_tables.php
{CAV}HTMl.IFrame-33 : ./includes/languages/espanol/index.php
{CAV}HTMl.IFrame-33 : ./includes/languages/german/index.php
{CAV}HTMl.IFrame-33 : ./includes/configure.php
These were on the second list but what happened to the rest that were supposedly infected? I also found out recently that they stopped accepting adult content and websites are being suspended for it. Although I was not notified. I am wondering if this has anything to do with my situation as some of my sites are adult related. I wonder if they are just stringing me along and still collecting my monthly payment. I do plan on switching hosts, but I want to make sure I do not have any malicious scripts in my files before I transfer them to a new host.
Any advice? Is it possible that my sites are not infected but they are just lying to me about it? Why does the list of files keep changing. Should I just transfer to a better host and have them scan the files and then go from there to fix it? I am getting very frustrated with all of this. I just want to get things resolved and get my sites back online. Thank you!