Lena Posted December 15, 2014 Posted December 15, 2014 my HelioHost username: mail2ftpserver: steviemy HelioHost main domain: mail2ftp.heliohost.org I don't know why it's suspended. I last logged into cPanel on November 30. Today I tried to renew/reactivate and got: "We're sorry, but we either could not find that account in the database, or it is not listed as inactive. Please contact an administrator if you feel this message is in error".
yashrs Posted December 15, 2014 Posted December 15, 2014 Your account was suspended for the following reason: Malware. 1 file(s). Worm.Mydoom-27 FOUND That means that there are some malware files found on your account. For your safety and to protect your website from potential further corruption the account has been suspended. To find the infected files we recommend making a backup of your site, download the backup file to your computer, and scan the backup using a reputable virus and malware scanner. If you're having trouble locating the offending files please ask and we can provide more information. If you are you certain that it is a false-positive, we strongly encourage you to file a false positive form here: http://cgi.clamav.net/sendvirus.cgi Your account should be unsuspended now, but keep in mind that this is a temporary unsuspension. You have 24 hours starting at the time of this post to clean your account of any and all malicious files or your account will be resuspended.
Byron Posted December 15, 2014 Posted December 15, 2014 Particularly this file: /home/mail2ftp/public_html/server/bounced
Lena Posted December 15, 2014 Author Posted December 15, 2014 Worm.Mydoom-27A virus (email worm) in a computer with Windows in India sent itself as a .exe attachment to (published) email address in my account. The virus forged that same email address in From and envelope-from. Exim on stevie bounced the message because of .exe attachment. But the bounce went again to the same email address. The bounce message (containing .exe) was stored in that "bounced" file for my manual inspection which I do monthly. I deleted the file. I changed my software to try to truncate saved bounce messages before the beginning of .exe or similar attachment.
Recommended Posts