Received email from Server host (Arvixe) that my domain and files hosted on their shared server was infected and they suspended the account subject to getting a professional cleaning. It was placed on a Spamhaus Blacklisting report.
Abuse Type: Spamhaus Blacklisting
Part of Message read as follows:
We have received a blacklist report from Spamhaus regarding malicious activity originating from the server this account is hosted on. Further investigation has concluded this activity originated from malware on an account under your control. We have temporarily disabled access to websites on the account to prevent further malicious activity.
This IP is infected (or NATting for a computer that is infected) with a botnet, most likely eitest.
This IP address is infected with or NATing for an infection of "Eitest". This IP address is probably a web server where one or more virtual hosts have been infected using an exploit kit (eg: angler, empire, RIG) using EItest protocols to download, install and operate malicious code, such as gootkit, dreambot, ramnit, vawtrak, cryptXXX - infostealers, ransomware etc.
This was detected by observing this IP attempting to make contact to a "eitest" Command and Control server, with contents unique to "eitest" C&C command protocols.
As your account was found to be listed on the Spamhaus blacklist, you are now required to professionally clean your account before restrictions can be removed. This service may be performed by our preferred partner SiteLock or another third-party company of your choosing. We will be happy to help you provide access to any third-party service which cleans your account.
I am here looking for someone with expertise to clean the account.
26 freelancers are bidding on average $121 for this job
Hello, Hope you are doing well. I have 6 years of experience in Linux and Webhosting. I will remove the malware content and secure the server. We can remove Server from Blacklist Regards. VishnuLal
i am fully experienced anti-malware removal and protection specialist. i can track and remove all the traces of malware on your server and ensure that your server on Arvixe if spam free and remove the suspension