|
Thanks everyone for your suggestions and help.
In the end, after having run about a million different scans and finding precisely nothing, we contacted the support from the hosting company.
They had a look, and found that the .htaccess file had some lines of code that were redirecting users depending on the referrer. E.g. if you accessed the site from a google or yahoo search, it redirected you to Antivirus 2009 spam sites.
The reason we didn't see it was that the was no .htaccess file, only a "ht" file, and a php file which renamed ht to .htaccess when it was accessed.
Anyway, all cleaned, deleted and pristine once again now. And several back ups made too. Lesson well learned.
Thanks again!
Rob
|