SkippyKtm
The Lorax, my FIL rip...
If a site is compromised, the only way to be real sure it is back up and clean is install from a known good backup. Fairly common in the hosting world, etc to have snapshots of the site, on another drive, just for this purpose. It has to come from before the compromise though and you will lose anything added from that point to present. but..you want to lose whatever malicious code got buried, so that's that.
For your own personal stuff, learn to use the browser security add-ons. Firefox is easy to use, but you should use several addons all the time in my opinion, then learn whitelisting and blacklisting. Noscript, adblock+, better privacy, ghostery are all good. Noscript and learning to use it is the most important. Also keep a couple live CDs (operating systems that run friom a CD or DVD disk only) hanging around if you think your hard drive got boned.
Even whopper big sites with full time ace IT guys get compromised, there is no permanent fix, no perfect solution as tech changes all the time. dotgov sites have gotten pwned, big commerce sites, all of them.
It is like saying, need the perfect machine that will never break, no matter how much it is used. Just ain't happening.
If an image is used to restore this site (and I do it all the time with my computers) it would be necessary, but kinda stink to lose all the data since this happened.
I know of a few AS members that are currently avoiding this site (because they're afraid it'll hose their computers...) until things get straightened out.:msp_wink: