We have today updated the terms of service to add a single line item to General Abuse:
Virus/Trojan/Malware sources & infected files. Such infected files will be cleaned, or quarantined without prior notice to prevent infection of site visitors.
This is to combat a growing issue of customers having uploaded virus infected files, trojans, and other malware.
It was time, we just had to make it official and start the process, I’ve seen too much. We’d rather be safe than have clients spreading virii, many times even when they are unaware.
The worst case now is there site may be missing a page or a download, and we can research the quarantine to find it if it is cleanable or not. At least now it promotes action on the clients behalf, and prevents further spread to their visitors which is very common now.
We’ve been mulling over the action path for a week, and decided this is the best way forward.
We will try to do so, however in some cases we may miss, so that is why we have worded it as such. Backup is probably not good, as it would have to come with a warning such as ‘this file is virus infected!’
the virus infections are not coming from the server, but from client upload (or deface) in the first place, we don’t execute client send files on the servers, so there is little to no risk for the server itself, it is just the visitors that download it from the internet, or browse to a page that tries to auto download it.
even for HTML/ASP/net/perl pages and all, we open them in a text editor, not a web browser.