ESET reports HTML/ScrInject. B when we disabled Memcached

Hi @jorgelpolanco,

There is probably malicious PHP code running on your server. Cleaning it up is beyond the scope of this forum – there are good general practices for doing this that aren’t specific to OJS – but I’d recommend reviewing a few threads on this forum for some general info:

If your server is running PHP scripts via mod_php, then the culprit could be any PHP script on your server – they will all run with the same user permissions. (For this reason we don’t recommend running PHP with mod_php in a shared environment.)

Regards,
Alec Smecher
Public Knowledge Project Team