The best way to avoid problems with user-downloaded files of any type is to have a command line virus scanner on the server that you use to scan files after downloading. If the result of the scanner is positive, delete the file, write down its IP address and inform the user.
This is a pain to install for the first time, but it is a life-saving.
source
share