Featured Posts

FREE Kaspersky Security Suite CBE 10 Everyone may have read about Kaspersky Security Suite CBE Win7 that Ramakanth Posted about 4 months ago. CBE means Computer Bild Edition. This is the version of Kaspersky that is reserved free for registered...

Readmore

Download Divx Pro 7 for Free I think there is no need for introduction to Divx,here is a promo which will give you $19.99 worth Divx Pro 7 software for free. About Divx Pro 7 DivX® Pro 7 provides everything you need for...

Readmore

Ashampoo Burning Studio 2010 Advanced for Free Ashampoo Burning Studio 2010 Advanced is nothing but Ashampoo Burning Studio v9.24,which had some advanced features compared to Ashampoo Burning Studio 2010(v 9.10). This  free offer is set by Chip...

Readmore

2 Packs to Transform Windows 7 to Mac OS X Generally we will try to get applications (or whatever) what we don't have, although we had much better application compared to what we are trying, may be I think  it's human nature. I was obsessed...

Readmore

Advanced SystemCare Pro 3.6, Free 1 year License Yet another 1 year free offer  for IObit Advanced SystemCare Professional edition, last time Kowshik posted about the free Giveaway of  Advanced SystemCare Pro from Iobit itself. This time this free...

Readmore

  • Prev
  • Next

7 Steps to remove Iframe virus from your WordPress blog

Posted on : 18-07-2009 | By : Ramakanth | In : Security, blogging, wordpress

6

Iframe virus in wordpress blog

Today we are very busy in dealing “Iframe virus”,which infected to one of my friend’s blog.His site was reported as Harmful site or Malware carrying site by both Google and Firefox.At first we don’t know what malware or virus infected his blog. After few trail and error methods we discovered an iframe placed in index.php and other php files.we thought this is the root cause because,this infected site is a personal blog,so no ads and he never used any iframe. With this clue we googled and found good tutorials to get rid of this virus,thanks to WordPress Community.This is not a new virus,we can see similar instances in 2007 blogger blog also.

Motive of Iframe virus :
This Iframe malware can infect any Php file,which access your website mainly from your (99%)

PC via FTP transaction(steals Ftp passwords) and injects harmful Iframe code in php files,this code often overwrites the ending php tags in the file and thus brings the site down.

7 Steps to remove Iframe virus

Step 1

First Install this wordpress plugin AntiVirus 0.4,then scan your templates,if you find any harmful code or virus indication.

Now Block access to your site by creating a temporary page index.htm and upload it to the server explaining that your site is down temporarily,this prevents infecting others PC’s,also ask your hosting service to scan your server.

Step 2

Now start cleaning viruses in your PC,update your anti-virus or Install branded or good working Internet security suites, as i said before the origin of infection to your site will be your PC which some how get infected through other sites.

Step 3
After complete cleaning , now Change all your FTP and cpanel passwords or ask your Site Hosting staff to change them if you do not know how to change.

Step 4

Now uninstall your FTP(desktop) software, and all the registry entries with nice uninstaller( I recommend Revo uninstaller) and install new software(Filezilla recommended)

Step 5
Don’t delete the files on the server ,What you need to do is replace the infected files with original files.
Some times your Webhoster may help you restore instead of going through all this fixing,but maintaining the site is the responsibility of the customer.

Step 6

Now Download same WordPress version,themes (Fresh copy) and plugins,scan them and check if there is iframe code in them with TextCrawler(freeware),then start replacing infected files with these files.Then remove unwanted themes and plugins.

Reopen your web site and check if your Antivirus prompt any alert about the site.

Step 7

The Iframe virus or malware can infect any files (.php, .html, .asp) which have got </body> tag,below are some common files where we can find this code
index.php in root folder
wp-config.php in root folder( carefully while replacing this file,it contains database information like, user name and password)
index.php in wp-admin folder
index-extra.php in wp-admin folder
index.php in wp-contents\yourtheme\ folder
home.php in wp-contents \ yourtheme \ folder
default-filters.php in wp-includes folder

I hope this will resolve the issue if you find this virus in your blog,but i cannot give 100% assurance.As errors are always possible,if you find any errors please notify us in comments.

Reference:

How to remove IFrame Trojan?
Frame Hack WP on Several Sites
Using Combofix to guide and tutorial
HTML: iframe wordpress-inf Infection

Ramakanth

I'm the editor of this blog & one of the Founder of Techno360.in. I likes to blog about everything,but my knowledge doesn't allow me,so I'm currently sticking to freebies, web-browsers and Windows OS related articles.

Comments (6)

The following article helped me clean my websites from iframe virus
http://www.qualitycodes.com/tutorial.php?articleid=29

Well i have also written an article on my blog. There is a script in PHP which automaticly scans and cleans you hosts and all index files infected with a iframe code. It is easy to use, if you would like you can inlcude it in you site. My post URL is
http://hotfixes.edibra.com/webmasters/clean-iframe-virus

I've also written in my blog with a clear steps to avoid it.
http://mycodings.blogspot.com/2009/05/remove-malw...
My recent post Mysql Query Tips &amp; Tricks

very well

information you write it very clean. I’m very lucky to get this information from you.

Hello everyone thanks for

good information.

[...] such as the Zen Cart eCommerce solution.The interesting nature of this exploit is, similar to iframe virus it is injecting a script in php files  (.php files like wp-config.php) and installs a malware, but [...]

Write a comment