Featured Posts

FREE Kaspersky Security Suite CBE Win7 or KIS 2010... I know & I think every one know that kaspersky is top rated security solution compared to all other security products. Previously we shared several kaspersky Promotions and one (26) KIS 2010 License...

Readmore

Download Ashampoo Burning Studio 9.10 For Free Previously( on Sept 22)  we shared promo for Ashampoo Burning Studio Advanced,now we are here with another Ashampoo  promo which will give you Free full version license key for Ashampoo Burning...

Readmore

Download Divx Pro 7 for Free I think there is no need for introduction to Divx,here is a promo which will give you $19.99 worth Divx Pro 7 software for free. About Divx Pro 7 DivX® Pro 7 provides everything you need for...

Readmore

Free 60 days Kaspersky Internet Security 2009 License This promo doesn't requires any registration...e.t.c, just click this  link http://www.kasperskyusa.com/custom/nasba/kis8.0.0.506en.exe and download the installation file. A activation key is already...

Readmore

Free 6 months BitDefender Total Security 2010 License we already shared this promo for previous Bitdefender  version (2009), today we are re-posting same promo which will give you free 6 months license for latest BitDefender Total Security 2010 software About...

Readmore

Techno 360 Rss

7 Steps to remove Iframe virus from your Wordpress blog

Posted by Ramakanth | Posted in Security, blogging, wordpress | Posted on 18-07-2009

2

Iframe virus in wordpress blog

Today we are very busy in dealing “Iframe virus”,which infected to one of my friend’s blog.His site was reported as Harmful site or Malware carrying site by both Google and Firefox.At first we don’t know what malware or virus infected his blog. After few trail and error methods we discovered an iframe placed in index.php and other php files.we thought this is the root cause because,this infected site is a personal blog,so no ads and he never used any iframe. With this clue we googled and found good tutorials to get rid of this virus,thanks to Wordpress Community.This is not a new virus,we can see similar instances in 2007 blogger blog also.

Motive of Iframe virus :
This Iframe malware can infect any Php file,which access your website mainly from your (99%)

PC via FTP transaction(steals Ftp passwords) and injects harmful Iframe code in php files,this code often overwrites the ending php tags in the file and thus brings the site down.

7 Steps to remove Iframe virus

Step 1

First Install this wordpress plugin AntiVirus 0.4,then scan your templates,if you find any harmful code or virus indication.

Now Block access to your site by creating a temporary page index.htm and upload it to the server explaining that your site is down temporarily,this prevents infecting others PC’s,also ask your hosting service to scan your server.

Step 2

Now start cleaning viruses in your PC,update your anti-virus or Install branded or good working Internet security suites, as i said before the origin of infection to your site will be your PC which some how get infected through other sites.

Step 3
After complete cleaning , now Change all your FTP and cpanel passwords or ask your Site Hosting staff to change them if you do not know how to change.

Step 4

Now uninstall your FTP(desktop) software, and all the registry entries with nice uninstaller( I recommend Revo uninstaller) and install new software(Filezilla recommended)

Step 5
Don’t delete the files on the server ,What you need to do is replace the infected files with original files.
Some times your Webhoster may help you restore instead of going through all this fixing,but maintaining the site is the responsibility of the customer.

Step 6

Now Download same Wordpress version,themes (Fresh copy) and plugins,scan them and check if there is iframe code in them with TextCrawler(freeware),then start replacing infected files with these files.Then remove unwanted themes and plugins.

Reopen your web site and check if your Antivirus prompt any alert about the site.

Step 7

The Iframe virus or malware can infect any files (.php, .html, .asp) which have got </body> tag,below are some common files where we can find this code
index.php in root folder
wp-config.php in root folder( carefully while replacing this file,it contains database information like, user name and password)
index.php in wp-admin folder
index-extra.php in wp-admin folder
index.php in wp-contents\yourtheme\ folder
home.php in wp-contents \ yourtheme \ folder
default-filters.php in wp-includes folder

I hope this will resolve the issue if you find this virus in your blog,but i cannot give 100% assurance.As errors are always possible,if you find any errors please notify us in comments.

Reference:

How to remove IFrame Trojan?
Frame Hack WP on Several Sites
Using Combofix to guide and tutorial
HTML: iframe wordpress-inf Infection

Twitter It!

Related posts:

  1. 10 best plugins to monetize your Wordpress blog
  2. 17 themes for Wordpress Personal blogs
  3. How to remove or delete the worm Conficker
  4. Free Premium Wordpress Themes
  5. Wordpress 2.8 Now Available

Buzz it!

Comments (2)

The following article helped me clean my websites from iframe virus
http://www.qualitycodes.com/tutorial.php?articleid=29

Well i have also written an article on my blog. There is a script in PHP which automaticly scans and cleans you hosts and all index files infected with a iframe code. It is easy to use, if you would like you can inlcude it in you site. My post URL is
http://hotfixes.edibra.com/webmasters/clean-iframe-virus

Write a comment

Spam Protection by WP-SpamFree