re: iframe virus / malware infected our site

Hi

It seems our site (on a shared host) has been infected with iframe virus

Lots of our html / php files had iframe code added - pointing to 2 external dodgy looking websites

(I have removed most of the code manually and / or copied over with a clean backup)

At the moment when we try to upload index.htm or index.html
the files are removed immediately from the FTP server so homepage doesn’t load! ???

Please check out our site:
hxxp://www.visualiminals.com (HOMEPAGE NOT WORKING as mentioned above)

so please try
hxxp://www.visualiminals.com/products/genius.htm

I also found this script which looks suspicious :o

We used McAfee secure which found 2 possible vulnerabilities:

  1. Cross site scripting vulnerability in recommend a friend popup script

  2. website stats script

I have contacted our host already but any tips to remove the threats and secure the site would be great!

Thank you in advance

I get a 403 permissions error on the home page

No alert on the products/genius.htm page.
I presume you have removed the malicious code from that page ?

Can you modify your post as by copying the script into this page, avast could possibly alert on this page, although it didn’t, but it isn’t advised to leave it unadulterated.

change the < > characters to ^ ^ or something like that so it can’t possibly be interpreted as a script command.

Change your passwords, for uploading, any modification of files and content management software, etc. old versions of PHP can be vulnerable to exploit so you need to ensure that they are fully up to date.