<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: HTML:Iframe-inf wordpress Infection</title>
	<atom:link href="http://fieldsmarshall.com/htmliframe-inf-wordpress-infection/feed/" rel="self" type="application/rss+xml" />
	<link>http://fieldsmarshall.com/htmliframe-inf-wordpress-infection/</link>
	<description>Website Optimization and PPC Issues</description>
	<lastBuildDate>Sun, 10 Jan 2010 03:09:23 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Malware - netzwelt.de Forum</title>
		<link>http://fieldsmarshall.com/htmliframe-inf-wordpress-infection/comment-page-1/#comment-1323</link>
		<dc:creator>Malware - netzwelt.de Forum</dc:creator>
		<pubDate>Fri, 07 Aug 2009 06:44:20 +0000</pubDate>
		<guid isPermaLink="false">http://fieldsmarshall.com/?p=133#comment-1323</guid>
		<description>[...]  [...]</description>
		<content:encoded><![CDATA[<p>[...]  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 7 Steps to remove Iframe virus from your Wordpress blog &#124; Techno360</title>
		<link>http://fieldsmarshall.com/htmliframe-inf-wordpress-infection/comment-page-1/#comment-1319</link>
		<dc:creator>7 Steps to remove Iframe virus from your Wordpress blog &#124; Techno360</dc:creator>
		<pubDate>Sat, 18 Jul 2009 15:41:42 +0000</pubDate>
		<guid isPermaLink="false">http://fieldsmarshall.com/?p=133#comment-1319</guid>
		<description>[...] How to remove IFrame Trojan? Frame Hack WP on Several Sites  Using Combofix to guide and tutorial  HTML: iframe wordpress-inf Infection  [...]</description>
		<content:encoded><![CDATA[<p>[...] How to remove IFrame Trojan? Frame Hack WP on Several Sites  Using Combofix to guide and tutorial  HTML: iframe wordpress-inf Infection  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Como limpar o maldito vírus IFrame que infectou o seu blog na plataforma Wordpress &#8211; WP (vírus de blogs) &#124; Rei da Cocada Preta</title>
		<link>http://fieldsmarshall.com/htmliframe-inf-wordpress-infection/comment-page-1/#comment-1317</link>
		<dc:creator>Como limpar o maldito vírus IFrame que infectou o seu blog na plataforma Wordpress &#8211; WP (vírus de blogs) &#124; Rei da Cocada Preta</dc:creator>
		<pubDate>Sun, 12 Jul 2009 17:08:48 +0000</pubDate>
		<guid isPermaLink="false">http://fieldsmarshall.com/?p=133#comment-1317</guid>
		<description>[...] para limpeza usadas neste tutorial: How to remove IFrame Trojan? HTML:Iframe-inf wordpress Infection  iFrame Hack on Several WP Sites  AntiVirus protection for your blog Using Combofix a guide and [...]</description>
		<content:encoded><![CDATA[<p>[...] para limpeza usadas neste tutorial: How to remove IFrame Trojan? HTML:Iframe-inf wordpress Infection  iFrame Hack on Several WP Sites  AntiVirus protection for your blog Using Combofix a guide and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: HTML:Iframe-inf fun&#8230;.not</title>
		<link>http://fieldsmarshall.com/htmliframe-inf-wordpress-infection/comment-page-1/#comment-1316</link>
		<dc:creator>HTML:Iframe-inf fun&#8230;.not</dc:creator>
		<pubDate>Thu, 02 Jul 2009 00:13:25 +0000</pubDate>
		<guid isPermaLink="false">http://fieldsmarshall.com/?p=133#comment-1316</guid>
		<description>[...] days ago, which helped me a treat, but also returns more files that are ok than the ones infected:  here The shell scripts this guy has created, did help me track the bits i needed to remove which was a [...]</description>
		<content:encoded><![CDATA[<p>[...] days ago, which helped me a treat, but also returns more files that are ok than the ones infected:  here The shell scripts this guy has created, did help me track the bits i needed to remove which was a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ????? ???????? &#8211; ???? ????? iframe injections ??????? SSH &#124; ?? ?????</title>
		<link>http://fieldsmarshall.com/htmliframe-inf-wordpress-infection/comment-page-1/#comment-1313</link>
		<dc:creator>????? ???????? &#8211; ???? ????? iframe injections ??????? SSH &#124; ?? ?????</dc:creator>
		<pubDate>Sun, 21 Jun 2009 19:57:24 +0000</pubDate>
		<guid isPermaLink="false">http://fieldsmarshall.com/?p=133#comment-1313</guid>
		<description>[...] ????? ????) ?????? ???? ???? ?? ????? ??? ????? ?? iframe, http://fieldsmarshall.com/htmliframe-inf-wordpress-infection/ ?? ?????? ????? ??????? ????? ??? [...]</description>
		<content:encoded><![CDATA[<p>[...] ????? ????) ?????? ???? ???? ?? ????? ??? ????? ?? iframe, <a href="http://fieldsmarshall.com/htmliframe-inf-wordpress-infection/" rel="nofollow">http://fieldsmarshall.com/htmliframe-inf-wordpress-infection/</a> ?? ?????? ????? ??????? ????? ??? [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fields.marshall</title>
		<link>http://fieldsmarshall.com/htmliframe-inf-wordpress-infection/comment-page-1/#comment-1312</link>
		<dc:creator>fields.marshall</dc:creator>
		<pubDate>Fri, 19 Jun 2009 17:08:42 +0000</pubDate>
		<guid isPermaLink="false">http://fieldsmarshall.com/?p=133#comment-1312</guid>
		<description>Victor thanks for your comments.. 

Email me your SED code and I will place it .. You think this is better than perl ? 


Max you would need to talk to your hosting provider to get command line access</description>
		<content:encoded><![CDATA[<p>Victor thanks for your comments.. </p>
<p>Email me your SED code and I will place it .. You think this is better than perl ? </p>
<p>Max you would need to talk to your hosting provider to get command line access</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Max</title>
		<link>http://fieldsmarshall.com/htmliframe-inf-wordpress-infection/comment-page-1/#comment-507</link>
		<dc:creator>Max</dc:creator>
		<pubDate>Thu, 28 May 2009 05:10:35 +0000</pubDate>
		<guid isPermaLink="false">http://fieldsmarshall.com/?p=133#comment-507</guid>
		<description>what&#039;s a command line and how do you access it</description>
		<content:encoded><![CDATA[<p>what&#8217;s a command line and how do you access it</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Victor</title>
		<link>http://fieldsmarshall.com/htmliframe-inf-wordpress-infection/comment-page-1/#comment-327</link>
		<dc:creator>Victor</dc:creator>
		<pubDate>Fri, 22 May 2009 13:52:56 +0000</pubDate>
		<guid isPermaLink="false">http://fieldsmarshall.com/?p=133#comment-327</guid>
		<description>Sorry but i can&#039;t add the full code because this doesn&#039;t support url in comment.

&lt;pre&gt;find ./ -type f -exec sed -i &#039;s///&#039; {} \;&lt;/pre&gt;</description>
		<content:encoded><![CDATA[<p>Sorry but i can&#8217;t add the full code because this doesn&#8217;t support url in comment.</p>
<pre>find ./ -type f -exec sed -i 's///' {} \;</pre>
]]></content:encoded>
	</item>
	<item>
		<title>By: Victor</title>
		<link>http://fieldsmarshall.com/htmliframe-inf-wordpress-infection/comment-page-1/#comment-326</link>
		<dc:creator>Victor</dc:creator>
		<pubDate>Fri, 22 May 2009 13:50:18 +0000</pubDate>
		<guid isPermaLink="false">http://fieldsmarshall.com/?p=133#comment-326</guid>
		<description>I think this is the simpliest solution to remove iframe-inf after you have found the infected text. Works 100%.

find ./ -type f -exec sed -i &#039;s///&#039; {} \;


Just replace the iframe src addres with the one from your infected text. Use regex on click=.*.  Run the command from /home directory to remove the virus from all website files.

Good Luck!</description>
		<content:encoded><![CDATA[<p>I think this is the simpliest solution to remove iframe-inf after you have found the infected text. Works 100%.</p>
<p>find ./ -type f -exec sed -i &#8217;s///&#8217; {} \;</p>
<p>Just replace the iframe src addres with the one from your infected text. Use regex on click=.*.  Run the command from /home directory to remove the virus from all website files.</p>
<p>Good Luck!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fields.marshall</title>
		<link>http://fieldsmarshall.com/htmliframe-inf-wordpress-infection/comment-page-1/#comment-220</link>
		<dc:creator>fields.marshall</dc:creator>
		<pubDate>Tue, 05 May 2009 14:10:18 +0000</pubDate>
		<guid isPermaLink="false">http://fieldsmarshall.com/?p=133#comment-220</guid>
		<description>Hi GrandPa Smurf, 

Yes, I have seen the infection on servers without wordpress. On shared hosting if the infection can get in with one website then it seems to be able to access other websites and spread to others. 

Glad the script was helpful</description>
		<content:encoded><![CDATA[<p>Hi GrandPa Smurf, </p>
<p>Yes, I have seen the infection on servers without wordpress. On shared hosting if the infection can get in with one website then it seems to be able to access other websites and spread to others. </p>
<p>Glad the script was helpful</p>
]]></content:encoded>
	</item>
</channel>
</rss>
