<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: HEUR:Trojan.Script.Iframe</title>
	<atom:link href="http://linuxsysadminblog.com/2009/03/heurtrojanscriptiframe/feed/" rel="self" type="application/rss+xml" />
	<link>http://linuxsysadminblog.com/2009/03/heurtrojanscriptiframe/</link>
	<description></description>
	<lastBuildDate>Tue, 31 Jan 2012 18:06:48 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
	<item>
		<title>By: gerold</title>
		<link>http://linuxsysadminblog.com/2009/03/heurtrojanscriptiframe/comment-page-2/#comment-2485</link>
		<dc:creator>gerold</dc:creator>
		<pubDate>Tue, 31 Jan 2012 18:06:48 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=432#comment-2485</guid>
		<description>@Katrina -- i agree, Kaspersky sometimes detect scripts (ex: php) as virus or dangerous even if they&#039;re not.  Of course it&#039;s better to look at the script itself if you doubt the Kaspersky result.

This is also true with other antivirus suites.  Thanks for pointing this out!</description>
		<content:encoded><![CDATA[<p>@Katrina &#8212; i agree, Kaspersky sometimes detect scripts (ex: php) as virus or dangerous even if they&#8217;re not.  Of course it&#8217;s better to look at the script itself if you doubt the Kaspersky result.</p>
<p>This is also true with other antivirus suites.  Thanks for pointing this out!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Katrina</title>
		<link>http://linuxsysadminblog.com/2009/03/heurtrojanscriptiframe/comment-page-2/#comment-2484</link>
		<dc:creator>Katrina</dc:creator>
		<pubDate>Mon, 30 Jan 2012 06:24:25 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=432#comment-2484</guid>
		<description>@Gerald-Just because it pops up on Kaspersky doesn&#039;t always mean it&#039;s infected...Kaspersky will deny something and turn it into an Inactive virus. Kaspersky support provided the information with numerous screenshots.</description>
		<content:encoded><![CDATA[<p>@Gerald-Just because it pops up on Kaspersky doesn&#8217;t always mean it&#8217;s infected&#8230;Kaspersky will deny something and turn it into an Inactive virus. Kaspersky support provided the information with numerous screenshots.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alexander</title>
		<link>http://linuxsysadminblog.com/2009/03/heurtrojanscriptiframe/comment-page-2/#comment-2444</link>
		<dc:creator>Alexander</dc:creator>
		<pubDate>Wed, 04 Jan 2012 09:46:57 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=432#comment-2444</guid>
		<description>Hi there
Happy New Year
Are you offering a service to clean up some pages we run?
Greetings
Alexander</description>
		<content:encoded><![CDATA[<p>Hi there<br />
Happy New Year<br />
Are you offering a service to clean up some pages we run?<br />
Greetings<br />
Alexander</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: will</title>
		<link>http://linuxsysadminblog.com/2009/03/heurtrojanscriptiframe/comment-page-2/#comment-2391</link>
		<dc:creator>will</dc:creator>
		<pubDate>Tue, 22 Nov 2011 20:42:17 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=432#comment-2391</guid>
		<description>Removing some of this same virus...it seems to be old version of Wordpress with out of date timthumb.php which allows upload of .pl or .js files to the file_upload directory.  Once the script is uploaded, you can then write, change permissions, etc. which then leads to iframes etc.

Make sure to check all temp folders, image upload folders and remove any .pl or .js files in there.  Also check code in any .js files in a wordpress install as 99% of the time they are supposed to be php or have been added by an attacker.</description>
		<content:encoded><![CDATA[<p>Removing some of this same virus&#8230;it seems to be old version of WordPress with out of date timthumb.php which allows upload of .pl or .js files to the file_upload directory.  Once the script is uploaded, you can then write, change permissions, etc. which then leads to iframes etc.</p>
<p>Make sure to check all temp folders, image upload folders and remove any .pl or .js files in there.  Also check code in any .js files in a wordpress install as 99% of the time they are supposed to be php or have been added by an attacker.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wtf?</title>
		<link>http://linuxsysadminblog.com/2009/03/heurtrojanscriptiframe/comment-page-2/#comment-2374</link>
		<dc:creator>Wtf?</dc:creator>
		<pubDate>Tue, 01 Nov 2011 20:56:37 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=432#comment-2374</guid>
		<description>[...] HEUR:Trojan.Script.Iframe &#124; Linux Sysadmin Blog        Proud Member of Team.Fix-9000 Affiliate of Team Roma Founding Member of the former Team [...]</description>
		<content:encoded><![CDATA[<p>[...] HEUR:Trojan.Script.Iframe | Linux Sysadmin Blog        Proud Member of Team.Fix-9000 Affiliate of Team Roma Founding Member of the former Team [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam Saad</title>
		<link>http://linuxsysadminblog.com/2009/03/heurtrojanscriptiframe/comment-page-2/#comment-1327</link>
		<dc:creator>Adam Saad</dc:creator>
		<pubDate>Wed, 20 Oct 2010 13:18:01 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=432#comment-1327</guid>
		<description>Yes its great Adam is saying right this way hacker will keep attacking but your site will not be effected and that&#039;s all</description>
		<content:encoded><![CDATA[<p>Yes its great Adam is saying right this way hacker will keep attacking but your site will not be effected and that&#8217;s all</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam Saad</title>
		<link>http://linuxsysadminblog.com/2009/03/heurtrojanscriptiframe/comment-page-2/#comment-1326</link>
		<dc:creator>Adam Saad</dc:creator>
		<pubDate>Wed, 20 Oct 2010 13:16:18 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=432#comment-1326</guid>
		<description>Dear All Got the solution to the problem , just make a backup of the all index and login files and put a code to replace the file if there is any change in the code and you are done , now hacker can&#039;t do any thing any more</description>
		<content:encoded><![CDATA[<p>Dear All Got the solution to the problem , just make a backup of the all index and login files and put a code to replace the file if there is any change in the code and you are done , now hacker can&#8217;t do any thing any more</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ITRCP SOFT</title>
		<link>http://linuxsysadminblog.com/2009/03/heurtrojanscriptiframe/comment-page-2/#comment-1300</link>
		<dc:creator>ITRCP SOFT</dc:creator>
		<pubDate>Wed, 13 Oct 2010 14:26:19 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=432#comment-1300</guid>
		<description>Many of the website tells that its a virus infection but I think its the Code injection but need the solution to that how we can make our website secure from this code injection</description>
		<content:encoded><![CDATA[<p>Many of the website tells that its a virus infection but I think its the Code injection but need the solution to that how we can make our website secure from this code injection</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam Saad</title>
		<link>http://linuxsysadminblog.com/2009/03/heurtrojanscriptiframe/comment-page-2/#comment-1299</link>
		<dc:creator>Adam Saad</dc:creator>
		<pubDate>Wed, 13 Oct 2010 14:21:37 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=432#comment-1299</guid>
		<description>Hi all , 
I am also having the same problem with more than 10 of my site and the only solutions till now I found is manual removal of the code from html or php files , 

does any one have the Idea how to prevent this code injection ?</description>
		<content:encoded><![CDATA[<p>Hi all ,<br />
I am also having the same problem with more than 10 of my site and the only solutions till now I found is manual removal of the code from html or php files , </p>
<p>does any one have the Idea how to prevent this code injection ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: amrikarisma</title>
		<link>http://linuxsysadminblog.com/2009/03/heurtrojanscriptiframe/comment-page-2/#comment-1277</link>
		<dc:creator>amrikarisma</dc:creator>
		<pubDate>Tue, 28 Sep 2010 08:54:52 +0000</pubDate>
		<guid isPermaLink="false">http://linuxsysadminblog.com/?p=432#comment-1277</guid>
		<description>menakutkan,, but good posted. . . :D</description>
		<content:encoded><![CDATA[<p>menakutkan,, but good posted. . . <img src='http://linuxsysadminblog.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>

