1 jacquesjeanjean Dec 09, 2012 22:47
3 sam2kb Dec 10, 2012 20:25
Your website is hacked. Either your browser or some kind of a script on your website injects iframes with the link to
http://pe revod.me/sts/sTDS/got.php?sid=1
It's a fishing URL
I recommend you to scan your computer for viruses. Ask hosting support to scan your files for backdoor scripts. Change hosting account password, change FTP & MySQL passwords. Re-upload fresh b2evolution files and use your existing database.
Also go into phpMyAdmin and search b2evolution table evo_items__item for the "iframe" keyword, examine all rows with this tag.
4 jacquesjeanjean Dec 11, 2012 09:50
Thks, will try to proceed as suggested and readvise.
5 jacquesjeanjean Dec 12, 2012 10:47
Done as suggested, found hundred+ occurences of the phishing URL with the help of the guies from bluehost. Most of them in the B2evo php files but not only. Didn't find anything in phpMyAdmin. Have reloaded clean set of b2evo 4.1.6 and cleaned manually remaining files. Also Changed all access passwords and scanned my drives and everything is back to normal. Thanks indeed for your support, season greetings,
Jacques
6 sam2kb Dec 12, 2012 16:25
No problem ;)
Well, that particular post you're trying to edit must have an iframe. Other posts probably don't have an iframe.
I believe it has nothing to do with 4.1.6.