Posted on May 21, 2010 - by CDS, 4 Comments
Fix for HolasionWeb WordPress GoDaddy Virus
If you have a WordPress app version 2.9.2 hosted by GoDaddy, and have been experiencing issues lately, there’s a good chance you have the HolasionWeb Virus. To check, log into the WordPress admin. The first thing you might notice is that your admin panel may be all screwed up and look something like this:
If you’re seeing something like this, you probably have the virus associated with holasionweb.com (don’t go to this website, it is not safe). The virus plants a javascript from the holasionweb.com website in either the header or footer of your WordPress admin. Although the virus so far doesn’t appear to do much besides screw up your admin interface, it is still an alarming breach that should be handled immediately. Also note that if you are using a blog feed application, such as SimplePie, it will likely cause your feed to disappear completely. That is exactly what led to the discovery of this virus running on a clients website today.
How to Get Rid of holasionweb.com Infection
First thing, re-upload your wp-admin and wp-includes folders. This will fix your admin interface issues, but will not get rid of the virus. To get rid of it, I found this handy little program by http://www.sucuri.net (via http://www.dlocc.com) that effectively removes the malware.
- Download the HolasionWeb Script Fix
- Unzip and upload wordpress-fix.php to your WordPress directory.
- Run the script by going to http://www.YourSite.com/wordpress-fix.php (note that if your blog is in a subdirectory, you would navigate to http://www.YourSite.com/subdirectory/wordpress-fix.php)
- The detection and removal should take a few moments, and you will see the progress detailed on the page.
Here’s a link to the original solution: http://blog.sucuri.net/2010/05/simple-cleanup-solution-for-latest.html
Hope that works for you and Happy Blogging!
4 Comments
We'd love to hear yours!
Leave a Reply
Here's your chance to speak.


Visit My Website
May 27, 2010
Permalink
VBSCRIPT said:
Thank you for that I had this virus too. I found the scripts in my wordpress footer but could not get rid of it and this php script fixed it. Also it only affects v 2.9.2 I read somewhere.
Visit My Website
June 12, 2010
Permalink
Audopilit said:
Wow that sucks! I thought godaddy was one of the more secure hosts. But I guess not!
Visit My Website
December 10, 2010
Permalink
Prakash said:
It sounds great & it would be more helpful for the people who were using the wordpress solution to fix the virus.
Thank you so much for sharing this idea. Keep posting good things always.
Visit My Website
June 18, 2011
Permalink
Ashton Kubecka said:
Hello! I assume using too many figures in meta tags in HTML computer code as well as including too a lot of keywords and phrases in the internet site’s content are the most indecent SEO strategies.