How to Remove Androidczad.info Malware from Your Website

A few weeks back one of my website were attacked by a malware called Androidczad.info. The infected site were blocked by Google and warned visitors to stay away from the website. The site was temporarily blocklisted by Google until I resolve the problem. I can't really tell how and when my site got infected, but I suspected an infected image that I might have uploaded to my server when I perform the FTP. I never have thought that I could have malware in my computer.


What I first did was scanned my entire computer with the latest update of antivirus database. I used the updated AVG and Super Antispyware program to scanned the entire computer. It found some suspected malwares but it didn't seem to show that Androidczad.info as the culprit. It feels so frustrating when you don't know what causes the problem. But I continued to investigate.

The next thing I did was scanned my website using an online web scanner called SUCURI  - its a useful tool to scanned malicious program in your website. It's easy to use but unfortunately, the free service doesn't give you the ability to remove the malware. Still it is helpful in locating the source of the malware in your server. It tells you where and what parts of your website are infected. For me its save me time because you know where to start looking.


I did found a simple piece of code embedded the index file: Checkout the screenshot below. Please click the image to zoom.


You'll see at the bottom of the page an iframe tag with the androidczad .info as source. That's what cause my site to be blocklisted for days. I finally figured it out and have deleted it.

So to remove the androidczad.info malware in your website files, simply delete the piece of code from the beginning of the <iframe> to </iframe> tag. Everything inside of that tag must be deleted.



Next scan again your website using SUCURI website scanner and check for files that might have been infected. If it finds another malware, then go over to that file and remove that code.

If SUCURI does not find any malwares anymore, then request Google team to review your site. It usually takes a few days to get your site back to normal and remove from being blocklisted.


I hope this article help you in removing the malware that cause your website blocklisted.

Does your website also infected by Malware? Tell me your experience.

0 comments:

Post a Comment

Twitter Delicious Facebook Digg Stumbleupon Favorites More