How did I remove the iframe the hackers put on my index pages

… files that have body tags in them...  they can be both php or html files. the Commonality is that they contain a body tag, that looks like this <body> Sometimes after the <body there is other code, and then it closes with a > tag. It is still a starting body tag. this is (above) how a healthy file looks with body tag this is (above) how an infected file looks with body tag you need to delete the line that has the iframe tag <iframe src..to <iframe>. Third important …