1, Check that there are no unfamiliar admins
2, Check Control panel log for unfamiliar activity
If no & no, probably safe,
If yes:
1, Ban the user & their IP (Need to get the IP from the CP Logs)
2, Delete the /install folder
3, Search templates for "biz", "derpina" & "iframe". Delete any unfamiliar.
4, Look in all your header templates at the bottom for a weird huge script, if there, delete it.
5, Check plugin manager, look at top for a script called "init_startup" delete it.
Lastly probably pays to upgrade/Reinstall all your VB files to ensure no other scripts that have not been found are still lurking.
I did another test, this time disabling my ad blocker. Using Firefox's "Save page" feature, which has an option to save all content (HTML, CSS, images, javascript, etc), I looked through the resulting file set for "iframe" and found only two references, neither out of the ordinary: one in a Yahoo javascript library, and the other in Google Analytics code.For the forum admins,
This has been a known problem on vBulletin (which I believe is the software this forum is running on). It can mean that some header templates have been hacked, and "iframes" with potentially malicious URLs may have been installed.
<snip>