MALWARE IN THEME_OPTIONS_NAME 'TD_011'

Posted in: Newsmag
Post count: 3

Hello,

On my website, I have a malware with redirection to advertising pages.
Wordfence tell me that I have in the theme/template options at line ‘ td_011 ‘ the following virus link: js.givemealetter.biz

I think … I have to find this line to erase this spurious address.

Have you ever encountered the same problem?

Where I need to go to find precisely this line ‘ td_011 ‘ ?

There I am stuck!

I have this problem on two websites that relate to NewsPaper7.
I still have two other sites with this same template.
And I have two other websites waiting.

So big problem.

help me !

Post count: 9544
Post count: 9544
Post count: 23312

Hi,

Please note that the theme has to be updated along with WordPress and plugins. Old versions can have security breaches and these can be exploited by different tools.

The old version from prior to April 2016 had a security issue which was patched in 6.7.2. Similarly, WordPress prior to 4.7 is insecure.

Please make sure you update your theme, plugins, and WordPress and do not stick to old versions.

If you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:

http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/

Here is a link for best WordPress security practices created by Chris S:

https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

Thank you!

Post count: 7

I just had the same problem. I have solved it by deleting javascript code fragments in the following theme options: Theme Panel> Ad> Header Ad
Theme Panel> Custom Code> Custom Javascript

You must also delete all the contents of the Cache (WP Super Cache or W3 Cache or similar)

This malwere came with the latest update of the theme Newsmag and Newspaper in the month of July / August

Post count: 9544

Malware was not in current version of theme — a ‘vulnerability’ was in old version. Two totally different things. Legal copy of theme has no malware or it wouldn’t be uploaded onto ThemeForest which checks/approves everything after TagDiv does.

For those who didn’t update the theme on time, or who ‘copied’ theme files on top of old files vs proper upgrade method (proper upgrade is DELETE old folder, upload NEW one), you might have been at risk. Much like running OLD version of WP, would get you hacked as well.

BE SURE TO READ:
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

  • This reply was modified 8 years by simchris.
Viewing 6 posts - 1 through 6 (of 6 total)
The forum ‘Newsmag’ is closed to new topics and replies.