Hello,
when I want to share an article on facebook, I get this:

I have disabled all plugins, deleted the cache of my browser, I even launched ccleaner and restarted my computer. I always have this message displayed before the description of my article.
Thank you in advance for your help.
When I am connected I do not see anything in the source code of the page, but once logged out of my blog, so as a visitor, I see this:
<div class="tdc-content-wrap">
<div style="position:absolute;top:0;left:-9999px;">Want create site? Find Free WordPress Themes and plugins.</div>
Well, after hours of research, I found some leads. I hope to retrieve my blog as it was before!
I will detail my research and hope you can tell me if my research is sufficient.
1-
in the wp-includes folder, I have 3 more files than in version 4.8.2 of wordpress (I put its files online in version .txt)
wp-includes/class.wp.php ==> click here
wp-includes/wp-vcd.php ==> click here
wp-includes/wp-feed.php ==> click here
I do not know the coder language but I think I understood that its files try to create a user in my database with administrator rights and then insert code into my themes files. am I right ?
I can delete the 2 users registered on my blog and I checked my database in the table users and usermeta, I think it is good. I think ….
To search further, I installed the Quttera Web Malware Scanner plugin and I performed an internal scan of the entire blog. in addition to its 3 files it tells me that there are other suspicious files (I also join them as a precaution):
/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/td_view_update_newspaper_6.php ==> click here
Severity: enMaliciousThreatType
File: /wp-content/themes/Newsp/.../td_view_update_newspaper_6.php
File signature: 814e64bc5a2f806f056be20e6426d120
Threat signature: 9632714c466ed4838165e9057dfb18c5
Threat: <?php if (empty(
Details: Malicious PHP Script
/wp-content/themes/Newspaper/js/tagdiv_theme.js ==> click here
Severity: enPotentiallySuspiciousThreatType
File: /wp-content/themes/Newspaper/js/tagdiv_theme.js
File signature: 6de7782788357b741a2703a368cf4f0a
Threat signature: dce48b63cbaf409a3bd5edb9042e7628
Threat: 'Y-m-d\\TH:i:sP'.rep
Details: Suspicious obfuscated JavaScript threat
After all his research and removal / replacement of infected files, I still get this message:

I have just seen that I also have this code in my page as a visitor:
<div style="position:absolute;top:0;left:-9999px;">Did you find apk for android? You can find new Free Android Games and apps.</div>
Please help me …
Hi Guims!
If you have suspicions that your site is hacked, read carefully (!) these sections of the forum:
https://forum.tagdiv.com/topic/traffictrade-malware-newspaper-8-1-all-updated/
https://forum.tagdiv.com/topic/when-the-theme-is-activated-redirecting-to-other-sites-from-the-home/
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/
Also:
http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/
Looks like site may have been hacked. See my [tutorial] post on securing and fixing your site asap
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/
Hello,
First of all, thank you for your help. I did not manage to remove the malware so I reinstalled a blog all clean and I followed your security tips for wordpress blog. now I would like to know if it is possible to scan the zip file of a plugin before sending it in my administration? Before I install it.
Thank you in advance for your answer.
Hello, I do not talk about the theme but plugins that I will add on my blog. Is the “total virus” site suitable for scanning malware?
on the other hand, my blog is reinstalled, I added some plugins that come from the wordpress repository, but when I do a scan of my blog on sucuri with https://bpe.fun, it tells me that my blog has a malware and if I do a scan with https://bpe.fun/ it tells me everything is fine.
I do not understand …
You need to do all the steps in my security post, as even re-installing your theme and WP might not remove items in your ad boxes in theme panel, or in dbase. Those will still be there, so you need to do *all* the items from my post, or similar ones to ‘clean’ your site.
The theme itself has no malware. Your site itself has malware due to a bug in either older version of theme and/or insecure versions of WordPress core. So, when theme and WP not updated for security fix this allows your site, and possibly database to be hacked with malware.
Items in your database are not part of the theme files you download from ThemeForest.
I followed your topic … really
I reinstalled a blank wordpress with the latest version 4.8.2, then I inserted your theme on it, I resumed everything, because with what you gave me I could not do anything, I always had the malware in my blog, so I started everything again, my blog was very small so it was much faster, with what you gave me I spent more than 15h trying to remove the malwares, without any result, but what I say about my previous message today is for a blank version of my blog
is it possible that sucuri guard does not remember the scan of the day since my blog?
So, you checked ALL your theme panel settings for errant items inserted into boxes?
You checked your database with either a dbase plugin or via phpMyAdmin in your hosting panel?
Delete all old themes and plugins not being used?
Checked your website via FTP for any errant plugins or files?
Checked your htaccess file for any weird redirects?
You changed all your passwords for hosting, site, superuser?
Made backup via phpMyAdmin of your MySQL dbase for safe keeping?
Only you can fix your site. Or hire somebody.
Good luck!
(I don’t work here.)
Hello Chris S, 🙂
As I said above, I reinstalled a wordpress all clean, I then add the theme I downloaded from envato and then I added my plugins one by one (I scanned all these plugins on virustotal to be sure that there is no malware). And I see that today sucuri tells me that all is well! Coool ^^.
I think he had to remember my previous scan.
Otherwise I followed your topic on secure wordpress:
– I changed all my passwords by putting very strong passwords for my FTP account, my database and of course my wordpress account.
– During the wordpress installation all clean, I changed the table prefix which was wp_, which I think too sensitive. So I put 15 characters (uppercase, lowercase and number) before the “_”.
– I deleted ALL the plugins and theme that I do not use.
– I added a plugin that backs up my database and my ftp every day, and that sends it to me on drobox and a remote ftp.
– I also have a plugin that automatically updates ALL plugins updated if necessary.
– This morning I added a plugin named “WP Cerber”, which protects me well wordpress and blocked me attempts to intusions (131 ip blocked trying to access my wp-login page when I disabled it)
– I also have the plugin Shield Security, do you think there would be conflict in both ???
I think now I’m secure, what do you think?
I really want to thank you for the help you have been able to bring me
So, you did not do a search of your theme panel ad boxes, and other boxes?
So, you did not do search/replace in your dbase for infection?
You need to to those FIRST to fix an infected site. Without that, infection is still there as it’s in dbase NOT the files themselves!