My host is bringing up a malware detection for a file in the Newspaper theme.
I’m sure it’s nothing, but I need to get this sorted with them so the site won’t be taken down, which has happened to me before though on a different host.
Filename
MetaBox.php
/home/sites/14a/8/8d3f08f670/public_html/wp-content/plugins/td-composer/legacy/common/wp_booster/wp-admin/external/wpalchemy/MetaBox.php
Exploit Found
php.var.pattern
Hi,
I just done some scans in the theme files and there were no malware/virus detected.
Maybe there is a code that is detected that it can be a malware by the tool that your host is using. We’ll like to do some deep investigations if you agree. For this please contact us via email at contact@tagdiv.com and please provide wp-admin access.
We’ll check it as soon as possible.
Thank you!
Hi everyone,
I am having the same issue here, I just searched the forum for MetaBox.php and found this fresh thread.
My hosting is emailing me similarly to @joema, that their scan has found some infected file(s), together with the info I paste below:
File path
/home/umuseooc/public_html/wp-content/plugins/td-composer/legacy/common/wp_booster/wp-admin/external/wpalchemy/MetaBox.php
Firma antivirus (antivirus signature)
{HEX}Malware.Expert.php.var.pattern
Last modified (which dates back to when I installed the theme)
2022-06-20 17:38:59
Quarantined status
no (which means my hosting doesn’t consider it such an evil threat)
I would be very grateful if you could sort this out.
I am happy to provide wp-admin access if needed. Let me know.
Thank you
Paolo
Hi museooggi,
We made more investigations, also we tested with other tools like those:
-> https://www.virustotal.com/gui/home/upload
-> https://shellray.com/
But we do not find anything. Also, the theme package has been well reviewed by themeforest.
We can do some investigations on you install too, for this please contact us via email at contact@tagdiv.com
Thank you!
My hosting did a second scan and still got a positive. I put contact@tagdiv.com in cc in the mail thread.
Hello,
From the tests on the package that is on themeforest, I did not find any problems.
Now it is possible that the tool that you or your host uses is different and interprets certain structures as malware.
If you can give us more information, like what host you use and what tool was used, I will pass it on to the development team.
Thank you for your understanding!
I’ll have a word with the host and get back to you.
When doing a malware scan, it does say on there that they are checking it against known malware signatures, if that helps.
I have the theme on two sites on separate accounts with the same host, but only one shows as having malware (I just did a manual check) so that’s strange.
-
This reply was modified 3 years by
joema.
I received this form the host:
It’s possible that the theme itself is clean but one of its files has been infected within just this package. There are several reasons a website can become infected, with the most common being outdated or insecure plugins and themes.
I’ve run a scan and this is coming back as clean. Checking the latest scan showing as infected, it looks like the file in question is at:
/home/sites/14a/8/8d3f08f670/public_html/wp-content/plugins/td-composer/legacy/common/wp_booster/wp-admin/external/wpalchemy/MetaBox.php
I’ve checked this over for you and it doesn’t appear to be currently infected, so it’s possible that this was a false-positive or that the infection has been overwritten during an update. You may wish to send the contents of this file to the theme developers.
If you see further infection warnings, please let us know and we can have our malware specialist manually check this over to confirm if the warning is legitimate for you.
I hope that makes sense. Please let me know if you have any further questions.
Hi,
I understand, since you use the theme on two sites and the problem appears only on one of them, then it is possible that somehow malware has reached that site. In such situations, it is recommended to delete the theme and plugins from the there, download the theme from themeforest and reinstall it (the settings will not be lost because they are saved in the database).
I will also inform the developers, maybe I can do something to protect that file in the future.
Thank you!
Thank you for assistance.
Okay, here is what I tried, in sequence, but sadly it didn’t work…
1- deleted the theme and removed all plugins
2- ran a scan of the site and that came back clean
3- downloaded the theme full package from themeforest
4- uploaded it on the site and installed it again
5- ran the scan and found the same supposedly infected file
6- disabled and deleted the single plugin td-composer
7- ran the scan and it came back clean
8- manually uploaded the td-composer plugin from the one .zip file included in themeforest package and activated it
9- ran the scan and found the same supposedly infected file
10- deleted again the td-composer plugin
7- ran the scan and it came back clean
11- downloaded the td-composer plugin from within the theme’s plugins panel, hence straight from tagDiv cloud server.
12- ran the scan and found the same supposedly infected file
the scan returned the MetaBox.php file and virus signature {HEX}Malware.Expert.php.var.pattern.UNOFFICIAL
The tool I used is clam-av (the one available from my admin tools), the same my host uses.
I need the site running so for now I am just ignoring the file, I tried to quarantine it, but it breaks the site.
What would you recommend to do? Did I miss any step?
Honestly, I don’t know what to think…
@joema did you manage to get rid of your supposedly infected file?
thank you
@museooggi I didn’t fix it, but have ended up using another theme for the site, as I needed something that I could use to look like my whmcs site.
I’ll be using that one on a different domain though.
The strange thing is, whatever I did, it wasn’t fixed, but another site with the theme, on the same host, shows as clean.
Hi,
We made some search on google related to the ClamAV and it seems that there are many users reclaiming that the ClamAV that is providing false alarms.
-> https://www.bleepingcomputer.com/forums/t/640599/malware-found-using-clamav-but-not-by-malwarebytes-anti-malware/
Also, I informed the developers to check with that plugin and see if there is a problem or in in the theme files.
Hi anisimran, your website has been infected, and most probably the theme files too.
Please contact us via email at contact@tagdiv.com and we’ll help you to clean the website.
Thank you!