Hosting account malware check is showing a virus

Posted in: Newspaper
Post count: 38

My host is bringing up a malware detection for a file in the Newspaper theme.

I’m sure it’s nothing, but I need to get this sorted with them so the site won’t be taken down, which has happened to me before though on a different host.

Filename
MetaBox.php
/home/sites/14a/8/8d3f08f670/public_html/wp-content/plugins/td-composer/legacy/common/wp_booster/wp-admin/external/wpalchemy/MetaBox.php

Exploit Found
php.var.pattern

Post count: 35449

Hi,
I just done some scans in the theme files and there were no malware/virus detected.
Maybe there is a code that is detected that it can be a malware by the tool that your host is using. We’ll like to do some deep investigations if you agree. For this please contact us via email at contact@tagdiv.com and please provide wp-admin access.
We’ll check it as soon as possible.
Thank you!

Post count: 11

Hi everyone,
I am having the same issue here, I just searched the forum for MetaBox.php and found this fresh thread.
My hosting is emailing me similarly to @joema, that their scan has found some infected file(s), together with the info I paste below:

File path
/home/umuseooc/public_html/wp-content/plugins/td-composer/legacy/common/wp_booster/wp-admin/external/wpalchemy/MetaBox.php

Firma antivirus (antivirus signature)
{HEX}Malware.Expert.php.var.pattern

Last modified (which dates back to when I installed the theme)
2022-06-20 17:38:59

Quarantined status
no (which means my hosting doesn’t consider it such an evil threat)

I would be very grateful if you could sort this out.
I am happy to provide wp-admin access if needed. Let me know.

Thank you
Paolo

Post count: 35449

Hi museooggi,
We made more investigations, also we tested with other tools like those:
-> https://www.virustotal.com/gui/home/upload
-> https://shellray.com/
But we do not find anything. Also, the theme package has been well reviewed by themeforest.
We can do some investigations on you install too, for this please contact us via email at contact@tagdiv.com
Thank you!

Post count: 38

Is there something in the code with the same signature as a known virus?

Post count: 11

My hosting did a second scan and still got a positive. I put contact@tagdiv.com in cc in the mail thread.

Post count: 11

I’m no programmer but it would make sense. On my part I haven’t had a single problem in nearly 4 months of use and now this shows up out of nothing.

Post count: 35449

Hello,
From the tests on the package that is on themeforest, I did not find any problems.
Now it is possible that the tool that you or your host uses is different and interprets certain structures as malware.
If you can give us more information, like what host you use and what tool was used, I will pass it on to the development team.
Thank you for your understanding!

Post count: 38

I’ll have a word with the host and get back to you.

When doing a malware scan, it does say on there that they are checking it against known malware signatures, if that helps.

I have the theme on two sites on separate accounts with the same host, but only one shows as having malware (I just did a manual check) so that’s strange.

  • This reply was modified 3 years by joema.
Post count: 38

I received this form the host:

It’s possible that the theme itself is clean but one of its files has been infected within just this package. There are several reasons a website can become infected, with the most common being outdated or insecure plugins and themes.

I’ve run a scan and this is coming back as clean. Checking the latest scan showing as infected, it looks like the file in question is at:

/home/sites/14a/8/8d3f08f670/public_html/wp-content/plugins/td-composer/legacy/common/wp_booster/wp-admin/external/wpalchemy/MetaBox.php

I’ve checked this over for you and it doesn’t appear to be currently infected, so it’s possible that this was a false-positive or that the infection has been overwritten during an update. You may wish to send the contents of this file to the theme developers.

If you see further infection warnings, please let us know and we can have our malware specialist manually check this over to confirm if the warning is legitimate for you.

I hope that makes sense. Please let me know if you have any further questions.

Post count: 35449

Hi,
I understand, since you use the theme on two sites and the problem appears only on one of them, then it is possible that somehow malware has reached that site. In such situations, it is recommended to delete the theme and plugins from the there, download the theme from themeforest and reinstall it (the settings will not be lost because they are saved in the database).
I will also inform the developers, maybe I can do something to protect that file in the future.
Thank you!

Post count: 11

Thank you for assistance.

Okay, here is what I tried, in sequence, but sadly it didn’t work…

1- deleted the theme and removed all plugins

2- ran a scan of the site and that came back clean

3- downloaded the theme full package from themeforest

4- uploaded it on the site and installed it again

5- ran the scan and found the same supposedly infected file

6- disabled and deleted the single plugin td-composer

7- ran the scan and it came back clean

8- manually uploaded the td-composer plugin from the one .zip file included in themeforest package and activated it

9- ran the scan and found the same supposedly infected file

10- deleted again the td-composer plugin

7- ran the scan and it came back clean

11- downloaded the td-composer plugin from within the theme’s plugins panel, hence straight from tagDiv cloud server.

12- ran the scan and found the same supposedly infected file

the scan returned the MetaBox.php file and virus signature {HEX}Malware.Expert.php.var.pattern.UNOFFICIAL

The tool I used is clam-av (the one available from my admin tools), the same my host uses.

I need the site running so for now I am just ignoring the file, I tried to quarantine it, but it breaks the site.

What would you recommend to do? Did I miss any step?

Honestly, I don’t know what to think…


@joema
did you manage to get rid of your supposedly infected file?

thank you

Post count: 38

@museooggi I didn’t fix it, but have ended up using another theme for the site, as I needed something that I could use to look like my whmcs site.

I’ll be using that one on a different domain though.

The strange thing is, whatever I did, it wasn’t fixed, but another site with the theme, on the same host, shows as clean.

Post count: 35449

Hi,
We made some search on google related to the ClamAV and it seems that there are many users reclaiming that the ClamAV that is providing false alarms.
-> https://www.bleepingcomputer.com/forums/t/640599/malware-found-using-clamav-but-not-by-malwarebytes-anti-malware/
Also, I informed the developers to check with that plugin and see if there is a problem or in in the theme files.

Post count: 3

Hello, When I activate the Composer plugin my site redirects to another URL. And when I deactivate the TagDiv_Composer plugin it stops redirecting to another URL. Please help me with it.

  • This reply was modified 3 years by anisimran.
Post count: 35449

Hi anisimran, your website has been infected, and most probably the theme files too.
Please contact us via email at contact@tagdiv.com and we’ll help you to clean the website.
Thank you!

Post count: 3

I already have sent a message there along with the details, but no reply. And the hacker is eating my website

Post count: 35449

Hi anisimran, I’m sure that one of my colleagues answered and solved the problem until now.
Thank you!

Post count: 3

Yeah, Thanks really much my problem is now solved!

Viewing 19 posts - 1 through 19 (of 19 total)
The forum ‘Newspaper’ is closed to new topics and replies.