Strange things appeared after you fixed site

Posted in: Newspaper
Post count: 7

Hi Carlos, did you do this on the admin side, when you made changes? (CapitalCityNews.online)

  • 3 new users appeared (see 2a.png below), and I can’t delete (see error msg screen grab – 3a.png).
  • 2 new plugins were added (see 1a.png below) that are not listed on WordPress plugin site.
  • Plus, now I cannot do maintenance (delete users, etc) — I get same error message as above.

Thanks for your help,
Dave

1a
2a
3a

Post count: 7

I have figured out one of these problems — the not being able to save anything. I had to go back to PHP 7.4 (down from 8.1). I can now save things.

BUT…my malware program has flagged these files (list below) from your TD Composer as MALWARE.

!…/capcitynews/wp-content/plugins/td-composer/assets/js/style.php
!…/capcitynews/wp-content/plugins/td-composer/css-live/assets/style.php
!…/capcitynews/wp-content/plugins/td-composer/css-live/assets/wCBsc
!…/capcitynews/wp-content/plugins/td-composer/css-live/includes/td_live_css_ajax.php
!…/capcitynews/wp-content/plugins/td-composer/td-multi-purpose/header/js.php
!…/capcitynews/wp-content/plugins/td-newsletter/viwphleq.php

Post count: 27744

Hello,

Unfortunately, our tagDiv team doesn’t have an employee named Carlos. From what I see there, that person has installed some malware plugins on your site, so you’ll need to manually clean the site. For example, you should delete plugins with strange or unknown names, remove any users you don’t recognize, and clean any suspicious code files, both in the theme and WordPress.
You could consider reinstalling the WordPress version, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins;
– Delete the weird/unknown themes;
– Clean unfamiliar Theme Panel injected code (example – https://i.imgur.com/4q70kCv.png);
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)
Please block /wp-json/tdw/save_css
If an attacker wants to target this URL /wp-json/tdw/save_css they can do so. Even if the website uses a different theme, the attacker can still try that URL. We could add an option to be able to enable/disable the Live CSS, it will be considered. But for now in order to remove it this can only be done with a modification to the composer plugin. I think that all that removing it requires is to comment this line of code – https://prnt.sc/RtwvL5Nc4ikR -> https://prnt.sc/ymZmhdUfp57U But as I mentioned, the attacker can still try to access the URL.

Thank you!

Post count: 7

Hi Anamaria, thank you for your information. I have done the steps you outlined, and will install Wordfence. Also, I think my computer auto-corrected my email…should have said Calin, not Carlos. It was Calin that had made changes to the site for it to look correct.

Again, thanks for your help!!
Dave

Post count: 27744

Hi,

Ok, but here is Carlos https://i.imgur.com/BRcHXOG.png
So, you solve it?

Thank you!

Post count: 7

Ah yes, that’s where I got “Carlos”. Yes, I deleted both of those. Thanks again for your help!!

Dave

Viewing 6 posts - 1 through 6 (of 6 total)
The forum ‘Newspaper’ is closed to new topics and replies.