I received this mail from the server, i scan with avast the newspaper.zip but is clean:
El dominio xxxxxx ha subido ficheros desde ES con la IP 181.xxx.xxx.xxx. ste es el fichero:
/furanet/sites/xxxxxx/web/htdocs/wp-content/themes/Newspaper/includes/wp_booster/external/td-old-class-tgm-plugin-activation.php
El BS lo detecta como malicioso por:
POSITIVO en (“php shell”|Locus7s|”c100 shell”|emp3ror|afe0ver|M4il3r|T3MPL3|N3tsh|FilesMan|kebsyno|DEFAULT_DIR_DEEP_BACK|system_custom\()|By POKAMOM|jewsforjudaismg|r0nin|m0rtix|upl0ad|r57shell|c99shell|shellbot|phpshell|phpremoteview|directmail|bash_history|multiviews|cwings|vandal|bitchx|eggdrop|guardservices|psybnc|dalnet|undernet|vulnscan|spymeta|raslan58|Webshell|FilesTools|bckdrprm|hackmeplz|wrgggthhd|Arhack\.Net|WSOsetcookie|”By HasnZin”|”[S]uper[BAD] Mailer”|_GET[w….t]|aHR0cDovL21icm93c2Vyc3RhdHMuY29tL3N0YXRIL3N0YXQucGhw|”HighTech Brazil HackTeam
Que alegria escuchar español jejeje, gracias por el consejo, he borrado todo por completo y volvi a subirlo, y me llegan dos emails del servidor por estos dos archivos:
El dominio xxxxxx ha subido ficheros desde ES con la IP 181.xxxxxx Este es el fichero:
– web/htdocs/wp-content/themes/Newspaper/Newspaper/includes/wp_booster/external/td-old-class-tgm-plugin-activation.php
– web/htdocs/wp-content/themes/Newspaper/Newspaper/includes/wp_booster/external/class-tgm-plugin-activation.php
En cada uno pone lo mismo:
El BS lo detecta como malicioso por:
POSITIVO en (“php shell”|Locus7s|”c100 shell”|emp3ror|afe0ver|M4il3r|T3MPL3|N3tsh|FilesMan|kebsyno|DEFAULT_DIR_DEEP_BACK|system_custom\()|By POKAMOM|jewsforjudaismg|r0nin|m0rtix|upl0ad|r57shell|c99shell|shellbot|phpshell|phpremoteview|directmail|bash_history|multiviews|cwings|vandal|bitchx|eggdrop|guardservices|psybnc|dalnet|undernet|vulnscan|spymeta|raslan58|Webshell|FilesTools|bckdrprm|hackmeplz|wrgggthhd|Arhack\.Net|WSOsetcookie|”By HasnZin”|”[S]uper[BAD] Mailer”|_GET[w….t]|aHR0cDovL21icm93c2Vyc3RhdHMuY29tL3N0YXRIL3N0YXQucGhw|”HighTech Brazil HackTeam”
Tenga en cuenta que es posible que sea un falso positivo. Es posible que alguna cadena usada en su fichero coincida con una cadena usada por Malware. Por este motivo si despues de revisar su codigo considera que es correcto, no es necesario que realice nada, ya que este correo es para avisarle de un posible peligro, pero no bloquea o elimina ningun fichero.
He echado un ojo a los archivos que dice pero mis conocimientos de php son casi nulos 🙁
Gracias por la ayuda por cierto!!
sorry, I reupload and revised the both files:
– web/htdocs/wp-content/themes/Newspaper/Newspaper/includes/wp_booster/external/td-old-class-tgm-plugin-activation.php
– web/htdocs/wp-content/themes/Newspaper/Newspaper/includes/wp_booster/external/class-tgm-plugin-activation.php
But my php not good enough to know if is a false positive or not 🙁
Remember when updating to DELETE old theme and TD plugins, and upload NEW theme and plugins; including NEW child theme if you use one!
Try using my sticky upgrade guide or you may be sorry.
It’s a new version of theme; you may need to redo your home page for some modules, and reset sidebars.
It’s an UPGRADE not an update.
