Search Results for 'Malware'

    No search results were found in Documentation!

Results from the Forum
mgiannelis
tagDiv Member

Please review the following warnings found in Ninja Scanner plugin – File version change (about the same time I stared having the bad issues with site not loading from google search if I turn off litespeed “Guest Mode”

https://imgur.com/a/HTswbOa

Note. Before blaming or ponting this to virus just because I mentioned a virus scanner. Wordfence, Malcare, Ninja scanner, and cpanel mod sec and cpanel virus scans all show clean. No malware or infections

Anamaria
tagDiv Staff

Hello,

Seems you have malware on the website. This means that someone has access to your website, I suggest installing a security plugin as soon as possible, if you haven’t already.
My suggestion is to check those articles and clear the hack code and secure the website:
-> How to Scan Your WordPress Site for Potentially Malicious Code
– WordPress Malware Redirect Hack – How To Fix Guide [2022]
– WordPress Hacked Redirect? How To Clean Website Redirect Malware

I hope this will help you!

Thank you!

Gen Fujiwara
tagDiv Member

I’ve discovered a new problem and haven’t reported it yet.
My website has been hacked and is currently infected with malware. (Will be deleted soon)

Currently infected are: (some are hidden)
1.
/home/ba●●●●/public_html/blog/wp-content/plugins/td-composer/legacy/common/wp_booster/wp-admin/wp-admin/ijckTyKwdJa.wav

2.
/home/ba●●●●/public_html/blog/wp-content/uploads/revslider/templates/landing-page-call-to-action/landing-page-call-to-action/SKTuvdzixjkJXoL.mp4

3.
/home/ba●●●●/public_html/blog/wp-content/uploads/revslider/templates/clear-view-single-menu/clear-view-single-menu/CIMgT.mov

4.
/home/ba●●●●/public_html/blog/wp-content/uploads/2022/08/08/C.bmp

Maybe this is the reason for this error? “Or is it irrelevant?”

Calin
tagDiv Staff

Hi,
We made some search on google related to the ClamAV and it seems that there are many users reclaiming that the ClamAV that is providing false alarms.
-> https://www.bleepingcomputer.com/forums/t/640599/malware-found-using-clamav-but-not-by-malwarebytes-anti-malware/
Also, I informed the developers to check with that plugin and see if there is a problem or in in the theme files.

museooggi
tagDiv Member

Thank you for assistance.

Okay, here is what I tried, in sequence, but sadly it didn’t work…

1- deleted the theme and removed all plugins

2- ran a scan of the site and that came back clean

3- downloaded the theme full package from themeforest

4- uploaded it on the site and installed it again

5- ran the scan and found the same supposedly infected file

6- disabled and deleted the single plugin td-composer

7- ran the scan and it came back clean

8- manually uploaded the td-composer plugin from the one .zip file included in themeforest package and activated it

9- ran the scan and found the same supposedly infected file

10- deleted again the td-composer plugin

7- ran the scan and it came back clean

11- downloaded the td-composer plugin from within the theme’s plugins panel, hence straight from tagDiv cloud server.

12- ran the scan and found the same supposedly infected file

the scan returned the MetaBox.php file and virus signature {HEX}Malware.Expert.php.var.pattern.UNOFFICIAL

The tool I used is clam-av (the one available from my admin tools), the same my host uses.

I need the site running so for now I am just ignoring the file, I tried to quarantine it, but it breaks the site.

What would you recommend to do? Did I miss any step?

Honestly, I don’t know what to think…


@joema
did you manage to get rid of your supposedly infected file?

thank you

Calin
tagDiv Staff

Hi,
I understand, since you use the theme on two sites and the problem appears only on one of them, then it is possible that somehow malware has reached that site. In such situations, it is recommended to delete the theme and plugins from the there, download the theme from themeforest and reinstall it (the settings will not be lost because they are saved in the database).
I will also inform the developers, maybe I can do something to protect that file in the future.
Thank you!

joema
tagDiv Member

I received this form the host:

It’s possible that the theme itself is clean but one of its files has been infected within just this package. There are several reasons a website can become infected, with the most common being outdated or insecure plugins and themes.

I’ve run a scan and this is coming back as clean. Checking the latest scan showing as infected, it looks like the file in question is at:

/home/sites/14a/8/8d3f08f670/public_html/wp-content/plugins/td-composer/legacy/common/wp_booster/wp-admin/external/wpalchemy/MetaBox.php

I’ve checked this over for you and it doesn’t appear to be currently infected, so it’s possible that this was a false-positive or that the infection has been overwritten during an update. You may wish to send the contents of this file to the theme developers.

If you see further infection warnings, please let us know and we can have our malware specialist manually check this over to confirm if the warning is legitimate for you.

I hope that makes sense. Please let me know if you have any further questions.

joema
tagDiv Member

I’ll have a word with the host and get back to you.

When doing a malware scan, it does say on there that they are checking it against known malware signatures, if that helps.

I have the theme on two sites on separate accounts with the same host, but only one shows as having malware (I just did a manual check) so that’s strange.

  • This reply was modified 3 years by joema.
Calin
tagDiv Staff

Hello,
From the tests on the package that is on themeforest, I did not find any problems.
Now it is possible that the tool that you or your host uses is different and interprets certain structures as malware.
If you can give us more information, like what host you use and what tool was used, I will pass it on to the development team.
Thank you for your understanding!

museooggi
tagDiv Member

Hi everyone,
I am having the same issue here, I just searched the forum for MetaBox.php and found this fresh thread.
My hosting is emailing me similarly to @joema, that their scan has found some infected file(s), together with the info I paste below:

File path
/home/umuseooc/public_html/wp-content/plugins/td-composer/legacy/common/wp_booster/wp-admin/external/wpalchemy/MetaBox.php

Firma antivirus (antivirus signature)
{HEX}Malware.Expert.php.var.pattern

Last modified (which dates back to when I installed the theme)
2022-06-20 17:38:59

Quarantined status
no (which means my hosting doesn’t consider it such an evil threat)

I would be very grateful if you could sort this out.
I am happy to provide wp-admin access if needed. Let me know.

Thank you
Paolo

Calin
tagDiv Staff

Hi,
I just done some scans in the theme files and there were no malware/virus detected.
Maybe there is a code that is detected that it can be a malware by the tool that your host is using. We’ll like to do some deep investigations if you agree. For this please contact us via email at contact@tagdiv.com and please provide wp-admin access.
We’ll check it as soon as possible.
Thank you!

joema
Participant
#0

My host is bringing up a malware detection for a file in the Newspaper theme.

I’m sure it’s nothing, but I need to get this sorted with them so the site won’t be taken down, which has happened to me before though on a different host.

Filename
MetaBox.php
/home/sites/14a/8/8d3f08f670/public_html/wp-content/plugins/td-composer/legacy/common/wp_booster/wp-admin/external/wpalchemy/MetaBox.php

Exploit Found
php.var.pattern

Simion C.
tagDiv Staff

Hi,

That is the live CSS option -> https://prnt.sc/jTNj90DpZ-L4 Please check there.

I believe that is where the malware code is entered. This means that someone has access to your website, I suggest installing a security plugin as soon as possible, if you haven’t already.

Thank you!

viipale
Participant
#0

Hi, I have one site that has malware placed into this position:
“<style id=”tdw-css-placeholder”></style>”malware js code here“</head>”
Any ideas how to locate where it is coming from? Tried look everywhere, but can not locate the source where it is.

Calin
tagDiv Staff

Hi salty, I saw this, even today when I accessed the link the first time I was redirected to this link -> xcebph.snowfalltwenty.top/ but those are redirections are not normal and a malware or a code injected can be programed how to affect the website.
Also, I suggest to ash your host for help too.
Thank you!

Calin
tagDiv Staff

Hi salty,
Indeed so it looks that is acting. Most of the time when this is happened is a code that has been injected in the WordPress.
My suggestion is to check those articles and clear the hack code and secure the website:
WordPress Malware Redirect Hack – How To Fix Guide [2022]
WordPress Hacked Redirect? How To Clean Website Redirect Malware
I hope this will help you!

Calin
tagDiv Staff

Hello,
Normally the .htaccess file is generated by WordPress, but it can be injected with extra code using functions, plugins, malwares. So if you have those kind of problems it will be better to ask your host about the security that they provide for your website and how to prevent this kind of situations.
Also, maybe those articles can help you:
How to Scan WordPress for Malware in 4 Easy Steps
How to Scan Your WordPress Site for Potentially Malicious Code
Thank you!

Calin
tagDiv Staff

Hi,
It is possible to me a code that is injected in .htaccess and this provide this problem.
The code can be from a plugin or it can be a malware injection.
Also, please check this article https://wpbrainery.com/wordpress/how-to-fix-a-corrupted-htaccess-file/
I hope this will help you!

Bettina
tagDiv Staff

Hello!

Other users have reported also this issue. Please check this article: https://www.getastra.com/blog/911/japanese-keyword-hack/
Also, I recommend you to check and clean your files: https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
After that, you should reinstall everything, starting with the WordPress, theme, plugins so that it will be a clean install.

Thank you!

Bettina
tagDiv Staff

Hello!

Please check this article: https://www.getastra.com/blog/911/japanese-keyword-hack/
Also, I recommend you to check and clean your files: https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
After that, you should reinstall everything, starting with the WordPress, theme, plugins so that it will be a clean install.

Thank you!

itgrcapitallink
Participant
#0

I have dev server and have been attack with malware.
I delete the whole files that have been affected.

When the td composer was enabled I get this error
Parse error: syntax error, unexpected ‘?’ in /home/xxxxx/public_html/xxxx/wp-content/plugins/td-composer/legacy/Newspaper/includes/td_config.php on line 33408

The same error displayed when I delete the td composer and install it again.

Do you know why?

Thank you!

underwooddesign
tagDiv Member

Calin,

Thanks for your prompt reply! We indeed did receive a pop-up message as the demo content installation status showed complete – see below:

rtbuild.underwood-design.com says

tagDiv Importer detexts that your server is not properly configured.
Don’t worry, the importer will continue to install the demo after you click the OK button.

Steps to verify:
– Please go to the SYSTEM STATUS tab and check if all parameters are gree – Verify the permissions on your upload folder
– Contact our support via email contact@tagdiv.com (please provide your product license key)

We have checked the System Status portion of the theme, but are showing no yellow (all green unless grayed out with “i”).

Other than WordFence and some malware protection plugins (in addition to those loaded by the them), this is a fresh build.

theoccidental
Participant
#0

Hello,

After Godaddy removed malware from my website, I became unable to access the Wp-Admin page. I called Godaddy and that informed me that this was, in fact, a theme issue. Here is an image of the error I am getting on my Wp-Admin page:

Warning: include_once(/home/occidentalweekly/public_html/wp-content/themes/Newspaper5745747/includes/wp_booster/wp-admin/external/wpalchemy/MetaBox.php): failed to open stream: No such file or directory in /home/occidentalweekly/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/content-metaboxes/td_templates_settings.php on line 3

Warning: include_once(): Failed opening '/home/occidentalweekly/public_html/wp-content/themes/Newspaper5745747/includes/wp_booster/wp-admin/external/wpalchemy/MetaBox.php' for inclusion (include_path='.:/opt/alt/php73/usr/share/pear') in /home/occidentalweekly/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/content-metaboxes/td_templates_settings.php on line 3

Fatal error: Uncaught Error: Class 'WPAlchemy_MetaBox' not found in /home/occidentalweekly/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/content-metaboxes/td_templates_settings.php:13 Stack trace: #0 /home/occidentalweekly/public_html/wp-includes/class-wp-hook.php(286): td_register_post_metaboxes('') #1 /home/occidentalweekly/public_html/wp-includes/class-wp-hook.php(310): WP_Hook->apply_filters(NULL, Array) #2 /home/occidentalweekly/public_html/wp-includes/plugin.php(465): WP_Hook->do_action(Array) #3 /home/occidentalweekly/public_html/wp-settings.php(525): do_action('init') #4 /home/occidentalweekly/public_html/wp-config.php(107): require_once('/home/occidenta...') #5 /home/occidentalweekly/public_html/wp-load.php(37): require_once('/home/occidenta...') #6 /home/occidentalweekly/public_html/wp-admin/admin.php(34): require_once('/home/occidenta...') #7 /home/occidentalweekly/public_html/wp-admin/index.php(10): require_once('/home/occidenta...') #8 {main} thrown in /home/occidentalweekly/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/content-metaboxes/td_templates_settings.php on line 13

The site is experiencing technical difficulties. Please check your site admin email inbox for instructions.

Bettina
tagDiv Staff

Hello Marco!

I’m sorry to hear that your website has been attacked. I can recommend you some tips, please check this topic: https://forum.tagdiv.com/topic/hacking-issues-with-version-11-2/
Also, I recommend you to check and clean your files: https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
After that, you should reinstall everything, starting with the WordPress, theme, plugins so that it will be a clean install.

Thank you!

luki1680
tagDiv Member

Such a function is unacceptable. This is malware and breaking the law. I bought your theme and can even cut it off from your servers. It was invented by a total moron.
Please let me know when this feature will be removed from the theme.

Viewing 25 results - 326 through 350 (of 681 total)