Search Results for 'Malware'

    No search results were found in Documentation!

Results from the Forum
Guims
tagDiv Member

Hello, I do not talk about the theme but plugins that I will add on my blog. Is the “total virus” site suitable for scanning malware?

on the other hand, my blog is reinstalled, I added some plugins that come from the wordpress repository, but when I do a scan of my blog on sucuri with https://bpe.fun, it tells me that my blog has a malware and if I do a scan with https://bpe.fun/ it tells me everything is fine.
I do not understand …

Guims
tagDiv Member

Hello,

First of all, thank you for your help. I did not manage to remove the malware so I reinstalled a blog all clean and I followed your security tips for wordpress blog. now I would like to know if it is possible to scan the zip file of a plugin before sending it in my administration? Before I install it.

Thank you in advance for your answer.

Catalin
tagDiv Staff

Hello,

Please note that the theme has to be updated along with WordPress and plugins. Old versions can have security breaches and these can be exploited by different tools.

The old version from prior to April 2016 had a security issue which was patched in 6.7.2. Similarly, WordPress prior to 4.7 is insecure.

Please make sure you update your theme, plugins, and WordPress and do not stick to old versions.

If you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:

http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/

Here is a link for best WordPress security practices created by Chris S:

https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

Thank you!

ReyLagarto
Participant
#0

Hi, anyone suffers like me attacks to his site?!
I’ve Newspaper 8.1 and WordPress 4.8.2 –> http://novedadesdeloeste.com

– I installed and configure iThemes Security
– I protected the folders wp-admin and wp-includes with password (via Cpanel)
– I banned all the IPS from USA via .htaccess
Any suggestion?!

The following files are modified by this malware/virus
wp-includes/script-loader.php
wp-includes/version.php
wp-includes/wp-db.php
wp-includes/class-wp-customize-manager.php
wp-includes/widgets/class-wp-widget-text.php
wp-includes/embed.php
wp-includes/formatting.php
wp-includes/js/twemoji.min.js
wp-includes/js/wp-emoji-loader.min.js
wp-includes/js/wplink.min.js
wp-includes/js/wplink.js
wp-includes/js/wp-emoji-loader.js
wp-includes/js/tinymce/plugins/wplink/plugin.min.js
wp-includes/js/tinymce/plugins/wplink/plugin.js
wp-includes/js/tinymce/wp-tinymce.js.gz
wp-includes/js/mce-view.min.js
wp-includes/js/mce-view.js
wp-includes/js/wp-emoji-release.min.js
wp-includes/js/twemoji.js
readme.html
error_log
wp-admin/edit-tag-form.php
wp-admin/install.php
wp-admin/plugin-editor.php
wp-admin/setup-config.php
wp-admin/user-edit.php
wp-admin/plugins.php
wp-admin/about.php
wp-admin/js/widgets/text-widgets.min.js
wp-admin/js/widgets/text-widgets.js
wp-admin/error_log
wp-admin/theme-editor.php
wp-admin/includes/class-wp-plugins-list-table.php
wp-admin/includes/update-core.php
wp-admin/includes/file.php
wp-admin/includes/template.php
license.txt

PD: And there is a problem between Newspaper and IP Geo Block?! (for the 500 error)

Guims
tagDiv Member

Well, after hours of research, I found some leads. I hope to retrieve my blog as it was before!
I will detail my research and hope you can tell me if my research is sufficient.

1-
in the wp-includes folder, I have 3 more files than in version 4.8.2 of wordpress (I put its files online in version .txt)

wp-includes/class.wp.php ==> click here

wp-includes/wp-vcd.php ==> click here

wp-includes/wp-feed.php ==> click here

I do not know the coder language but I think I understood that its files try to create a user in my database with administrator rights and then insert code into my themes files. am I right ?
I can delete the 2 users registered on my blog and I checked my database in the table users and usermeta, I think it is good. I think ….

To search further, I installed the Quttera Web Malware Scanner plugin and I performed an internal scan of the entire blog. in addition to its 3 files it tells me that there are other suspicious files (I also join them as a precaution):

/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/td_view_update_newspaper_6.php ==> click here

Severity: enMaliciousThreatType
File: /wp-content/themes/Newsp/.../td_view_update_newspaper_6.php
File signature: 814e64bc5a2f806f056be20e6426d120
Threat signature: 9632714c466ed4838165e9057dfb18c5
Threat: <?php if (empty(
Details: Malicious PHP Script

/wp-content/themes/Newspaper/js/tagdiv_theme.js ==> click here

Severity: enPotentiallySuspiciousThreatType
File: /wp-content/themes/Newspaper/js/tagdiv_theme.js
File signature: 6de7782788357b741a2703a368cf4f0a
Threat signature: dce48b63cbaf409a3bd5edb9042e7628
Threat: 'Y-m-d\\TH:i:sP'.rep
Details: Suspicious obfuscated JavaScript threat

After all his research and removal / replacement of infected files, I still get this message:
image

simchris
tagDiv Member

Try checking all the theme panels for any inserted ads. if you see malware ads, your site might have been hacked and you need to use t he links provided to clean up your site and also perhaps repair dbase.

Simion C.
tagDiv Staff

Hi,

After successfully activating it, the theme will not ask for another activation. The activation code does not disable or resets by itself. The theme code needs activation once and that’s it. You have a problem that resets the database most likely. Either it’s a malware or a plugin that needs resetting those fields. I can’t say for sure but it’s not a theme related issue.
There is an external influence over the db fields where the activation is kept. The theme only resets the key activation if the reset key button is pressed in the system status screen.

Thanks

Catalin
tagDiv Staff

Hello bednarp,

Please note that the theme has to be updated along with WordPress and plugins. Old versions can have security breaches and these can be exploited by different tools.

Please make sure you update your theme, plugins and WordPress and do not stick to old versions.

If you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:

http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/

Here is a link for best wordpress security practicess created by Chris S:

https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

Thank you!

Bogdan B.
tagDiv Staff

Hello,

I can only see the standard header ad spot being used. Please check your theme panel under ads and header ads.
If you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:
http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/

Here is a link for best WordPress security practices:

https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

Thank you!

Catalin
tagDiv Staff

Hello bednarp,

Please note that the theme has to be updated along with WordPress and plugins. Old versions can have security breaches and these can be exploited by different tools.

Please make sure you update your theme, plugins, and WordPress and do not stick to old versions.

If you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:

http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/

Here is a link for best WordPress security practices created by Chris S:

https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

Thank you!

bednarp
Participant
#0

There is a security hole in the template. Malware inserts the code http://prntscr.com/gkyoub into the template

John
tagDiv Member

I know I did not put ANYTHING in my header ad section and I go and check there.. boom… Malware javascript!

Updated theme to 8.1 SAME THING HAPPENED FEW DAYS LATER. THIS THEM GAVE ME A NIGHTMARE. Now my amazon affiliate account is banned permanently. DO NOT USE THIS THEME. TERRIBLE TERRIBLE theme.

John
Participant
#0

Guys, DO NOT BUY THIS THEME. This theme has vulnerability that allows hackers to hack into this theme and injects malicious redirects. This f*cking theme got me banned from my amazon affiliate account. DO NOT BUY THIS. More info: https://www.wordfence.com/blog/2017/08/traffictrade-malware/

Bogdan B.
tagDiv Staff

Hello,

Unfortunately you will need access to oyur files if you are to celan your install. Your issue is not tied to the theme. Please use one of these guides to clean your install:

http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/

Thank you!

Catalin
tagDiv Staff

Hi,

Please note that the theme has to be updated along with WordPress and plugins. Old versions can have security breaches and these can be exploited by different tools.

Please make sure you update your theme, plugins, and WordPress and do not stick to old versions.

If you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:

http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/

Here is a link for best WordPress security practices created by Chris S:

https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

Thank you!

Simion C.
tagDiv Staff

Hi,

Please follow this very useful and detailed guide describing steps to take in case of malware infection
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/
https://forum.tagdiv.com/topic/traffictrade-malware-newspaper-8-1-all-updated/

Thanks

pablograna
tagDiv Member

Hello! I do all the tests of the sites listed in the post to analyze malware and detect nothing! It only happens to me with the sites that have the Newspaper template. I did restorations to July. I already updated WordPress and theme to the latest version. Change password for BBDD and all users. However it continues to redirect to other sites … Please help

simchris
tagDiv Member

Malware was not in current version of theme — a ‘vulnerability’ was in old version. Two totally different things. Legal copy of theme has no malware or it wouldn’t be uploaded onto ThemeForest which checks/approves everything after TagDiv does.

For those who didn’t update the theme on time, or who ‘copied’ theme files on top of old files vs proper upgrade method (proper upgrade is DELETE old folder, upload NEW one), you might have been at risk. Much like running OLD version of WP, would get you hacked as well.

BE SURE TO READ:
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

  • This reply was modified 8 years by simchris.
Catalin
tagDiv Staff

Hi,

Please note that the theme has to be updated along with WordPress and plugins. Old versions can have security breaches and these can be exploited by different tools.

The old version from prior to April 2016 had a security issue which was patched in 6.7.2. Similarly, WordPress prior to 4.7 is insecure.

Please make sure you update your theme, plugins, and WordPress and do not stick to old versions.

If you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:

http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/

Here is a link for best WordPress security practices created by Chris S:

https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

Thank you!

Viewing 25 results - 476 through 500 (of 681 total)