Search Results for 'Malware'

    No search results were found in Documentation!

Results from the Forum
ningthouja
tagDiv Member

@ Chris S. No malware. It is popads and popcash ads code. No problem is faced by me. Ok, I have deactivated pop ads code now. Kindly clear cache and look again.

ningthouja
tagDiv Member

No malware. It is popads and popcash ads code. No problem is faced by me.

simchris
tagDiv Member

Might be the malware popups you have on your site? Link launched multiple windows, forcing me to restart computer. BAD! BAD! BAD!

No help from me until you get your site fixed.

simchris
tagDiv Member

Suggestions:

http://codex.wordpress.org/Hardening_WordPress

Plugin – not tested:
https://wordpress.org/plugins/protect-wp-admin/

Older article:
http://www.wpbeginner.com/wp-tutorials/11-vital-tips-and-hacks-to-protect-your-wordpress-admin-area/

(check comments for article on feedback re opposing views/out of date warnings for DOA plugins or procedures)

——–
main items:
a) create new superuser; delete admin account
b) use ‘limit login attempts’ plugin
c) avoid plugins not updated for security fixes in WP 4.2 era (check Securi for list of bad plugins, for example; feedback on the support forum for any plugin on WordPress.org)
d) avoid plugins from ThemeForest/Envato unless very well documented, updated for security issues, and check feedback comments to see if malware/abandonware/bugs
e) consider turning off the pingback and XLMRPC stuff.

  • This reply was modified 11 years by simchris.
josito
tagDiv Member

Que alegria escuchar español jejeje, gracias por el consejo, he borrado todo por completo y volvi a subirlo, y me llegan dos emails del servidor por estos dos archivos:
El dominio xxxxxx ha subido ficheros desde ES con la IP 181.xxxxxx Este es el fichero:
– web/htdocs/wp-content/themes/Newspaper/Newspaper/includes/wp_booster/external/td-old-class-tgm-plugin-activation.php
– web/htdocs/wp-content/themes/Newspaper/Newspaper/includes/wp_booster/external/class-tgm-plugin-activation.php

En cada uno pone lo mismo:

El BS lo detecta como malicioso por:
POSITIVO en (“php shell”|Locus7s|”c100 shell”|emp3ror|afe0ver|M4il3r|T3MPL3|N3tsh|FilesMan|kebsyno|DEFAULT_DIR_DEEP_BACK|system_custom\()|By POKAMOM|jewsforjudaismg|r0nin|m0rtix|upl0ad|r57shell|c99shell|shellbot|phpshell|phpremoteview|directmail|bash_history|multiviews|cwings|vandal|bitchx|eggdrop|guardservices|psybnc|dalnet|undernet|vulnscan|spymeta|raslan58|Webshell|FilesTools|bckdrprm|hackmeplz|wrgggthhd|Arhack\.Net|WSOsetcookie|”By HasnZin”|”[S]uper[BAD] Mailer”|_GET[w….t]|aHR0cDovL21icm93c2Vyc3RhdHMuY29tL3N0YXRIL3N0YXQucGhw|”HighTech Brazil HackTeam”

Tenga en cuenta que es posible que sea un falso positivo. Es posible que alguna cadena usada en su fichero coincida con una cadena usada por Malware. Por este motivo si despues de revisar su codigo considera que es correcto, no es necesario que realice nada, ya que este correo es para avisarle de un posible peligro, pero no bloquea o elimina ningun fichero.

He echado un ojo a los archivos que dice pero mis conocimientos de php son casi nulos 🙁

Gracias por la ayuda por cierto!!

Riyathe
Participant
#0

Hi,
Firstly great theme, love it!, i know very little about html coding and am finding wordpress and this theme very user friendly.

I have a couple of issues with my site im trying to work through maybe someone can help.

1) Social Buttons work in the TagDiv widget with FB/YT/Twitter when i enter the details there but for the top menu and bottom menu they dont work, i added the same info into the ‘Social Networks’ tab as i had for widget fields and it just take me to my website… eg for youtube i put channel/XXXXXX into the field, then when i click it goes to http://www.website.com/channel/XXXXXX instead of youtube. Am i making a mistake with the format?

2) Ad code, i made 2 types of ads in my adsense account, a 728 x 90 for the top banner and a ‘responsive’ ad for the sidebar (i figured these sound about right). I copied the code for the 728×90 one into the header adcode section and the responsive adcode into the sidebar section of themepanel>ads and saved but when i view my website there is no ads. Am i missing something here?.

3) Caching – is it better to disable W3 total cache while working on the site so i can see the changes reflected quickly live?, im finding in mozilla with ad blocker im having to use another browser to check what my updates look like and it behaves unpredictably (sometimes shows updates, sometimes not). When i did disable adblocker for my site page only all sorts of malware appeared on my computer subsequently i installed bitdefender and malwarebyte seems to have sorted it.

p.s im a newbie to all this stuff but trying hard and enjoying your theme and this learning curve alot 🙂

my website is http://tabletopminis.com (its still in early development)

Emil G
tagDiv Staff

Hi,

I’ve downloaded the theme again to check the files and there’s no virus, the plugins come with the following files – http://screencast.com/t/QZQlMxK2http://screencast.com/t/BhuszySr

You can check the code on each one, it’s short, to see that there’s no malware/backdoor.

Thank you, Emil G.

simchris
tagDiv Member

ON my Windows7/64 system they don’t have a file type of ‘eastobuy’ … but simply “file”

They also pass the malwarebytes anti-malware scan as not being malware files.

simchris
tagDiv Member

btw …
if running Windows I can HIGHLY recommend running malwarebytes anti-malware PRO on your PC.

it’s what we use in our office, highly recommended by top techs, maximum pc magazine, etc.

You can also try this anti-rootkit from malwarebytes:
https://www.malwarebytes.org/antirootkit/

(HIGHLY RECOMMENDED TO HELP RESCUE YOUR PC!)

  • This reply was modified 11 years by simchris.
simchris
tagDiv Member

Scan your site for other malware here

https://sitecheck.sucuri.net/

simchris
tagDiv Member

If you downloaded the theme from a “warez” site they often have malware.

If you bought the theme from ThemeForest, and you look at the installer on your hard drive and it has a virus you may need to scan your system, but also contact ThemeForest to double check the downloads are not infected in some way “all of a sudden” — when did you download the files?

If the virus is ON YOUR DOMAIN in those folders, your site may have been hacked. You should change all passwords, and delete and reinstall your WordPress files, delete and reinstall all plugins and themes RIGHT NOW.

None of our sites running these plugins have this issue.

  • This reply was modified 11 years by simchris.
simchris
tagDiv Member


@planetaim

Malwarebytes anti-malware pro for Windows blocks your site loading for containing malware. You may want to contact them about that.

https://www.malwarebytes.org/lp/ip-blocking/?ipblock=true

Your Malwarebytes malicious website blocking technology has blocked outgoing or incoming communication between your computer and a malicious Internet Protocol (IP) address. That’s a good thing. This communication could be:
• An attempt to download malware onto your computer
• An attempt to redirect you to a malicious webpage
• An attempt to deliver malicious advertising

eyayu
tagDiv Member

I spoke several times with a storage company that is what they told me ”

The issue which you’re experiencing is due to the ‘max_questions’ for the MySQL database which is being used by the blog. If the MySQL user exceeds the database query limit, which is 75,000 per hour per user, then the WordPress website will be redirected to the installation page. This setting is in place to ensure that the MySQL database cannot be overloaded with to many query requests. The queries will reset every hour and is kept by user; however every time the pages on your website are accessed you are still attempting to make queries to the database server. It will be fixed automatically within one hour.

There are many possible causes for the ‘max_questions’ limit get exceeded. Some of them are:
* A script is not closing the MySQL connection after accessing the database. In WordPress, such chances are less, however if there is an error in the scripting of a plugin or theme which you’re using, then the MySQL connection won’t close after querying the database. Hence, please make sure that you close the connection immediately after accessing the database using mysql_close() command from your scripts.
* Your scripts or pages are hitting too frequently from a specific IP address through brute force tools or manually or from other websites. You can check raw logs available in the /stats directory or check the Visitor Statistics for such possibilities. Using the .htaccess Hotlink Protection and the .htaccess Block IP Addresses would resolve this issue.
* Using a single database for multiple applications or having too many users for a single database. A solution for this is creating separate databases for separate applications as well as having separate users.

Additionally, if you get a lot of traffic for your WordPress blog, then I suggest that you use a caching plugin, such as WP-Cache. WP-Cache will make a file copy of a page and serve that up instead of the original page (refreshing it every so often). This not only speeds up your website a lot, but hits to the cached pages make no SQL queries or database hits whatsoever.

We have launched new premium hosting product ‘WP Essential’ that is designed specifically for WordPress users and built for speed on a WordPress platform. Which has many more features and benefits such as website speeds up to 60% faster, Automatic updates through WordPress built-in functionality, Integrated, Handpicked Themes & Plugins, Dedicated WordPress experts team available 24/7, Automatic malware detection & removal, and many more features. You can know more about its features at http://www.ipage.com/advanced-hosting/wp-essential/upgrade.bml. I would suggest you to upgrade your hosting plan to ‘WP Essential’ to make use of additional features and benefits. ”

planetaim
tagDiv Member

my web site is a informative and entertainment it can’t be blocked as malware.


@Chris
S

simchris
tagDiv Member

Adding unrelated items to a thread may not help you get support quicker.

Best to open a new thread with *your* issue.


@planetaim

your website comes up as blocked by my anti-malware software.

kordysix
tagDiv Member

Hi,

95%, the problem came from pernicious malware and cookies. Specially the one named googleads.g.doubleclick. Problems almost solve. But I keep on struggling …

Thanks

simchris
tagDiv Member

Setup a Google webmaster tools account; verify it; setup XML sitemap; submit sitemap.

Check the account for errors once site is spidered properly.

In your webmaster tools account, Google will inform you of any violations, malware, etc.

simchris
tagDiv Member

There is no virus or malware in the theme.

You have some kind of weird interstitial popup which tries to load and obscures your home page with a grey backing.

Likely you need to disable plugins to determine which one is causing problems. You may have infected/bad plugin.

You should also check to see if your copy of Revolution Slider is newer than version 4.14 or remove it entirely if not using it.

sanay3070
Participant
#0

I have a virus when I try to edit the CSS of the Newspaper template.
Please help because I have a lot of problem when people try to connect to the site.

http://www.amanbox.be

Thanks

Bayu
tagDiv Member
sbo
Participant
#0

Where can I access the revolution slider that is built into the theme (where in the directory)? My website was listed as malware due to some sort of code injected through the rev slider. I can’t say 100% if the rev slider built into the theme or if its the rev slider downloaded from a different source. You can read it up here https://wordpress.org/support/topic/all-my-sites-6-hacked-with-soaksoakru/page/2?replies=5 – just need to know in case.

simchris
tagDiv Member

You might want to inform malwarebytes that your site isn’t “malware” 🙂

fitbodylife
tagDiv Member

malware bytes is blocking some of the javascript on our site that our Crm uses for tracking. turn off malware bytes.

simchris
tagDiv Member

I can’t even get to your site — Malwarebytes Anti-malware blocks your site for possible malware!

ref
https://www.malwarebytes.org/lp/ip-blocking/?ipblock=true

  • This reply was modified 11 years by simchris.
simchris
tagDiv Member

Note – if you really want to “debug” this you would need to

1) specify which OS version you’re using on your computer, the browser version, what anti-virus or anti-malware you’re using (both Avast and Symantec have wonky issues from time to time) – try turning them off to see if that causes the issue. Don’t use “branded” versions of web browser provided by an ISP like TimeWarner, etc. Use the un-branded versions of web browser.

Turn off ANY “ad blocking” software.

2) be sure to run a full anti-virus scan, clear temp files from your Windows system if running Windows, fully clear the cache in your web browser(s).

Check the theme forest demo of the theme, check the thread where somebody is again suggesting “post your sites here” to see different sites, and see if icons appear or not.

If several people post their setups here, one might be able to determine the commonality of the culprit as to why “a few” people are having this issue while the majority do not. I don’t think anybody would be buying these themes if all the icons were broken in the demo, for example.

That’s about all I can think of at this point.

Viewing 25 results - 651 through 675 (of 681 total)