No search results were found in Documentation!
Hi
Relatively tech unsavvy and have malware redirecting, seems to be Trojan one other people are seeeing.
Whats the playbook for this?
Thanks
Hi I have 2 sites under newspaper theme but both caught redirection malware. I looked at the previous threads and did everything discussed but still got the redirection issue. Please advise on what I can do.
I’m losing money, and a lot of time to fix it. And, by now, I’m not secure to updated the theme with this suppose “secure” new version. I’ve bought a licence of an anti-malware, and even the service said the “automatic cleanup of the site failed”. So, I had to contact the Malcare service for the “manual cleanup” of the malware, which is inside the Newspaper Theme. I don’t feel confident to updated, that’s it.
@loslunes, yeah, I’ve got it. But how can I delete the injected code in the Javascript of custom HTML? I’ve run a anti-malware and detected in my PC. I’m afraid to proceed with the updating prior than eliminate the malware on the site.
Hello,
Update Required: Newspaper 12.1.1 brings extra security checks to avoid potential vulnerabilities in the Theme Options.
If you notice that the site redirects to other sites, it may be because of injected malware. We recommend you follow the steps below:
– Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins;
– Delete the weird/unknown themes;
– Clean unfamiliar Theme Panel injected code (example – https://i.imgur.com/4q70kCv.png);
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)
– Update the theme to the latest version, Newspaper v12.2
If you have gone through the steps above and are still facing issues, don’t hesitate to contact us via email at contact@tagdiv.com. We’ll be ready to help you as soon as possible.
Thank you!
Hi thanhtan09,
Do you have some suspect code set in the Theme panel? in those sections – https://i.imgur.com/HHCXH2S.png – https://i.imgur.com/RPiH0Cj.png
If yes, please delete it, it can be malware (weatherpllatform) that is making the redirect.
Thank you!
When I install tagDiv Composer. My website redirect to a straight website.
My website is https://danangleisure.com/
Please help. Thanks
Thanks Calin, I will update asap to new version. I have answered you in the other post saying that the code only works when injected manually, as we show you, and caches were cleaned after the injection. If caches not cleaned or code is not here in custom fields the site works fine (so it couldn’t be an infected file in the server because the malware should then ALWAYS work, I hope I’m explaining well).
-
This reply was modified 3 years by
loslunes.
Ok thats the answer I wanted. I would update asap.
If any file infected in all the server files then the malware will run ALWAYS. The problem is that the malware only works when the hacker use tdcomposer / tdpanel option (as my partner and I said) to put into the custom javascript and custom html.
When you delete the code from there (I made 2 days ago and, fortunately, it doesn’t appears again) and clean caches, all works fine. When the code is injected and caches are not cleaned, the code doesn’t works because it has been not applied. I mean, it only happens when someone use td panel vulnerability to inject it. I don´t know if only in old version, I have 11.5.1.
Thanks for the help
Calin, you’re not giving us a solution since a couple of days that we have report the problem. Stop telling us it’s a viral campaign, people injected virus and malware… We know this happens because they use code vulnerabilities like the one you have here. I understand you don’t want to say it’s a theme problem, but I have talked with many developers with other themes, and they did not have the problem.
Someone is accessing tag div panel without a logged ip and then putting there malicious code. So then, your development team has to try to solve it asap. We have given you clear info about the process they use to do it, now it’s time for you to solve it.
Hi,
You can say it’s a “viral campaign” so many infections have been reported with different themes, not only with Newspaper or Newsmag.
I did more research and this malware is not from the theme, there are some viruses that are injected everywhere, in themes, plugins, and files.
Here are some reports and suggestions to fix the problem:
– https://wpxss.com/wp-admin/how-to-clean-trick-cofounderspecials-com-malware/
– https://guides.magefix.com/2022/09/cdn-weatherplllatform-com/
We will do more research and try to help as best we can!
Thank you!
Hi,
That is a code that is injected in the theme – https://ibb.co/Qbs0Xjn is not part of the theme is a malware (weatherplllatform) – https://www.reddit.com/r/Wordpress/comments/xuxb3l/redirection_malware_is_killing_me_its_spread_to_4/
– https://www.myantispyware.com/2022/11/13/go-weatherplllatform-com-pop-up-redirect-virus-removal-guide/
How to Remove Malware & Clean a Hacked WordPress Site
How to Find a Backdoor in a Hacked WordPress Site and Fix It
There are users with different themes, not only Newspaper that are affected by it.
Thank you!
Hi,
That code – https://ibb.co/Qbs0Xjn is not part of the theme is a malware (weatherplllatform) – https://www.reddit.com/r/Wordpress/comments/xuxb3l/redirection_malware_is_killing_me_its_spread_to_4/
– https://www.myantispyware.com/2022/11/13/go-weatherplllatform-com-pop-up-redirect-virus-removal-guide/
There are users with different themes, not only Newspaper that are affected by it.
Thank you!
Hi,
This is not from the theme, but, the database has been infected with weatherplllatform, there are many users with different themes infected with that malware – https://www.reddit.com/r/Wordpress/comments/xuxb3l/redirection_malware_is_killing_me_its_spread_to_4/
– https://www.myantispyware.com/2022/11/13/go-weatherplllatform-com-pop-up-redirect-virus-removal-guide/
By default, the themeforest package does not contain that code.
Thank you!
Same issue. Malware plugin was detected by Siteground (/public_html/wp-content/plugins/wp-clearlineee/wp-clearlineee.php in my case), and my site was taken offline. I checked the custom javascript code within the Newspaper theme and found the same code that others shared. I’ve deleted it for now.
This keeps happening to me over and over. I remove the malware and it gets reuploaded the next day. When people go to my site, they are redirected to a spam website. How can I fix this?
I’m looking the custom codes option every 30 min xD. This is insane. Anyway, I’m waiting the server to make a backup and a relaxing moment in my website (It’s happening when our visit has increased 300% from 5 months ago… so it’s a big problem having malware injected that random way) to update to last version and see if the problem persists.
Anyway, they should make a deep investigation about the issue and stop telling us its “our problem”
-
This reply was modified 3 years by
loslunes.
Hello!
We will investigate this problem. Until then, you need to protect, maintain your website and make a full backup. Follow this guide to clean your WordPress and theme of malware:
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/ or https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
Also, you can install an antivirus on your computer, scan it, and I think it can be found and deleted.
Thank you!
The issue still exists… My developer writes:
The issue is occurring as your theme is overwriting the option_name -> td_011 in the wp_options table whenever we remove the malware from your site. The option_value is being overwritten by the content ->Causing the site to break. I have attached a copy of how this row looks like infected with malware when we remove the code starting with ” s:2340:\”eval(String.fromCharCode ” the entire row gets replaced with the content I attached above.
—-
Can you take a look at what is overwriting this?
File: https://d.pr/f/MeY7iW
Hey, my WP anti-malware software has detected vulnerabilities ved tagDiv Composer (3.4 | built on 12.05.2022 9:11), which was a part of my Newspaper theme. What should I do now? i can’t seem to update it as it’s the latest version…
Hello!
I’ll add this to our investigation list so we can look into it as well.Can you please let us know which app you use to find the malware?
Thank you!
This is going to sound crazy, but that’s what I am experiencing.
My Desktop antimalware is reporting JS/Kryptik.co when I load my site. I ran Cpanel’s Imunify and sure enough, it identified the infected files. I cleaned them. I still have that trojan reported by my Desktop antimalware.
I figured it could be hiding in one of the plugins. I disabled them all. The trojan was gone. Then I started enabling them one by one. It showed up when I enabled tagDiv Composer.
Neither Wordfence nor Imunify could find any infected files. Yet the trojan was still reported by my Desktop antimalware. I then removed all the tagDiv Newspaper theme plugins entirely and proceeded to re-install them. I checked in File Manager that they were really gone from the server before re-installing. They were re-installed and what do you know, the virus came back.
I figured this can’t be. We cannot have a trojan in the files that come from the theme provider’s source directly. So I figured this bastard hid somewhere inside WordPress core files. If none of the host’s antivirus solutions nor Wordfence can find it, then I am stuck.
I decided to just WIPE the whole site. I made a backup of the Uploads directory and a DB dump. I wiped the site clean. Clean.
I reinstalled WordPress. No trojan was loading.
I then imported the DB. Fine.
I then installed Newspaper by uploading a fresh new installable ZIP from Themeforrest via Add New Theme.
I enable the theme’s plugins.
And what do you know? The virus is back.
I then proceeded to test with a default 2022 Theme by WordPress. I activated that and deactivated the Newspaper. Poof, the virus was gone. I activate Newspaper back, and boom, the virus came back. On a fresh install of everything it only pops up when the Newspaper theme is active.
I even wiped the cache on my browser. It didn’t do the trick. I tried in both Chrome and Firefox. The trojan is still loading.
But if I change the freshly installed theme with a WP default theme it’s gone.
What the heck? Anyone?
Problem solved. Topic can be deleted, it seems that I had a malware infection which is now repaired.
Dear TagDiv-team,
Could you please tell me if this is normal?
https://sitecheck.sucuri.net/results/https/www.rommalanders.com
If TagDiv Composer plugin is activated, the sucuri sitecheck recognizes the plugin as a malware. I’ve tried to reinstall the plugin, no changes.
Is there any kind of problem with the plugin in this case? Or false positive?
Best regards and thank you for your help!
Roman
Hi thilina36,
I recommend you do some investigations to see if your website does not has some malware or some injected code, usually, those are providing this kind of problem.
WordPress Hacked Redirect? How To Clean Website Redirect Malware
Thank you!