No search results were found in Documentation!
Please review the following warnings found in Ninja Scanner plugin – File version change (about the same time I stared having the bad issues with site not loading from google search if I turn off litespeed “Guest Mode”
Note. Before blaming or ponting this to virus just because I mentioned a virus scanner. Wordfence, Malcare, Ninja scanner, and cpanel mod sec and cpanel virus scans all show clean. No malware or infections
-
This reply was modified 3 years by
mgiannelis.
Hello,
Seems you have malware on the website. This means that someone has access to your website, I suggest installing a security plugin as soon as possible, if you haven’t already.
My suggestion is to check those articles and clear the hack code and secure the website:
-> How to Scan Your WordPress Site for Potentially Malicious Code
– WordPress Malware Redirect Hack – How To Fix Guide [2022]
– WordPress Hacked Redirect? How To Clean Website Redirect Malware
I hope this will help you!
Thank you!
I’ve discovered a new problem and haven’t reported it yet.
My website has been hacked and is currently infected with malware. (Will be deleted soon)
Currently infected are: (some are hidden)
1.
/home/ba●●●●/public_html/blog/wp-content/plugins/td-composer/legacy/common/wp_booster/wp-admin/wp-admin/ijckTyKwdJa.wav
2.
/home/ba●●●●/public_html/blog/wp-content/uploads/revslider/templates/landing-page-call-to-action/landing-page-call-to-action/SKTuvdzixjkJXoL.mp4
3.
/home/ba●●●●/public_html/blog/wp-content/uploads/revslider/templates/clear-view-single-menu/clear-view-single-menu/CIMgT.mov
4.
/home/ba●●●●/public_html/blog/wp-content/uploads/2022/08/08/C.bmp
Maybe this is the reason for this error? “Or is it irrelevant?”
Hi,
We made some search on google related to the ClamAV and it seems that there are many users reclaiming that the ClamAV that is providing false alarms.
-> https://www.bleepingcomputer.com/forums/t/640599/malware-found-using-clamav-but-not-by-malwarebytes-anti-malware/
Also, I informed the developers to check with that plugin and see if there is a problem or in in the theme files.
Thank you for assistance.
Okay, here is what I tried, in sequence, but sadly it didn’t work…
1- deleted the theme and removed all plugins
2- ran a scan of the site and that came back clean
3- downloaded the theme full package from themeforest
4- uploaded it on the site and installed it again
5- ran the scan and found the same supposedly infected file
6- disabled and deleted the single plugin td-composer
7- ran the scan and it came back clean
8- manually uploaded the td-composer plugin from the one .zip file included in themeforest package and activated it
9- ran the scan and found the same supposedly infected file
10- deleted again the td-composer plugin
7- ran the scan and it came back clean
11- downloaded the td-composer plugin from within the theme’s plugins panel, hence straight from tagDiv cloud server.
12- ran the scan and found the same supposedly infected file
the scan returned the MetaBox.php file and virus signature {HEX}Malware.Expert.php.var.pattern.UNOFFICIAL
The tool I used is clam-av (the one available from my admin tools), the same my host uses.
I need the site running so for now I am just ignoring the file, I tried to quarantine it, but it breaks the site.
What would you recommend to do? Did I miss any step?
Honestly, I don’t know what to think…
@joema did you manage to get rid of your supposedly infected file?
thank you
Hi,
I understand, since you use the theme on two sites and the problem appears only on one of them, then it is possible that somehow malware has reached that site. In such situations, it is recommended to delete the theme and plugins from the there, download the theme from themeforest and reinstall it (the settings will not be lost because they are saved in the database).
I will also inform the developers, maybe I can do something to protect that file in the future.
Thank you!
I received this form the host:
It’s possible that the theme itself is clean but one of its files has been infected within just this package. There are several reasons a website can become infected, with the most common being outdated or insecure plugins and themes.
I’ve run a scan and this is coming back as clean. Checking the latest scan showing as infected, it looks like the file in question is at:
/home/sites/14a/8/8d3f08f670/public_html/wp-content/plugins/td-composer/legacy/common/wp_booster/wp-admin/external/wpalchemy/MetaBox.php
I’ve checked this over for you and it doesn’t appear to be currently infected, so it’s possible that this was a false-positive or that the infection has been overwritten during an update. You may wish to send the contents of this file to the theme developers.
If you see further infection warnings, please let us know and we can have our malware specialist manually check this over to confirm if the warning is legitimate for you.
I hope that makes sense. Please let me know if you have any further questions.
I’ll have a word with the host and get back to you.
When doing a malware scan, it does say on there that they are checking it against known malware signatures, if that helps.
I have the theme on two sites on separate accounts with the same host, but only one shows as having malware (I just did a manual check) so that’s strange.
-
This reply was modified 3 years by
joema.
Hello,
From the tests on the package that is on themeforest, I did not find any problems.
Now it is possible that the tool that you or your host uses is different and interprets certain structures as malware.
If you can give us more information, like what host you use and what tool was used, I will pass it on to the development team.
Thank you for your understanding!
Hi everyone,
I am having the same issue here, I just searched the forum for MetaBox.php and found this fresh thread.
My hosting is emailing me similarly to @joema, that their scan has found some infected file(s), together with the info I paste below:
File path
/home/umuseooc/public_html/wp-content/plugins/td-composer/legacy/common/wp_booster/wp-admin/external/wpalchemy/MetaBox.php
Firma antivirus (antivirus signature)
{HEX}Malware.Expert.php.var.pattern
Last modified (which dates back to when I installed the theme)
2022-06-20 17:38:59
Quarantined status
no (which means my hosting doesn’t consider it such an evil threat)
I would be very grateful if you could sort this out.
I am happy to provide wp-admin access if needed. Let me know.
Thank you
Paolo
Hi,
I just done some scans in the theme files and there were no malware/virus detected.
Maybe there is a code that is detected that it can be a malware by the tool that your host is using. We’ll like to do some deep investigations if you agree. For this please contact us via email at contact@tagdiv.com and please provide wp-admin access.
We’ll check it as soon as possible.
Thank you!
My host is bringing up a malware detection for a file in the Newspaper theme.
I’m sure it’s nothing, but I need to get this sorted with them so the site won’t be taken down, which has happened to me before though on a different host.
Filename
MetaBox.php
/home/sites/14a/8/8d3f08f670/public_html/wp-content/plugins/td-composer/legacy/common/wp_booster/wp-admin/external/wpalchemy/MetaBox.php
Exploit Found
php.var.pattern
Hi,
That is the live CSS option -> https://prnt.sc/jTNj90DpZ-L4 Please check there.
I believe that is where the malware code is entered. This means that someone has access to your website, I suggest installing a security plugin as soon as possible, if you haven’t already.
Thank you!
Hi, I have one site that has malware placed into this position:
“<style id=”tdw-css-placeholder”></style>”malware js code here“</head>”
Any ideas how to locate where it is coming from? Tried look everywhere, but can not locate the source where it is.
Hi salty, I saw this, even today when I accessed the link the first time I was redirected to this link -> xcebph.snowfalltwenty.top/ but those are redirections are not normal and a malware or a code injected can be programed how to affect the website.
Also, I suggest to ash your host for help too.
Thank you!
Hi salty,
Indeed so it looks that is acting. Most of the time when this is happened is a code that has been injected in the WordPress.
My suggestion is to check those articles and clear the hack code and secure the website:
– WordPress Malware Redirect Hack – How To Fix Guide [2022]
– WordPress Hacked Redirect? How To Clean Website Redirect Malware
I hope this will help you!
Hello,
Normally the .htaccess file is generated by WordPress, but it can be injected with extra code using functions, plugins, malwares. So if you have those kind of problems it will be better to ask your host about the security that they provide for your website and how to prevent this kind of situations.
Also, maybe those articles can help you:
How to Scan WordPress for Malware in 4 Easy Steps
How to Scan Your WordPress Site for Potentially Malicious Code
Thank you!
Hi,
It is possible to me a code that is injected in .htaccess and this provide this problem.
The code can be from a plugin or it can be a malware injection.
Also, please check this article https://wpbrainery.com/wordpress/how-to-fix-a-corrupted-htaccess-file/
I hope this will help you!
Hello!
Other users have reported also this issue. Please check this article: https://www.getastra.com/blog/911/japanese-keyword-hack/
Also, I recommend you to check and clean your files: https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
After that, you should reinstall everything, starting with the WordPress, theme, plugins so that it will be a clean install.
Thank you!
Hello!
Please check this article: https://www.getastra.com/blog/911/japanese-keyword-hack/
Also, I recommend you to check and clean your files: https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
After that, you should reinstall everything, starting with the WordPress, theme, plugins so that it will be a clean install.
Thank you!
I have dev server and have been attack with malware.
I delete the whole files that have been affected.
When the td composer was enabled I get this error
Parse error: syntax error, unexpected ‘?’ in /home/xxxxx/public_html/xxxx/wp-content/plugins/td-composer/legacy/Newspaper/includes/td_config.php on line 33408
The same error displayed when I delete the td composer and install it again.
Do you know why?
Thank you!
Calin,
Thanks for your prompt reply! We indeed did receive a pop-up message as the demo content installation status showed complete – see below:
rtbuild.underwood-design.com says
tagDiv Importer detexts that your server is not properly configured.
Don’t worry, the importer will continue to install the demo after you click the OK button.
Steps to verify:
– Please go to the SYSTEM STATUS tab and check if all parameters are gree – Verify the permissions on your upload folder
– Contact our support via email contact@tagdiv.com (please provide your product license key)
We have checked the System Status portion of the theme, but are showing no yellow (all green unless grayed out with “i”).
Other than WordFence and some malware protection plugins (in addition to those loaded by the them), this is a fresh build.
Hello,
After Godaddy removed malware from my website, I became unable to access the Wp-Admin page. I called Godaddy and that informed me that this was, in fact, a theme issue. Here is an image of the error I am getting on my Wp-Admin page:
Warning: include_once(/home/occidentalweekly/public_html/wp-content/themes/Newspaper5745747/includes/wp_booster/wp-admin/external/wpalchemy/MetaBox.php): failed to open stream: No such file or directory in /home/occidentalweekly/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/content-metaboxes/td_templates_settings.php on line 3
Warning: include_once(): Failed opening '/home/occidentalweekly/public_html/wp-content/themes/Newspaper5745747/includes/wp_booster/wp-admin/external/wpalchemy/MetaBox.php' for inclusion (include_path='.:/opt/alt/php73/usr/share/pear') in /home/occidentalweekly/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/content-metaboxes/td_templates_settings.php on line 3
Fatal error: Uncaught Error: Class 'WPAlchemy_MetaBox' not found in /home/occidentalweekly/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/content-metaboxes/td_templates_settings.php:13 Stack trace: #0 /home/occidentalweekly/public_html/wp-includes/class-wp-hook.php(286): td_register_post_metaboxes('') #1 /home/occidentalweekly/public_html/wp-includes/class-wp-hook.php(310): WP_Hook->apply_filters(NULL, Array) #2 /home/occidentalweekly/public_html/wp-includes/plugin.php(465): WP_Hook->do_action(Array) #3 /home/occidentalweekly/public_html/wp-settings.php(525): do_action('init') #4 /home/occidentalweekly/public_html/wp-config.php(107): require_once('/home/occidenta...') #5 /home/occidentalweekly/public_html/wp-load.php(37): require_once('/home/occidenta...') #6 /home/occidentalweekly/public_html/wp-admin/admin.php(34): require_once('/home/occidenta...') #7 /home/occidentalweekly/public_html/wp-admin/index.php(10): require_once('/home/occidenta...') #8 {main} thrown in /home/occidentalweekly/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/content-metaboxes/td_templates_settings.php on line 13
The site is experiencing technical difficulties. Please check your site admin email inbox for instructions.
Hello Marco!
I’m sorry to hear that your website has been attacked. I can recommend you some tips, please check this topic: https://forum.tagdiv.com/topic/hacking-issues-with-version-11-2/
Also, I recommend you to check and clean your files: https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
After that, you should reinstall everything, starting with the WordPress, theme, plugins so that it will be a clean install.
Thank you!
Such a function is unacceptable. This is malware and breaking the law. I bought your theme and can even cut it off from your servers. It was invented by a total moron.
Please let me know when this feature will be removed from the theme.