Search Results for 'malware'

    No search results were found in Documentation!

Results from the Forum
Sohaib
Participant
#0

I found this malware script on my website:
<script type="text/javascript" src="//dolohen.com/apu.php?zoneid=2466565"></script>

Sometimes when I click anywhere on my page a new tab opens and loads an ad after redirection;

This is the page of my website. It is spread all over my site. How do I fix this?

https://www.wentdiary.com/top-17-things-to-do-in-oklahoma-city/

Calin
tagDiv Staff

Hi,

Please make sure that you have the last version of Newspaper theme and WordPress.

Please make sure that you do not have a plugin conflict, please deactivate all non theme plugins, also if you are using child theme or cache plugin, please deactivate them, clear all cache and try again.

If the problem persist please remove all code from them panel you can try to reinstall the newspaper theme.

Try to clean database of malicious
How to Remove McAfee SiteAdvisor Blacklist from Your Website -> https://blog.sucuri.net/2012/06/how-to-remove-mcafee-siteadvisor-blacklisting.html
How to Scan WordPress Database for Malware ->https://www.fixrunner.com/how-to-scan-wordpress-for-malware/
How to Clean a WordPress Hack -> https://sucuri.net/guides/how-to-clean-hacked-wordpress

Notice keeps popping up from McAfee “Whoa, do you really want to go there?”-> https://community.mcafee.com/t5/WebAdvisor/Notice-keeps-popping-up-from-McAfee-quot-Whoa-do-you-really-want/td-p/354431

Thank you!

Simion C.
tagDiv Staff

Hi,

Using a backup may also restore the malware. The website looks alright and working from what I can see at the moment. It looks same as before, at least in the frontend. What problems are you facing exactly?
Posts would only be affected if there are problems with the website database, that is where they are kept.

Thanks

jossytupsy
tagDiv Member

Hello Tagdiv,

Apparently it was a malware infection that affected my site. It later started redirecting to another IP address and later on, the website totally went blank. I had to contact Commodo CWatch to get rid of the malware. they did manage to quarantine the files that were infected and that has not made the website to lose functionalities. I could only see the text content, the other graphical part of the website is no more. Even when you try to login to the control panel, a 90% of the functionality has been removed. What is the best advice you can give me to restore my website back to its state so it can function well. I want to retain all post and still have all functions working. I don’t have a backup of any sort and the back up the hosting company has is infected so they can’t restore that as well

Simion C.
tagDiv Staff

Hi,

Updating to the latest version (now 9.5) would be in this case like switching to a new theme because of the differences between such an old theme and the current version. There was such a script from what I can remember quite a while ago in version 7 I believe. But this is not possible anymore.

There is an update guide here – https://forum.tagdiv.com/how-to-update-the-theme-2/

Remember to scan the database for malware, code in the theme panel, child theme etc. Currently when I visit the website my PC becomes almost unusable, this could be due to malware of some kind – https://www.screencast.com/t/lN5TWpUhS1

Thanks

veteranstoday
Participant
#0

Sites: VeteransToday.com (VT), VeteransNewsReport.com (VNR), VeteransTodayArchives.com (VT Archives)

Style 8 NOT working on VT and VNR
We do NOT see image.
Style 8 working on VT Archives
Why? How to resolve?

Newspaper Version: 9.2.2
PHP: 7.1 (ea-php71)
CDN: CloudFlare.com (CF)
Cache Plugin: WP-Rocket

On VT, it works when logged in. It does not work when NOT logged in
Here’s an example
https://www.veteranstoday.com/2019/02/05/extinction-event-our-two-shifting-north-poles/

On VNR, it does not work period; not logged in, logged in, no work both ways!
Here’s an example
https://www.veteransnewsreport.com/2019/01/30/mortgage-100-zero-down-payment-veterans/

TROUBLE SHOOTING ACTIONS TAKEN
We disabled CF and WP-Rocket cache, no work. So that’s ruled out.
We tried to use different images. no work. So that’s ruled out.

We know it worked on VT and VNR about 7 days ago
But now no work
Something changed but we don’t know what or where to look.

We do know that we got a report from our server company for all of our sites that use this template.
Here is an example of what they sent me;
“*Known javascript malware.: https://www.veteranstoday.com/wp-content/cache/min/1/f25d0f298fadac15548aa5218a6380ef.js&#8221;

Could that have something to do with it?
Or it is some setting we messed up on theme?
Or something else?

Frustrated!
HELP!

gmtimothy
Participant
#0

We have had a website user say that our website that is using newsmag theme is pushing browser notifications of the secular type and after some research we have found this page – https://blog.sucuri.net/2018/08/massive-wordpress-redirect-campaign-targets-vulnerable-tagdiv-themes-and-ultimate-member-plugins.html

we would like to completely disable any push notifications that the theme is serving how do we do this? we have done a malware scan and nothing has been returned….so we are reaching out to you to help us solve this issue.

we are using version 4.5

sanny
Participant
#0

Hello,

We have V4.6.1 installed and the site (http://banglalive.com) is getting repeatedly hacked by the redirection URL malware that is injecting spam URL links to the site and causing major disruption & impacting business.

We are planning to migrate the site to the latest version but that would take a bit of time. Meanwhile, we need a PATCH urgently to address the issue.

This is very urgent and looking forward to your prompt help.

Regards,
Sanny

simchris
tagDiv Member

When visiting this thread on tagdiv site, it triggers the Malwarebytes warning.

simchris
tagDiv Member

fyi – joxi.net screenshots used in this thread trigger outbound malware warning in malwarebytes …

Malwarebytes
www.malwarebytes.com

-Log Details-
Protection Event Date: 1/14/19
Protection Event Time: 10:47 AM
Log File: d2b385ec-182c-11e9-9768-3c07547ed697.json

-Software Information-
Version: 3.6.1.2711
Components Version: 1.0.508
Update Package Version: 1.0.8774
License: Premium

-System Information-
OS: Windows 10 (Build 17134.523)
CPU: x64
File System: NTFS
User: System

-Blocked Website Details-
Malicious Website: 1
, , Blocked, [-1], [-1],0.0.0

-Website Data-
Category: Trojan
Domain: dl4.joxi.net
IP Address: 176.9.162.201
Port: [50440]
Type: Outbound
File: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(end)

Simion C.
tagDiv Staff

Hi,

That may happen if you use old WordPress versions or old theme versions. Please try and scan the website, database etc for malware if there such a problem
https://codex.wordpress.org/FAQ_My_site_was_hacked
https://sucuri.net/guides/how-to-clean-hacked-wordpress
https://www.wpwhitesecurity.com/clean-hacked-wordpress-website-blog/
https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
https://wpbuffs.com/wordpress-website-hacked/
https://www.malcare.com/blog/2018/06/06/website-hacked-heres-a-guide-to-fix-it/
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

If you use an older theme version update the theme, update WordPress if needed as well
https://forum.tagdiv.com/how-to-update-the-theme-2/

After you remove the malware, take steps to improve the security of the website, be careful what plugins you install or what codes you enter in the theme or WordPress files or panels
https://www.greengeeks.com/tutorials/article/how-to-strengthen-the-security-of-your-wordpress-install/
https://premium.wpmudev.org/blog/ultimate-guide-wordpress-security/
https://www.wpbeginner.com/wordpress-security/
https://codex.wordpress.org/Hardening_WordPress

Hopefully you can identify the problem and solve it.
Thanks

Simion C.
tagDiv Staff

Hi,

Please try and scan the website, database etc for malware if there such a problem
https://sucuri.net/guides/how-to-clean-hacked-wordpress
https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

If you use an older theme version update the theme, update WordPress if needed as well
https://forum.tagdiv.com/how-to-update-the-theme-2/

After you remove the malware, take steps to improve the security of the website
https://www.greengeeks.com/tutorials/article/how-to-strengthen-the-security-of-your-wordpress-install/
https://premium.wpmudev.org/blog/ultimate-guide-wordpress-security/
https://www.wpbeginner.com/wordpress-security/
https://codex.wordpress.org/Hardening_WordPress

Hopefully you can identify the problem and solve it.
Thanks

wwsurfers
Participant
#0

I have three blogs. One uses the newspaper theme and the two others use another. Right now, the one using newspaper theme has been critically infected. As we talk, it has been blacklisted by Chrome; Google Search has removed it from all its relevant SERPs. BlueHost, my host, has deactivated it along with other blogs hosted on the account. Help, my brothers.

Simion C.
tagDiv Staff

Hi,

I can assure you that the theme downloaded from themeforest does not contain any malware, if that is what you are referring to. We scan the theme, Envato scans the theme as well.

The theme can only be downloaded from here, which is safe
https://themeforest.net/item/newspaper/5489609

I checked one of the websites on mobile, this one
http://elmoncasteller.cat/
I was redirected to an app download page when I clicked on the top header banner, but that would be the ad code used.

The other website I visited is not secure – https://www.screencast.com/t/rmnQGGwm81

Maybe try and scan the website, database etc for malware if there is a problem
https://sucuri.net/guides/how-to-clean-hacked-wordpress
https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

Thanks

Lorentz Yeung
Participant
#0

hello guys,
i just run some File Changes and Malware Scan with Wordfence on my admin panel, and found 2 files different from the original wordpress core files,
“wp-admin/includes/class-pclzip.php” and “wp-includes/SimplePie/Cache/File.php” files
so i am wondering, did the Newspaper theme maker make this changes, or it is hacked?

many thanks!

Simion C.
tagDiv Staff

Hi,

Maybe you entered code in the theme files or theme panel, or through a child theme. Please check if that is the case. Remove any theme modifications or codes/scripts entered directly in the theme files or in the theme panel.
The theme package downloaded from themeforest does not contain any type of malware of adware, so it must have been picked up from a different source.

From what I can find online this trenced.com is a type of adware, you could search for more information about removing it

http://greatis.com/blog/howto/remove-trenced-com-completely.htm
https://malwaretips.com/blogs/remove-trenced-com/
https://www.fixyourbrowser.com/removal-instructions/popups/trenced-com/
https://virus-removal-guide.com/27493-trenced-com-pop-up-redirect-removal-instruction/

Also here is a guide about WordPress and website security, created by one of our users
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

Thanks

MJ
Participant
#0

Hello,

I have a problem with the mobile version of my site. When using the back button, it redirects to a malicious spammy webpage.

This only happens with the mobile site, and not the desktop version. Numerous people have checked the issue, and it happens consistently for every user.

I’ve been trying to find the problem, and my server hosts checked the database and found it to be clean.

They then just sent me this message, suggesting that the problem is somewhere in the newspaper theme files:

“Hello again,

Thank you for providing the credentials. I properly cleared the WP Rocket cache and installed one of the WordPress core themes, “Twenty Seventeen”. I activated this and I found that the site no longer redirected on mobile. After switching back to the Newspaper theme, the redirect came back. This suggests that the problem is part of the Newspaper theme. I am unfamiliar with this theme, but I would recommend removing the theme and reinstalling it from a known clean copy if possible. Additionally, I recommend your developer review the theme files for any obfuscated content or functions that would be causing the redirection.”

Please can you help? Have you heard of this kind of redirect problem before?

Thanks

arrick
Participant
#0

We are getting the following flagged in Wordfence: Are these false positives?

This file may contain malicious executable code: /wp-content/plugins/td-composer/includes/tdc_ajax.php

This file may contain malicious executable code: /wpcontent/themes/Newsmag/includes/wp_booster/td_block.php

This is also on the scan which makes me think we’re probably safe and they’re just trying to sell us services….
“Since you have High Sensitivity scanning enabled, there is a very high likelihood that your results will include false positives. If you think you have indeed been hacked, our team of security experts can help.”

Thanks!

David
tagDiv Member

This kind of Malware is delivered by the ads on your site. We had the same 1-2 years ago. They attach their code somehow to ad campaigns of normal advertisers. We could identify the campaign containing the bad code and after we blocked it (and additionally some suspicious ad networks) it stopped happening. I’ve seen it on some pages lately, even on some big news sites.

bobbymc
Participant
#0

Saw this in the forum earlier about Malware. https://forum.tagdiv.com/topic/newspaper-theme-is-with-malware/

Just got a facebook messenger from a site visitor in Germany about being spammed from the site. See image here https://brandinginasia.com/wp-content/uploads/2018/09/spam-image.jpg

Any ideas on what’s happening and what can be done?

Thanks,

Bobby

jalewa
tagDiv Member

Issued Solved… thank a lot. Hope in the future we don’t get malware and injects to our theme.

arnaud1101
Participant
#0

My wordpress site running with an “old” version of Newspaper theme has been infected by this : http://labs.sucuri.net/?note=2018-09-18
I think I’ve succedeed in cleaning it (or almost…), but as it could be linked to Newspaper theme, I wanted to know if your tech team was aware. And do you think current version (I use the last version now !) is protected from such an attack.

Thank you so much.

Simion C.
tagDiv Staff

Hi,

The theme can only be downloaded from themeforest officially, that will guarantee a safe and secure package.

Re-installing the theme may not be enough in your case. You may need to reinstall WordPress and scan the database for malware or malicious code.

There are multiple guides online for removing malware from infected websites, one of our users also made a guide
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/

Also some guides I found that could be helpful to you
https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
https://www.webhostface.com/kb/knowledgebase/cleaning-up-infected-websites/
https://www.wpbeginner.com/beginners-guide/beginners-step-step-guide-fixing-hacked-wordpress-site/
https://sucuri.net/guides/how-to-clean-hacked-wordpress
https://codex.wordpress.org/FAQ_My_site_was_hacked

Catalin
tagDiv Staff

Hello jalewa,

Please notice that our theme is fully safe and is not a malware, sorry! Download the version from Theme Forest and install it via FTP way and you did not have any problem regarding on it. Everything is secure!

Thanks for your understanding!

Viewing 25 results - 401 through 425 (of 681 total)