No search results were found in Documentation!
We got this notice in Chrome today, also.
Might be false positive due to customer pasting code into a help post which is seen as nefarious.
But, since it’s a login/password protected site, that is very odd.
SECURI ALSO SHOWS ALERT
https://sitecheck.sucuri.net/results/forum.tagdiv.com/
ISSUE DETECTED DEFINITION INFECTED URL
Website Malware MW:JS:GEN2?web.js.malware.fake_jquery.003 https://forum.tagdiv.com/ ( View Payload )
Website Malware MW:JS:GEN2?web.js.malware.fake_jquery.003 https://forum.tagdiv.com/404testpage4525d2fdc ( View Payload )
Website Malware MW:JS:GEN2?web.js.malware.fake_jquery.003 https://forum.tagdiv.com/404javascript.js ( View Payload )
Website Malware MW:JS:GEN2?web.js.malware.fake_jquery.003 https://forum.tagdiv.com/login/ ( View Payload )
Website Malware MW:JS:GEN2?web.js.malware.fake_jquery.003 https://forum.tagdiv.com/register/ ( View Payload )
Website Malware MW:JS:GEN2?web.js.malware.fake_jquery.003
Hey Awesome tagdiv people,
Is this site forum.tagdiv.com attacked? Today while trying to access this site , Google Chrome gives this error:
“The site ahead contains malware
Attackers currently on forum.tagdiv.com might attempt to install dangerous programs on your computer that steal or delete your information (for example, photos, passwords, messages, and credit cards).”

Is everything alright?
Hi,
This email came today AND when trying to log in here my browser reported that this is a “Reported attack site”.
Care to give some comments?
This email was sent from your website “24Uutiset” by the Wordfence plugin.
Wordfence found the following new issues on “24Uutiset”.
Alert generated at Sunday 13th of November 2016 at 06:40:57 AM
Critical Problems:
* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/views/td_panel_custom_fonts.php
* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/plugins/td-social-counter/td-social-counter.php
* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/panel/views/td_panel_block_settings.php
* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/td_config.php
* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/td_api.php
* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/td_block_widget.php
* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/td_cake.php
* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/td_menu_back.php
* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/content-metaboxes/td_set_page_with_loop.php
* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/td_view_system_status.php
* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/views/ajax_boxes/td_panel_ads/td_get_ad_spot_by_id.php
* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/views/ajax_boxes/td_panel_cpt_taxonomy/td_get_tax_settings_by_tax_name.php
* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/views/td_panel_categories.php
* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/views/td_panel_excerpts.php
* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/views/td_panel_header.php
* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper-child/functions.php
Thank you, Bogdan and Chris for the reply.
I use following ad networks or tools for tracking.
1. Google Analytics
2. Tynt
3. Google Adsense
4. Content.ad
Though none of these “redirecting files” are related to these tools or networks but for precautions, I checked by disabling each of these from my site and turned off all ad modules.
Cleared the cache, turned off the CloudFlare after purging everything and also cleared the cache from the server side.
Even after doing all these things. I am still getting these files as the redirect chain.
Though I am aware that Pippio.com is supposed to be a ad network and redirects to https://arbor.io/, Linksynergy redirects to http://marketing.rakuten.com/affiliate-marketing and adbrn.com is http://www.adbrain.com which is also an ad network.
But I have never signed up or used any of these ad networks ever on my site. Also, a simple Google search shows that pippio , linksynergy and adbrn.com are mass reported as malware for computer.
For example: http://www.sitealyzer.net/en/p/sb/remove-p.adbrn.com/
http://www.exterminate-it.com/malpedia/remove-linksynergy-com
I have also scanned my WordPress with Anti-malware plugin and in the result, it shows some files from Visual composer and Contacts form 7 plugin as a potential threat which I hope is a false positive.
Kindly see if you can show me the right direction to look for.
Thank you.
Hello Friends,
On one of my site, I am getting some scripts like Pippio, LinkSynergy, ricdn, etc. when I test my site on Google Pagespeed, GTMatrix or Pingdom Tools. Have a look here: https://i.imgur.com/hozgLDk.jpg
With a quick google search, it appears that these are malware but then these are supposed to be on the computer, not on my WordPress site. Right? Then why is it showing there under test results?
When I manually check the presence of any such filename using View source on Google Chrome, I find nothing. I also cleaned my computer with Malwarebytes software, but nothing helps.
What are these? Are these on my computer or my website? What can I do now? Have you experienced something similar? Please help.
Thank you.
I added custom code in the theme’s panel section Custom Code, I deleted the code from that section, but I want to know if the code is still somewhere in the site.
Got Blacklisted by Google:
Harmful content
Google has detected harmful content on some of your siteâs pages. We recommend that you remove it as soon as possible. Until then, browsers such as Google Chrome will display a warning when users visit or download certain files from your site.
I was using RevenueHits as an alternative for AdSense. I used AdSense for about 2 months until they blocked my acount.
I ran 3 malware and antivirus tools and I want to make sure my site is clean before I ask for a status review with google.
Bogdan,
My provider said this:
“Hi JosĂ©,
I have cross checked the issue and I could see that some files are removed from the server after they are found to be virus files by our malware scanner.
These are the files reported as malware by malware scanner.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
———– SCAN SUMMARY ———–
Scanned directories: 163
Scanned files: 1388
Ignored items: 1
Suspicious matches: 5
Viruses found: 5
Fingerprint matches: 0
Data scanned: 17.47 MB
Scan time/item: 0.026 sec
Scan time: 40.205 sec
Newspaper/functions.php’
# ClamAV detected virus = [winnow.spam.ts.miscspam.1031628.UNOFFICIAL]
Newspaper/includes/demos/wedding/pages/homepage.txt’
# ClamAV detected virus = [winnow.spam.ts.miscspam.1031628.UNOFFICIAL]
Newspaper/includes/wp_booster/wp-admin/panel/td_view_welcome.php’
# ClamAV detected virus = [winnow.spam.ts.miscspam.1031628.UNOFFICIAL]
/Newspaper/js/tagdiv_theme.js’
# ClamAV detected virus = [winnow.spam.ts.miscspam.1031628.UNOFFICIAL]
Newspaper/mobile/js/tagdiv_theme.js’
# ClamAV detected virus = [winnow.spam.ts.miscspam.1031628.UNOFFICIAL]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Can you please contact your developer and make sure that these files are not infected? Make sure that this theme is from a trusted source. ”
Could you give an answer to him, I know everything is ok with your theme, but they need the designers explanation to these files.
Regards
Well, if there is malware, back doors, porn spam, etc. in the pirate version … uh, yeah, it probably will hurt your site — having no idea “where” the “friend’s copy” came from ?
You do realize this is the same as installing pirate software on your PC, there are many files, php codes, snippets, javascript — all of which can be damaging to your site if malicious.
Have you scanned your site with SECURI yet ?
Reinstalling WordPress is pretty quick if you know how to FTP stuff — unzip the clean WP installer from WordPress.org ( not from ‘a friend’ ) and then drag over all the pieces to your site “over-writing” the existing files … just to do quick safety check vs doing nothing at all. Replacing the default twenty-sixteen theme with clean version, deleting ALL other plugins and themes, is a wise choice.
Have you done anything at all, like research this on Google — it’s your site, only you can fix it if something is broken from using “borrowed” software. Theme devs can’t fix that for you.
http://www.wpbeginner.com/plugins/how-to-scan-your-wordpress-site-for-potentially-malicious-code/
Hopefully lesson learned!
Might be a firewall setting, malware/spyware on PC, weird zoom setting, etc.
Upshot: seems to be unique to your setup as generally EDGE works like Chrome, Safari, etc. and shares no lineage with Internet Explorer — it’s a modern browser using all the modern standards as Chrome and Safari do, and so will/should work the same for all websites.
You might check other theme demos on ThemeForest, try some ecommerce sites, etc., to see if also getting the same error, then try to narrow down what might be causing it.
Hello kibiribi,
You should not worry because this is not a value malware, it is just a false warning. Please keep in mind that some validation tools interpret some snippets of the code to be infected but it is not true. You will have to ignore this message and in the future, you can try to avoid this type of software because not always validate an accurate result.
Thanks for your understanding!
Thanks for reply, Chris S
FYI – this forum for registered users, so I don’t use pirated version. Purchase code for registration was required đ
Tested again by – Anti-Malware Security and Brute-Force Firewall v.4.16.39
it’s ok
Nothing – screenshot – http://screencast.com/t/PeyyCaKyJyiV
Problems for this Antivirus – AntiVirus v.1.3.9
warnings are there.
Result of scan – screenshot – http://screencast.com/t/12vjiABHi
I hope to click on the button – this is not a virus. Right ?
False positive unless you’re using pirated version.
Everything on ThemeForest scanned and safe. Everything TagDiv pushes is fully vetted.
Some “virus scanners” don’t understand things like an icon converted to base64 can look like malwware packet, etc.
Which “anti virus” tool are you using?
So, upshot – under normal use, nothing to worry about đ
You can scan your site with SECURI free scanner to find any “real” malware in your WP site.
I’ve got this warning dsureing the tempalte scan – http://screencast.com/t/g58Erdo8Z
“Virus suspected: The daily antivirus scan of your blog suggests alarm.”
please confirm – is it ok ?
——-/themes/Newspaper/functions.php——-
add_filter(‘loop_shop_per_page’, create_function(‘$cols’, ‘return 4;’));
———/themes/Newspaper/includes/td_templates_builder.php———
JTNDaDQlMjBjbGFzcyUzRCUyMmJsb2NrLXRpdGxlJTIyJTNFJTNDc3BhbiUzRVNlbmQlMjB1cyUyMGElMjBtZXNzYWdlJTIxJTNDJTJGc3BhbiUzRSUzQyUyRmg0JTNF
You need to tell Avast it’s not malware as an exception; one of many reasons I no longer use Avast. đ
===============
UPDATES!
Best way to do this is to learn to use FTP and manually delete the old theme folder, then upload the new theme folder to /themes/ folder and new plugins to the /plugins/ folder in wp-content on your website.
Seriously, worth learning to do – simple, quick, consistent. You know it works, because you’re doing it.
Also good time when doing that to make local backups by downloading your site to your HD, to have safe copies of your site, old themes/plugins, images, wp-config, htaccess, etc.
I have not seen any official word on this topic from TagDiv. I got the same message. As for FTP via FileZilla, I keep trying to download it from the offical site and Avast keeps flagging it as malware (grrr!). I thought about doing the patch instead of the full install and can see how that would get time consuming and cumbersome.
Is the issue due to an incompatibility in the latest WP release and the theme?
Cheers
I know I should have done an export of my config file, but I haven’t done it. I only have a backup of db and files of my site from prev backup ( start from yesterday ), so technically I should be able to retrieve config in prev db tables if I only knew where config is stored in db. I’ve always update the wp core files and plugins to the new versions, maybe I’ve some malware in my wp site, I don’t know, I’ll check soon. I’ve already changed my admin password.
Check your site with Securi malware scanner — note if you have not updated your site with latest versions of WordPress, your site is at risk of security flaws in WP, not the theme.
https://www.google.com/transparencyreport/safebrowsing/diagnostic/
ISSUE DETECTED DEFINITION INFECTED URL
Website Malware malware-entry-mwjs6525?web.js.spam-seo.redirect.021 http://alacatiplus.com/ ( View Payload )
Website Malware malware-entry-mwjs6525?web.js.spam-seo.redirect.021 http://alacatiplus.com/haberler/ ( View Payload )
Website Malware malware-entry-mwjs6525?web.js.spam-seo.redirect.021 http://alacatiplus.com/yeme-icme/ ( View Payload )
Website Malware malware-entry-mwjs6525?web.js.spam-seo.redirect.021 http://alacatiplus.com/eglence/ ( View Payload )
Website Malware malware-entry-mwjs6525?web.js.spam-seo.redirect.021 http://alacatiplus.com/alisveris/ ( View Payload )
Website Malware malware-entry-mwjs6525?web.js.spam-seo.redirect.021 http://alacatiplus.com/konaklama/ ( View Payload )
Hello pradeeppathak07,
I have tried to access your above link and I get only the blank page. We are unsure why this happens but malware is malware. Once it gets in, it can cause lots of issues. Please use these guides to get rid of it:
http://securepress.org/tutorial-how-to-remove-malware.php
https://wordpress.org/support/topic/malware-removal
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/(Wordfence blocks all access including the theme panel settings, so whenever you want to change the settings in the theme panel you need to set Wordfence to learning mode)
Also, please check the WordPress documentation for more info on how to setup your WP site:
https://codex.wordpress.org/Settings_General_Screen and make sure you have the latest secure version of WP installed.
Hope this helps!
Thanks.
Status: Infected With Malware. Immediate Action is Required.
Web Trust: Not Currently Blacklisted (10 Blacklists Checked)
ISSUE DETECTED DEFINITION INFECTED URL
Website Malware spam-seo-suspicious15?v12
đ
Check server for malware:
https://sitecheck.sucuri.net/?utm_term=%2Bscan%20%2Bwebsite&utm_campaign=649246947&utm_content=&utm_source=google&utm_medium=cpc&gclid=CMnI0dnY9s4CFZBefgodv8AIsg
Make sure you changed your username/password for super user.
Turn off “allow anybody to register”
Delete old plugins you don’t actually use.
Install “Limit Login Attempts” plugin.
Make sure you have clean backups up your website and consider re-installing WordPress entirely.
Hi Team,
I am getting a big issue now with Newspaper theme. The theme is accepting a malware. The malware link is http://www.i9wp.org/jquery.min.js and google is blocking it for adwords. Please look into this matter and give me solution for it as it really hard to find something in this complex theme.
Many Thanks
Pradeep Pathak
After lastest update, i tried again.It still does not update translation when i changed word what i like.
It is keep getting stuck on loading page ( icon)
I am not using any antivirus or malware program.
I am not using wordfence plug’in.
I already tried to disabled all of them.
Everything that should updated is updated.
Still it doesn’t work.It does not update new data on translation menu.
Buna ziua. Am un hacker care hackuieste site-ul X, adauga cumva continutul site-ului meu (si al altora, feed sau scrape) iar siteul X apare in google inaintea mea, desi titlul si continutul meu era primul. Redirectarea in google apare doar cand e refferer browserul. e un tip de hack facut de cel ce are siteul so.cc.erkp si altele (fara puncte, si are com). Acest hacker o face mereu, google nu e interesat.
Iar sunt afectat de el… Am observat in wordfence:
URL: http://siteulmeu.com/wp-admin/admin-ajax.php?td_theme_name=Newsmag&v=3.0
Type: Normal request
Referrer: http://www.siteulhackuit.com/?permalinkul-meu/
Full Browser ID: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Location: United StatesMountain View, United States
Vad mereu redirectarea asta: http://siteulmeu.com/wp-admin/admin-ajax.php?td_theme_name=Newsmag&v=3.0
nu reusesc sa o fac sa se duca in homepage, un 301… cand introduc in google acel link, imi apare un “0” – zero, in black page…
cum sa redirectez http://siteulmeu.com/wp-admin/admin-ajax.php?td_theme_name=Newsmag&v=3.0 to homepage
daca adaug in htaccess
Redirect 301 / wp-admin/admin-ajax.php?td_theme_name=Newsmag&v=3.0 to homepage /orice
nu merge…
ps: are acest js in siteurile hackuiote, e incredibil cum de o tot face si google un da malware pe siteurile hackerului… asta e jsul: h ds c on su lt or es.net/k v x p .j s
How to secure the site from malware & hackers
I had a malware black list site from google earlier now I just move my server and than I create from the beginning. Any idea suggest how to protect me website ?
Since the malware occur in the header.php of your theme folder, this suggest that the theme have security issues. I would recommend you to consider contacting the theme developers for security hardening or to change to another theme.
In case you need any further assistance, please do not hesitate to contact us.
Kind Regards,
Jack Mason
Technical Support Team
FastComet.com