Search Results for 'malware'

    No search results were found in Documentation!

Results from the Forum
Anamaria
tagDiv Staff

Hello,

1. Using our theme, you can choose from 3 mobile versions
-> mobile responsive => https://www.screencast.com/t/oJ2ShOp47
-> mobile theme plugin => https://forum.tagdiv.com/the-mobile-theme/
-> mobile page => https://tagdiv.com/newspaper-10-3-7-update-brings-customizable-and-fast-mobile-pages/
Suppose you created the mobile pages with tagDiv Composer. In that case, when you install the Mobile Theme plugin, your pages will be overwritten by the plugin (the mobile theme comes with its templates for page, post, category, etc, so your current templates from the desktop theme will get converted to the mobile theme layout, the page content is made without builders in mobile editor => https://www.screencast.com/t/xbgZG8kH also, the options that are provided to edit the mobile theme version are limited (this keeps the things simple)).
This is a video about Responsive Newspaper Theme, AMP & Mobile Theme, Mobile Pages & Templates -> https://www.youtube.com/watch?v=SpGkOnJeNZY.
So, the mobile responsive is what you see when that you select the viewport on phone => https://www.screencast.com/t/matV17hH, so some settings may apply for each viewport(where is the border blue), and others are not(where the border is black).
The mobile page has the mobile templates from Cloud Library => https://www.screencast.com/t/YCcZ8rL8
The Mobile responsive version of the theme and the mobile page editor can be edit with tagDiv Composer, the mobile theme plugin cannot.
For example, you can have the mobile theme plugin activated and use the mobile page/mobile responsive version for the homepage/pages, but for the categories pages/404 page, you can’t use the mobile page/mobile responsive version if you have the mobile theme plugin activated.
So, if you want to design the pages with tagDiv Composer, you can use the mobile page or mobile responsive version.
No, you do not need a plugin to redirect to the homepage; this will automatically change, but please make sure that you have a cache plugin with the support alos mobile versions.
2. You can use this plugin to reinstall wordpress https://wordpress.org/plugins/wp-downgrade/
3. No, this plugin contains malware. You need to remove it immediately.
4. You can use the Wordfence plugin to scan it.
All the plugins and themes can be infected -> https://www.wordfence.com/blog/2024/01/wordfence-intelligence-weekly-wordpress-vulnerability-report-january-1-2024-to-january-7-2024/

Thank you!

gobikrishna
tagDiv Member

Thanks for reply. When I try to update plugin some more. It will be good for one day. Again next day will come. Again remain plugin if I update it will be good again. This what happened yesterday I guess when you checked. Also it’s only from mobile browsers.

1) Shall I activate Tagdiv official AMP and mobile page plugin and separate home shall I edit?

2) How to re install wordpress again? You mean I should delete and have to do from beginning? After should get back via backup ? I’m confused how to reinstall wordpress.

3) it’s a official plugin? wp-zexit.php where will be located?

4) How to scan malware free plugin and clean it?

Note: non profit website and we try to provide education or fund to visually handicaped people. We don’t have developer too. That’s why we never install out source plugin. We only trust from wordpress plugins. But we are sad how could happen. If anyone please help us. It will be good for many people who get help from it. We are worried a lot. I hope you understand our situation. Thanks.

noozteam
Participant
#0

Hi, we’ve built our website using the Newspaper template over a year ago. We’ve also used some Tagdiv plugins.
Recently, when entering our mobile website, visitors are sometimes redirected to other websites. This issue doesn’t occur when entering our online website.
We suspect it may be due to malware which came from one of the plugins, but we’re unsure how to locate and remove it.
Can you advise?

Anamaria
tagDiv Staff

Hello,

Please let me know what theme version you have.
Please update the theme to the latest version 12.6.3.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.

Thank you!

arunmeena617
Participant
#0

Hi,

my website automatically redirects to other unknown links after using the td-composer plugin.

I think the plugin has some malware code that redirects my homepage to unknown websites.

luigiboschi
tagDiv Member

This is the message I’m referring to “I received this message from TagDiv support. Let’s hope it works:

Hi,

That is indeed the malwarehttps://labs.sucuri.net/blacklist/info/?domain=fast.quickcontentnetwork.com I found it as well on a few websites while I was investigating similar issues. Checking in the Live CSS option is a very important step in cleaning the malware, I’m not sure my colleagues from the forum didn’t mention it. We added a filter for the Live CSS in newer theme versions, which doesn’t allow malware to be entered there anymore. But if the website was infected while using an older theme version, updating the theme doesn’t solve the problem. What you have to do after updating the theme is open the Live CSS and press save – https://prnt.sc/a4XFrTI5j9tb That is it, the malware will be removed from there.

But I would still have a few suggestions based on what I encountered in other cases:
– In case you have not already, check in the plugins folder using a file manager (cPanel, FTP, etc.) to see if there are plugins there which you did not install. The plugins may not show up in wordpress but they could be there.
– Scan the website with wordfence.
– Check the website users.

The website does appear to be clean now – https://sitecheck.sucuri.net/results/https/www.marcocalvo.it There’s nothing in the Live CSS and no unusual scripts loading. If I can help with something let me know.

Regards.”

luigiboschi
Participant
#0

Hi there.
Siteground has found a malware inside the theme files.
I have already upgraded it to the latest version but nothing changes.

Regarding this topi https://forum.tagdiv.com/topic/malware-in-tagdiv-composer/ the solution seems to be to save the CSS live editor in order to delete the malware. However, in my site there is no live CSS box to open as the image provided by Marco in the last comment.

jtoney
tagDiv Member
jtoney
tagDiv Member

According to https://sitecheck.sucuri.net/ I don’t have the malware you speak of, so try again on that one. I’ve also revoked your access to server, cpanel, and wordpress installation so there won’t be any adding of malware.

jtoney
tagDiv Member

Let’s be clear there’s no malware on This Server you’re just not going to fix it. You know there’s a problem you don’t want to fix the issue. Let’s just be honest about it. You’re tired of dealing with me so you came up with whatever quick answer you could find.

Anamaria
tagDiv Staff

Hi,

I recognize your frustration, and I want to assure you that we’ve diligently addressed all your requests. It’s important to note that if you’re on a shared host without a dedicated server, certain aspects are beyond our control or that of the theme. We’ve thoroughly investigated and attempted to assist, but the specific nature of your issue remains unclear. Regarding malware concerns, it’s worth noting that the theme and other plugins and themes were affected. You can review the list here, which underscores why we implemented an update to rectify security-related issues.

Wishing you a joyous and festive Christmas!

Marco Calvo
tagDiv Member

I received this message from TagDiv support. Let’s hope it works:

Hi,

That is indeed the malwarehttps://labs.sucuri.net/blacklist/info/?domain=fast.quickcontentnetwork.com I found it as well on a few websites while I was investigating similar issues. Checking in the Live CSS option is a very important step in cleaning the malware, I’m not sure my colleagues from the forum didn’t mention it. We added a filter for the Live CSS in newer theme versions, which doesn’t allow malware to be entered there anymore. But if the website was infected while using an older theme version, updating the theme doesn’t solve the problem. What you have to do after updating the theme is open the Live CSS and press save – https://prnt.sc/a4XFrTI5j9tb That is it, the malware will be removed from there.

But I would still have a few suggestions based on what I encountered in other cases:
– In case you have not already, check in the plugins folder using a file manager (cPanel, FTP, etc.) to see if there are plugins there which you did not install. The plugins may not show up in wordpress but they could be there.
– Scan the website with wordfence.
– Check the website users.

The website does appear to be clean now – https://sitecheck.sucuri.net/results/https/www.marcocalvo.it There’s nothing in the Live CSS and no unusual scripts loading. If I can help with something let me know.

Regards.

jtoney
tagDiv Member

@simchris Respectfully you should not come into someone else’s thread and tell them they need to learn how to use WordPress and manage a server. I’ve had this theme install for over 2 years now. They updated something it caused issues. It is well known and documented that they had vulnerabilities in a prior build. Plenty of people got infected with malware I did not. This theme is filled with loaded coding and back doors and whatever else you want to add to it. Whenever you try to tell them that there’s a problem they tell you you need to fix it instead of them fix their code. Whenever you’re hosting provider and others have looked at this and have said the same thing that they the developer needs to work on it something’s wrong. Just go look all over the internet you’ll find where tagdiv has issues.

jtoney
tagDiv Member

So now you’re trying to say it’s malware. I don’t think you know what’s going on. You said you’re not developer you have to contact someone else who is a developer what’s actually going on here? You’re not going to tell me you’re going to leave me in the dark and then try to say it’s malware. At no time has that been an issue. I have checked the PHP tables many times and I have checked the domain structure. Unless you have added it to it it isn’t there. They wouldn’t surprise me if you added it to it try to say that that’s my problem.

Anamaria
tagDiv Staff

Hi,

The code was in live css; please delete it and save it because a code for malware was injected.

Thank you!

Anamaria
tagDiv Staff

Hi,

Your issue is related to the server. We did everything we could.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /

Thank you!

jtoney
tagDiv Member

They keep responding with the same thing that they can’t access the cpanel but that’s not correct. Someone in their organization named Calin has been in there. I know I can see the access to it. The solution to this problem was you need to buy a better hosting package and spend a lot more money. They’re not interested in fixing the code they’re interested in making money and that’s it. It’s very frustrating to deal with people who don’t offer real support who only respond to emails at the end of the work day and who do everything in their power not to assist. Getting one email per week is not a solution. Their countless articles if you search the internet of vulnerabilities with this developer as well as bloatware. It’s a problem that doesn’t seem to be getting resolved. The recent malware attack is another instance of problems with tag div. I’m at a point now I’m going to go find a different theme and a better Builder from an organization that actually wants to help. I’m revoking my access to my seat panel and my website to you immediately.

loslunes
tagDiv Member

Same here, this ips from Russia, Romania and Netherlands are trying to inject malware. They had the same problems months ago. Many of us were injected with a redirection code that you can see in theme options> custom code> javascript (or something similar). At least it’s seems they solved the problem blocking these petitions.

But yes, since a month ago we have had a continuous and non-stop traffic from this ips. Look at my server visit log https://ibb.co/Y7TWgxy

loslunes
tagDiv Member

Its a vulnerabilty of the theme. Someone is constantly trying to inject malware. Take a look to your server visit log and maybe you´ll find ips asking without stop to “/wp-json/tdw/save_css” or something similar.

My version of the theme gives them a 403, I was injected a few months ago and it’s seem the new version they built “solved the problem”. But hackers knows this vulnerability and they are trying and trying and trying. Look at the attached image, where you can find my server log from this morning. I haven’t seen them since a couple of weeks but they have come back again… Ips from Romania, Russia and Netherlands.

https://ibb.co/Y7TWgxy (attached image)

  • This reply was modified 2 years by loslunes.
avenlylane
Participant
#0

Hi,

My host is trying to clean up the malware that came through your site and needs the clean zip archive from you. Could you please supply that?

Thank you,
Clarissa

ganuk007
tagDiv Member

Hello Marco Calvo,

Attempting to delete that field won’t work; it won’t delete. If you try to delete it, it will automatically regenerate as it’s a Balada Malware Injector.

Therefore, you’ll need to reinstall the theme manually. Follow Step 5 & Step 6 as outlined above. & Before this don’t forget Step 2: Backup

Hopefully, this will work for you.

  • This reply was modified 2 years by ganuk007.
  • This reply was modified 2 years by ganuk007.
simchris
tagDiv Member

We had some weirdness the other day with one of our old sites running Newsmag 3 also; the menus got rearranged oddly – suddenly the top bar was the main nav bar. I reset that easily, but only updates were on the web server itself for PHP 7x and such. This happened prior to the latest WordPress update today.

We’ve got one site migrated to NM5 and PHP 8.1 and minor pain; really just rebuilding home page elements, but code is a little cleaner now. Most of the tricky stuff now in the composer plugin, following the practice of stuff like elementor, etc. — way less file withing file within file and endless redirects like v3 (ahem).

Anyway: this only happened on (1) site; with NM3x (final version), and PHP 7.x. But scanned site for malware and nothing found, so chalking that up to some oddity on server. Not using ‘Visual Composer’ – only TagDiv Composer.

Good time to move to Newsmag v5, frankly.

Advisable, but I didn’t do it: turn debug on in the wp-config file to write error log into content folder; then check it for anything notable beyond deprecation warnings. 🙂

Marco Calvo
tagDiv Member

Thank you Ganuk007,

I found the malware in the td_live_css_local_storage table. Do we need to delete all the content of the field or just the string:

(/style)(script src="https://fast.quickcontentnetwork.com")(/script)(style)

ganuk007
tagDiv Member

Hello everyone,

I managed to resolve this issue manually. Please follow the steps below to help address the malware problem:

Step 1: Identification
Firstly, locate the malware within the database. Look for a row in the wp-option table named td_live_css_local_storage that contains JavaScript code resembling fast.quickcontentnetwork.com within the option value.

Click here to see snaps

Step 2: Backup
Ensure you create a backup of your current site or application.

Step 3: Deactivate td-composer
Deactivate td-composer and proceed to delete it.

Step 4: Download the Newspaper zip file
Unzip and manually upload the plugin from the following path – Newspaper-tf > plugins > td-composer. If the issue persists, proceed to step 5.

Step 5: Manual Theme Reinstallation
Remove the theme from the server. Navigate to public_html > wp-content > themes and delete the “Newspaper” folder.

Step 6: Reinstall the Theme
Head to the WordPress dashboard, navigate to Appearance > Themes, click on Add New Theme, and install the theme.

Following these steps should help resolve the malware issue. Feel free to provide any feedback or if you need further assistance.

  • This reply was modified 2 years by ganuk007.
  • This reply was modified 2 years by ganuk007.
ganuk007
tagDiv Member

Hello Anamaria/tagdiv team,

I wanted to inform you that the same issue has occurred. I reported it to SiteGround, and they mentioned that there seems to be an issue within the theme itself—a malware presence in the database is causing unwanted redirects to other sites, classifying it as adware. Users are experiencing unwanted pop-ups and redirections when visiting our site. Specifically, there is a row in the wp-option td_live_css_local_storage that contains JavaScript code resembling fast.quickcontentnetwork.com within the option value.

Furthermore, there’s a problem with updating my theme to version 12.6.2. Whenever I attempt the update, it redirects me to the Dashboard instead of completing the process. Could you please assist me in understanding why this is happening? Your help would be greatly appreciated.

Viewing 25 results - 126 through 150 (of 681 total)