Search Results for 'malware'

    No search results were found in Documentation!

Results from the Forum
kurdi
tagDiv Member

Hello tagdiv support. I am asking for something specific here please read

I’m having such a hard time removing this malware. My hosting company removed it one time, apparently via editing the database, but it has come back. They have removed it again, but they said it is only a matter of time till the issue re-surfaces.

I am running into many issues; I will mentioned three of them:
(1) Updating my version of Newspaper breaks my site; (2) updating td-composer with a newer version is apparently not possible without updating Newspaper, and (3) I tried running the SQL query mentioned by mmorselli somewhere on these pages and got nothing but errors

I am sure I am speaking for a lot of Newspaper users when I request the following:
(A) A patch, please. If these problems are due to a vulnerability in your plugin, why not release a patch? Perhaps a temporary plugin that just cleans it up?
(B) In the short term, if a patch is not forthcoming, can you please provide a version of td-composer that removes the vulnerability and can be installed on older versions of Newspaper?
(C) If no patch, can you please provide a removal guide FOR DUMMIES with simple to understand steps. Perusing many posts on these forums where people say different things has not worked out for me.

Thanks

Abraham Duarte
Participant
#0

Hi my td composer plugin is infected a few days ago i star to notice that my malwarebites display a warnign about a troyan in my page https://revoluciontrespuntocero.news/
I check other conversations and found that is the td composer plugin, I unistalled and installed agian but still shows the same warning, what can I do ?
I also check the code but couldn’t found the abnormal code, also I can’t upgrade my theme because it displays a error (Could not move the old version to upgrade-temp-backup directory)

Hope you can help me

Calin
tagDiv Staff

Hello,
Indeed there seems to be a malware loading in the page source – https://i.imgur.com/ljaE7iK.png what I recommend is to login on the website and click on live css, the type a css like this one:
.text{}
save the css, then reload the page and search in page source after “_udyuzjck”.
Also, please contact us via email at contact@tagdiv.com and please provide wp-admin and cPanel access to check the website and clean it in case that this is in more places.
Thank you!

Bettina
tagDiv Staff
meteor83
Participant
#0

Hi,
I got message from my hosting company that my website http://www.korneri.net is infected with malwares!
they recommended me to contact the owners of the theme! i use centos-webpanel
When my costumers open my webpage are opening other malware pages

Please what can i do?

i got this message from my hosting company
Hello,

It has been brought to our attention that you’re hosting a phishing webpage on your service ns387694[.]ip-5-196-73[.]eu.

A malicious person has probably taken control of all or part of your website, and injected this page without your knowledge.
This kind of webpage is made to steal personal information from victims by impersonating well-known legitimage websites (such as banks, e-commerce websites or others).

If you’re using a content manager system (aka “CMS”) on your shared hosting offer or on your server, such as WordPress, Joomla or Drupal, check that it’s being maintained up to date at all times. This kind of software is widely used on Internet which is why it’s often targeted when hackers are trying to take control of a website such as yours. Please also verify that any plugins that you may have installed are also up to date, and avoid any unofficial plugin, as those have a higher chance of being malicious or not seriously maintained.

It is possible that some of those URLs are not accessible right now, because our anti-phishing system might have been activated, protecting victims of this type of fraud, while you’re working to fix the problem.

Please delete these phishing webpages and secure your service (CMS update, system update, password change) to ensure it cannot be hacked again.

When you have fixed the problem, please answer to this e-mail address

and this message from centos-webpanel

hi, the site is having security issue and infected kindly check with the devs and update the theme files and check the wp theme dir if there is any suspicious folders

casprom
tagDiv Member

Hi Calin,

I’ve sent an email to the address you mentioned, with the credentials and the subject of Malware Detection. Please let me know if I can help.

Best

casprom
Participant
#0

Hi guys, I’ve been trying to post this delicate and very urgent topic about malware that was detected in my website through the theme. Kaspersky and our host have been trying to help but this matter also concerns you so I’m asking for your help since it’s a function inside your buttons.

Since I’ve been unable to create the topic with full description of the matter, I’ve copied the original topic text to here were you can follow the Kaspersky topic and code and site. Please help as this been going for a week now and we have a lot of users trying to access our media website.

Doc: https://docs.google.com/document/d/1iMSzVvVqbONgXuNdjpGri-7z4gMO6VCUOYITuY8VG4Y/edit?usp=sharing

Bettina
tagDiv Staff

Hello!

Follow this guide to clean your WordPress and theme of malware: https://askwpgirl.com/10-steps-remove-malware-wordpress-site/

In the latest update, you won’t have any issues because the new versions of the theme are not compromised.
But if you do not solve the issues before the update, then of course the issue will persist there.

Thank you!

Bettina
tagDiv Staff

Hello!

Follow this guide to clean your WordPress and theme of malware:
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/ or https://askwpgirl.com/10-steps-remove-malware-wordpress-site/

1. The child theme is not overwritten by the update. An issue for that could be the compatibility of your child theme with the new version of our theme(if you use some files which were updated).

2. A code in your frontend is appearing only when you have a plugin uninstalled when it should be installed, so instead of the code, it will display the element from that plugin. Check in Newspaper -> Plugins (the Standard Pack plugin).

Thank you!

mcdv01
tagDiv Member

Hi Tagdiv,

So what is the final solution here?

This is just a work around on how to identify where is the malware.

Did you already have a fix for the vulnerability? Even if we follow steps here – there’s always a tendency for the site to be hacked again unless you apply a fix to the plugin/theme.

Your response puts us in circles.
You reply the solution is in this link: https://forum.tagdiv.com/topic/wp-zexit-malware-and-newspaper-theme-problem-please-see/

Then that link points to this link: https://forum.tagdiv.com/topic/update-tag-div-composer-and-wp-bakery-page-builder-plugin/

It is stated here that there’s a vulnerability in your Theme/Plugin:
https://forum.tagdiv.com/topic/backdoor-in-td-composer-allows-anyone-to-append-css-code-to-the-page-by-making-a/

So what is the final fix to prevent this? Do you expect us to just fix this everytime this happens – knowing that the theme has a vulnerability?

E K
tagDiv Member

I have the same issue, and nobody can remove the malware, not even the Sucuri team. Where can I send you my credentials so you can have a look, please?

FreshySites
Participant
#0

We recently faced a malware issue on our website due to the documented vulnerabilities with this theme/dependent plugins. In an attempt to resolve this, we updated our theme (8.7.3) to the latest version. We encountered the following issues:

1. Child Theme Error: Our child theme is throwing a critical error related to the td_api_header_style::_helper_show_header(); function. This appears to be depreciated or no longer supported in the latest version of the theme, and the error prevents the site from loading at all

2. Parent Theme Shortcode Issue: Even when reverting to the parent theme, we noticed that shortcodes are visible all over the website as seen here on this staging site running the latest version of the parent theme.

Could you please assist us in resolving these 2 issues as soon as possible? We’re at a standstill until this is fixed.

My intuition is that because we are jumping from version 8.7.3 to the latest version, we’re missing some conversion that happened with how the shortcodes are handled – perhaps the update needs to be done in steps?

We can provide full access to a staging site if needed

Bettina
tagDiv Staff

Hello!

This issue has been discussed already here: https://forum.tagdiv.com/topic/wp-zexit-malware-and-newspaper-theme-problem-please-see/

Thank you!

E K
tagDiv Member

Hi Calin

We have several websites hosted on the same AWS and protected by Cloudflare and Sucuri. All three websites are on the Newspaper theme.

One year ago, only these three sites got hacked. We got Sucuri to remove the malware – who pointed at that time to a potential theme issue.

Yesterday, we got hacked again – the same three sites running on the same theme.

Sucuri points again here (wp_options.option_value, option_name=td_live_css_local_storage)

We need someone to look into this – please contact us so we can provide you access to all three sites.

E K
tagDiv Member

We have several websites hosted on the same AWS and protected by Cloudflare and Sucuri. All three websites are on the Newspaper theme.

One year ago, only these three sites got hacked. We got Sucuri to remove the malware – who pointed at that time to a potential theme issue.

Yesterday, we got hacked again – the same three sites running on the same theme.

Sucuri points again here (wp_options.option_value, option_name=td_live_css_local_storage)

We need someone to look into this – don’t hesitate to get in touch with us so we can provide you access to all three sites.

E K
tagDiv Member

We have several websites hosted on the same AWS and protected by Cloudflare and Sucuri. All three websites are on the Newspaper theme.

One year ago, only these three sites got hacked. We got Sucuri to remove the malware – who pointed at that time to a potential theme issue.

Yesterday, we got hacked again – the same three sites running on the same theme.

Sucuri points again here (wp_options.option_value, option_name=td_live_css_local_storage)

We need someone to look into this – please contact us so we ca provide you with access to all three sites.

Bettina
tagDiv Staff

Hello @kurdi !

You should delete those values from your database. We already discussed about this issue in this topic as well: https://forum.tagdiv.com/topic/wp-zexit-malware-and-newspaper-theme-problem-please-see/
There you will find the solution provided by mmorselli.

Thank you!

kurdi
tagDiv Member

I also have a problem with malware associated with TagDiv Composer
Avira antivirus flagged it (https://i.imgur.com/RUuzOPv.png). Apparently it makes a request to: “https://cdn.statisticscripts.com/stats/step.js”

My host identified it in Tagdiv Composer; they provided this picture (which btw means nothing to me): https://i.imgur.com/XvUnPSD.png
Sadly they do not offer help with removal

Anyway the first thing I did was to delete my old version of Newspaper and install the new v12, but sadly this broke my site, so I reverted back

Next I deleted tagdiv composer plugin, but was not able to install the new version with the old version of Newspaper that exists on my site. I found an old version of the plugin from 2018 saved locally on my hd and installed it. I thought for a while that this fixed the problem, but it came back.

I am reading and re-reading the posts above, but do not feel any closer to a solution. Any help would be appreciated.

Bettina
tagDiv Staff

Hello @ersandrino !

You should delete the entire script: https://prnt.sc/KpaaEh1M3Hg9
Usually, there is more than one place. That’s why you should delete every hacked path.
Follow this guide to clean your WordPress and theme of malware: https://askwpgirl.com/10-steps-remove-malware-wordpress-site/

Thank you!

ersandrino
tagDiv Member

hi,
i have the problem with wp-zexit. My version is newspaper: 11.5.1

This the code of the malware inside in some page: https://prnt.sc/dr7LcY9fg5SR

How do I solve the problem? If you want I can provide you with the credentials. The issue is quite urgent

ersandrino
tagDiv Member

hi,
i have the problem with wp-zexit. My version is newspaper: 11.5.1

This the code of the malware inside in some page: https://prnt.sc/dr7LcY9fg5SR

How do I solve the problem? If you want I can provide you with the credentials. The issue is quite urgent

Vertesinfo202310
tagDiv Member

Hi Calin,

Thanks for your guide. I removed the malicious code from database by the guide on Reddit.
https://imgur.com/a/WDhWPNj
The Live css window was empty. I saved it.

Could you confirm, the theme, theme plug-ins and the site doesn’t contains any malware or malicious code?

Thanks

Calin
tagDiv Staff

Hello Vertesinfo202310 do you have the last theme version and you have the same problem like on post from reddit? If so, then please open the “Live CSS” and click on save button – https://i.imgur.com/RkrmBkT.jpg (this will check if the malware is in live css and if is it will remove it).
I hope this will help you!

Elperiodicodeyecla .com
tagDiv Member

Hellow team Tag Div support,
brand’s antivirus Eset and Karspesky have blocked my site by malware problem with plugin wpzexit and admin user greeceman. I have update Newspaper theme and plugins a the last version 12.6. And the pop up alert antivirus finish, but my website continue blocked by background white when user with antivirus enter my website. I have less visitor and my Newspaper loose credibility.

Tad Div Suport Company may speak with antivirus’s business for help to we buyers from Newspaper theme? and that antivirus companies delete his restrictions.

Gracias.
Pedro García Ródenas
Web Site:
https://elperiodicodeyecla.com/

Viewing 25 results - 201 through 225 (of 681 total)