Stange scripts like Pippio, LinkSynergy, ricdn show in speed testing PageSpeed

Posted in: Newspaper
Post count: 436

Hello Friends,
On one of my site, I am getting some scripts like Pippio, LinkSynergy, ricdn, etc. when I test my site on Google Pagespeed, GTMatrix or Pingdom Tools. Have a look here: https://i.imgur.com/hozgLDk.jpg

With a quick google search, it appears that these are malware but then these are supposed to be on the computer, not on my WordPress site. Right? Then why is it showing there under test results?

When I manually check the presence of any such filename using View source on Google Chrome, I find nothing. I also cleaned my computer with Malwarebytes software, but nothing helps.

What are these? Are these on my computer or my website? What can I do now? Have you experienced something similar? Please help.

Thank you.

Post count: 436

To make it more clear, these are the strange redirecting files:

Kindly help me to know , what are these?

Thank you.

Post count: 22421

Hi,

Well online scanners don;t seem to detect anything but you can never trust them completely though: http://screencast.com/t/wiz7S4vq3
Maybe one of these might be helpful;
http://wpdean.com/wordpress-malicious-code-plugins/
Might give this a shot as well to harden wp:
https://codex.wordpress.org/Hardening_WordPress

Thanks

Post count: 9544

Many of those are from the Ad Networks from the ad systems(s) you are using to track visitors/viewers.

If you turn off your ad modules and retest, you might see something quite different. 🙂

Post count: 436

Thank you, Bogdan and Chris for the reply.

I use following ad networks or tools for tracking.

1. Google Analytics
2. Tynt
3. Google Adsense
4. Content.ad

Though none of these “redirecting files” are related to these tools or networks but for precautions, I checked by disabling each of these from my site and turned off all ad modules.

Cleared the cache, turned off the CloudFlare after purging everything and also cleared the cache from the server side.

Even after doing all these things. I am still getting these files as the redirect chain.

Though I am aware that Pippio.com is supposed to be a ad network and redirects to https://arbor.io/, Linksynergy redirects to http://marketing.rakuten.com/affiliate-marketing and adbrn.com is http://www.adbrain.com which is also an ad network.

But I have never signed up or used any of these ad networks ever on my site. Also, a simple Google search shows that pippio , linksynergy and adbrn.com are mass reported as malware for computer.

For example: http://www.sitealyzer.net/en/p/sb/remove-p.adbrn.com/
http://www.exterminate-it.com/malpedia/remove-linksynergy-com

I have also scanned my WordPress with Anti-malware plugin and in the result, it shows some files from Visual composer and Contacts form 7 plugin as a potential threat which I hope is a false positive.

Kindly see if you can show me the right direction to look for.

Thank you.

Post count: 9544

Remember that certain plugins include tracking/advertising.

Things which load off another site, like Facebook/Twitter likes, comments plugins, social sharing plugins, etc., can all add tracking.

Try turning off ALL your plugins except visual composer, and scan again.

===
Also view your page source for one of your posts to see if something is actually printed in the source code to determine where that might be and what is putting that on page — perhaps do this FIRST.

Post count: 9544

Also super important:
a) delete old themes you no longer use!
b) delete plugins not being used or planned to be used.
c) make sure you have full dbase backup, site backup, etc.
d) look in your plugin folder for any weird php files you didn’t put there or included with theme;
e) reset/refresh CDN, clear cache, resave permalinks, clear transients with wp-optimize.

======
consider doing CLEAN install of WordPress and *all* plugins!

  • This reply was modified 9 years by simchris.
Post count: 436

Thank you Chris for the help.

I am doing things as said by you above. These may be because of any plugin then. Let me go through this step by step.

Thank you again.

Post count: 14

Nano2408 did you ever figure out what it was?

Post count: 436

Hi ohmichea,

Yes. It was all secretly added by Tynt ( now called 33Across). When checked thoroughly and complained about it multiple times, they agreed that they were mistakenly ( ? ) added these codes on my site and hence removed it from my code.

I used it for several months but then left it completely now.

Viewing 10 posts - 1 through 10 (of 10 total)
The forum ‘Newspaper’ is closed to new topics and replies.