Tagdiv and suspected malware

Posted in: Newspaper
Post count: 21

Hi,

This email came today AND when trying to log in here my browser reported that this is a “Reported attack site”.

Care to give some comments?

This email was sent from your website “24Uutiset” by the Wordfence plugin.

Wordfence found the following new issues on “24Uutiset”.

Alert generated at Sunday 13th of November 2016 at 06:40:57 AM

Critical Problems:

* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/views/td_panel_custom_fonts.php

* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/plugins/td-social-counter/td-social-counter.php

* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/panel/views/td_panel_block_settings.php

* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/td_config.php

* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/td_api.php

* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/td_block_widget.php

* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/td_cake.php

* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/td_menu_back.php

* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/content-metaboxes/td_set_page_with_loop.php

* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/td_view_system_status.php

* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/views/ajax_boxes/td_panel_ads/td_get_ad_spot_by_id.php

* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/views/ajax_boxes/td_panel_cpt_taxonomy/td_get_tax_settings_by_tax_name.php

* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/views/td_panel_categories.php

* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/views/td_panel_excerpts.php

* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper/includes/wp_booster/wp-admin/panel/views/td_panel_header.php

* File contains suspected malware URL: /home/n4uuti5/public_html/wp-content/themes/Newspaper-child/functions.php

Post count: 10

Same problem here.

TagDiv forum on Google Safe Browsing Site has “Dangerous” status

http://picpaste.com/pics/asda-TFcuqWPN.1479043108.jpg

Wordfence scan screenshot

http://picpaste.com/pics/wer-wvE0JNKi.1479043193.jpg

Post count: 9544

https://sitecheck.sucuri.net/results/forum.tagdiv.com/

ISSUE DETECTED DEFINITION INFECTED URL
Website Malware MW:JS:GEN2?web.js.malware.fake_jquery.003 https://forum.tagdiv.com/ ( View Payload )
Website Malware MW:JS:GEN2?web.js.malware.fake_jquery.003 https://forum.tagdiv.com/404testpage4525d2fdc ( View Payload )
Website Malware MW:JS:GEN2?web.js.malware.fake_jquery.003 https://forum.tagdiv.com/404javascript.js ( View Payload )
Website Malware MW:JS:GEN2?web.js.malware.fake_jquery.003 https://forum.tagdiv.com/login/ ( View Payload )
Website Malware MW:JS:GEN2?web.js.malware.fake_jquery.003 https://forum.tagdiv.com/register/ ( View Payload )
Website Malware MW:JS:GEN2?web.js.malware.fake_jquery.003

Post count: 11

I have the same warnings on one of my sites using the Newspaper theme after a Wordfence scan. Is this a sinking ship or a false warning?

Post count: 10

This is a question mark above our heads, both for TagDiv developers and for Newspaper theme users.

Post count: 9544

To be clear.. theme not infected.
This forum was infected due to forum software exploit.

Post count: 11

And are you sure that sites with this theme and the corresponding url are not going to be blacklisted also?

Post count: 11

If there is the slightest chance that our sites will be blacklisted because the scanners find a url to a blacklisted site in the theme files, then the problem is obviously serious. If I can´t be sure this is ok I will stop using the Newspaper theme.

Post count: 22421

Hello,

We can assure you your sites are safe. This forum got infected with a few malware exploits but they were removed and there is no threat anymore. Your sites got the warnings because the theme has links to this forum (to the documentation) in the theme panel. (Thy are the suggestions and references to the docs.)
This only affected our server and could not have affected anything beyond that.

Sorry for the inconvenience and thank you for your understanding.

Post count: 10

Thank you Bogdan,we are not only concerned about us but also about your work and your website (server). We hope that you will solve the problem.

Thanks for your time and efforts.

Best Regards, ayrton-senna.net|ayrton-senna-dasilva.com Team

Post count: 11

Thanks for the information. Wordfence has taken down the warning on my site which means this should be ok now.

Post count: 65

Hi,

Need your help urgently.

I got this malware message in last few days.

So I removed the TagDiv websites urls from the affected files such like

td_config.php
td_api.php
td_cake.php
td_panel_header.php

and many others.

Now I am getting these error in the dashboard, also few plugins are not working properly, there are delay in new plugin install, deleting and updating.

And this url (http://www.topfivebuzz.com/wp-admin/) is giving the error mentioned below

Warning: Cannot modify header information – headers already sent by (output started at /home2/mayanzc1/public_html/topfivebuzz/wp-content/themes/Newsmag/includes/td_config.php:1) in /home2/mayanzc1/public_html/topfivebuzz/wp-includes/pluggable.php on line 1174

Looking forward to your help.

Thanks & Regards
Debarup

Post count: 65

Hi,

Need your help urgently.

I got this malware message in last few days.

So I removed the TagDiv websites urls from the affected files such like

td_config.php
td_api.php
td_cake.php
td_panel_header.php

and many others.

Now I am getting these error in the dashboard, also few plugins are not working properly, there are delay in new plugin install, deleting and updating.

And this url (http://www.topfivebuzz.com/wp-admin/) is giving the error mentioned below

Warning: Cannot modify header information – headers already sent by (output started at /home2/mayanzc1/public_html/topfivebuzz/wp-content/themes/Newsmag/includes/td_config.php:1) in /home2/mayanzc1/public_html/topfivebuzz/wp-includes/pluggable.php on line 1174

Looking forward to your help.

Thanks & Regards
Debarup

Post count: 9544

Only the forum got infected,
So you need to put the working theme files back for your system to work.

Post count: 22421

Hello,
The threat has been eliminated and you can restore the theme back to it;s original state. Please make sure your anti-virus did not delete any files from the install. Just to be sure, update your theme again using the main theme package you download from envato and use this guide: https://forum.tagdiv.com/how-to-update-the-theme-2/
Thank you!

Viewing 15 posts - 1 through 15 (of 15 total)
The forum ‘Newspaper’ is closed to new topics and replies.