Hello,
I have the following problem: one of my sites with its Newspaper theme called http://www.imagenesyespecialistas.com has been presenting an issue for weeks where it only redirects to other advertising sites on the mobile version.
Before realizing that it was the TagDiv Composer, I used all the tools available to find the vulnerability. I debugged plugins one by one, but the problem persists.
I used Wordfence, Sucuri, Quttera Web Malware Scanner, and the tools provided by my hosting provider, but the problem still persists.
I consulted my hosting provider and this was their response:
“Hello,
We have been able to verify that the “td-composer” plugin is the cause of the problem.
You can disable the plugin and check again.
If the problem persists, please contact the corresponding plugin vendor.
Best regards,
Roshney P.
BanaHosting.com Inc.
Think Big, Think Bana!”
After receiving this message, I did the following:
I deleted the theme and reinstalled it, but the problem continues. I only installed the TagDiv Composer plugin after downloading it from https://themeforest.net/.
I would appreciate any help with this problem, as it would be very helpful for me and future individuals facing this issue. Thank you very much!
Hello,
Upon a quick analysis, I noticed that you’re using an older version of the theme.
Please update the theme to the latest version 12.6.5.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins;
– Delete the weird/unknown themes;
– Clean unfamiliar Theme Panel injected code (example – https://i.imgur.com/4q70kCv.png);
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)
If you’re not sure how to do it, our custom work team can help you with both theme updates and malware file cleanup https://tagdiv.com/submit-a-request/
Thank you!
Hello Anamaría,
After reading your response, I can tell that it seems like a robotic reply and you didn’t read carefully what I mentioned about my issue.
You’re telling me to update the theme to the latest version 12.6.5, which doesn’t exist in this theme. I’ve attached some screenshots for you to verify.
https://prnt.sc/5PFGbCQKfeWQ
https://prnt.sc/Yza1ViLf444P
You’re asking me to use tools like Wordfence to scan my site when I also mentioned the tools I’ve used, and it doesn’t detect the code in the tagDiv Composer. I would like your response to actually help me, not one that seems like I’m being assisted by a robotic support.
Thank you very much.
Hello,
You should download the latest version of it from the Theme Forest account and download it.
Also, please follow the steps above to identify and remove malware, even though you mentioned using Wordfence, I suggest using it after updating the theme and WordPress to check the files again.
Thank you!