Virus on update?

Posted in: Newspaper
Post count: 26

I received this mail from the server, i scan with avast the newspaper.zip but is clean:

El dominio xxxxxx ha subido ficheros desde ES con la IP 181.xxx.xxx.xxx. ste es el fichero:
/furanet/sites/xxxxxx/web/htdocs/wp-content/themes/Newspaper/includes/wp_booster/external/td-old-class-tgm-plugin-activation.php

El BS lo detecta como malicioso por:
POSITIVO en (“php shell”|Locus7s|”c100 shell”|emp3ror|afe0ver|M4il3r|T3MPL3|N3tsh|FilesMan|kebsyno|DEFAULT_DIR_DEEP_BACK|system_custom\()|By POKAMOM|jewsforjudaismg|r0nin|m0rtix|upl0ad|r57shell|c99shell|shellbot|phpshell|phpremoteview|directmail|bash_history|multiviews|cwings|vandal|bitchx|eggdrop|guardservices|psybnc|dalnet|undernet|vulnscan|spymeta|raslan58|Webshell|FilesTools|bckdrprm|hackmeplz|wrgggthhd|Arhack\.Net|WSOsetcookie|”By HasnZin”|”[S]uper[BAD] Mailer”|_GET[w….t]|aHR0cDovL21icm93c2Vyc3RhdHMuY29tL3N0YXRIL3N0YXQucGhw|”HighTech Brazil HackTeam

Post count: 3

Trata de eliminar la copia anterior y resubir el theme nuevamente.
No hay ningún virus.

Post count: 31

Holy shite!!! What the heck????

Post count: 26

Que alegria escuchar español jejeje, gracias por el consejo, he borrado todo por completo y volvi a subirlo, y me llegan dos emails del servidor por estos dos archivos:
El dominio xxxxxx ha subido ficheros desde ES con la IP 181.xxxxxx Este es el fichero:
– web/htdocs/wp-content/themes/Newspaper/Newspaper/includes/wp_booster/external/td-old-class-tgm-plugin-activation.php
– web/htdocs/wp-content/themes/Newspaper/Newspaper/includes/wp_booster/external/class-tgm-plugin-activation.php

En cada uno pone lo mismo:

El BS lo detecta como malicioso por:
POSITIVO en (“php shell”|Locus7s|”c100 shell”|emp3ror|afe0ver|M4il3r|T3MPL3|N3tsh|FilesMan|kebsyno|DEFAULT_DIR_DEEP_BACK|system_custom\()|By POKAMOM|jewsforjudaismg|r0nin|m0rtix|upl0ad|r57shell|c99shell|shellbot|phpshell|phpremoteview|directmail|bash_history|multiviews|cwings|vandal|bitchx|eggdrop|guardservices|psybnc|dalnet|undernet|vulnscan|spymeta|raslan58|Webshell|FilesTools|bckdrprm|hackmeplz|wrgggthhd|Arhack\.Net|WSOsetcookie|”By HasnZin”|”[S]uper[BAD] Mailer”|_GET[w….t]|aHR0cDovL21icm93c2Vyc3RhdHMuY29tL3N0YXRIL3N0YXQucGhw|”HighTech Brazil HackTeam”

Tenga en cuenta que es posible que sea un falso positivo. Es posible que alguna cadena usada en su fichero coincida con una cadena usada por Malware. Por este motivo si despues de revisar su codigo considera que es correcto, no es necesario que realice nada, ya que este correo es para avisarle de un posible peligro, pero no bloquea o elimina ningun fichero.

He echado un ojo a los archivos que dice pero mis conocimientos de php son casi nulos 🙁

Gracias por la ayuda por cierto!!

Post count: 31

This doesn’t look like a false positive, and PLEASE USE ENGLISH for gods sake!!!

Post count: 26

sorry, I reupload and revised the both files:
– web/htdocs/wp-content/themes/Newspaper/Newspaper/includes/wp_booster/external/td-old-class-tgm-plugin-activation.php
– web/htdocs/wp-content/themes/Newspaper/Newspaper/includes/wp_booster/external/class-tgm-plugin-activation.php

But my php not good enough to know if is a false positive or not 🙁

Post count: 260

No es un virus despreocupa.

Post count: 9544

Remember when updating to DELETE old theme and TD plugins, and upload NEW theme and plugins; including NEW child theme if you use one!

Try using my sticky upgrade guide or you may be sorry.

It’s a new version of theme; you may need to redo your home page for some modules, and reset sidebars.

It’s an UPGRADE not an update.

Post count: 26

Solved, the hosting staff taked a look to the files and confirm was a false positive 😉

Viewing 9 posts - 1 through 9 (of 9 total)
You must be logged in to reply to this topic.