• Hello. It all started when my website http://www.restorethemagic.org was hacked. It got nasty popups all over it.

    https://codex.wordpress.org/FAQ_My_site_was_hacked I followed this article to the best of my ability. I’m afraid I’m not very technical and created this for a bunch of kids. I ended up having to reinstall WordPress.

    Now I get this error:

    Not Found
    The requested URL /tags/4.2.2/.fastinclude was not found on this server.

    Apache Server at core.svn.wordpress.org Port 80

    When I google it, it seems to indicate something has gotten turned off or a file is missing but I have not been able to locate it. thank you for taking the time to read this. I’m just hoping to get pointed into the right direction.

    -Niki

Viewing 15 replies - 1 through 15 (of 15 total)
  • This really seems like a server issue. Have you asked your hosting provider to look at the site for you?

    Thread Starter NikiSB

    (@nikisb)

    My host is insisting its an issue with the theme or the core in WordPress and recommends reinstall although I’ve done that. They just tell me to do it again. I seem to have fixed it by renaming the file to .fastinclude.off which caused the error to go away in the footer and in the backend. Got the theme previews working again. Some of the themes still don’t show up correctly, with everything indented to the left. Others work fine. Some things still seem off, in the footer, but others work right. It’s better than it was.

    Do you have any security plugins installed? Wordfence is very good. If you install it (the free version) I will tell you how to best configure it.

    You may still have some malware on your site.

    Thread Starter NikiSB

    (@nikisb)

    I have Wordfence installed and have had the free version of Sucuri installed. What’s the best way to configure it please?

    The free version of Sucuri is not a server side scanner and will not find certain kinds for malware.

    As for Wordfence, go the your Dashboard > Wordfence > Options > find the section titled “Scans to include” and tick all the boxes in this section. Then scan.

    If the scan finds issues, post back here before you delete anything.

    Thread Starter NikiSB

    (@nikisb)

    It found some issues.

    Now I did completely change all the images on my theme Modern Multi-Purpose. Not sure about the header.php and the footer.php. It did detect all the changes to those files from the originals

    This file may contain malicious executable code/home/restoret/public_html/boards/rewrite.php
    Filename: boards/rewrite.php
    File type: Not a core, theme or plugin file.
    Issue first detected: 8 mins ago.
    Severity: Critical
    Status New
    This file is a PHP executable file and contains the word ‘eval’ (without quotes) and the word ‘urldecode(‘ (without quotes). The eval() function along with an encoding function like the one mentioned are commonly used by hackers to hide their code. If you know about this file you can choose to ignore it to exclude it from future scans.

    Modified theme file: wp-content/themes/modern-multipurpose/header.php
    Filename: wp-content/themes/modern-multipurpose/header.php
    File type: Theme
    Issue first detected: 15 mins ago.
    Severity: Warning
    Status New
    This file belongs to theme “Modern Multipurpose” version “1.3” and has been modified from the original distribution. It is common for site owners to modify their theme files, so if you have modified this file yourself you can safely ignore this warning.

    Tools:View the file. Restore the original version of this file. See how the file has changed.
    Select for bulk repair
    Resolve:I have fixed this issue Ignore until the file changes. Always ignore this file.
    Modified theme file: wp-content/themes/modern-multipurpose/footer.php
    Filename: wp-content/themes/modern-multipurpose/footer.php
    File type: Theme
    Issue first detected: 15 mins ago.
    Severity: Warning
    Status New
    This file belongs to theme “Modern Multipurpose” version “1.3” and has been modified from the original distribution. It is common for site owners to modify their theme files, so if you have modified this file yourself you can safely ignore this warning.

    Tools:View the file. Restore the original version of this file. See how the file has changed.
    Select for bulk repair
    Resolve:I have fixed this issue Ignore until the file changes. Always ignore this file.

    Modified plugin file: wp-content/plugins/wp-sticky/readme.txt
    Filename: wp-content/plugins/wp-sticky/readme.txt
    File type: Plugin
    Issue first detected: 15 mins ago.
    Severity: Warning
    Status New
    This file belongs to plugin “WP-Sticky” version “1.52” and has been modified from the file that is distributed by WordPress.org for this version. Please use the link to see how the file has changed. If you have modified this file yourself, you can safely ignore this warning. If you see a lot of changed files in a plugin that have been made by the author, then try uninstalling and reinstalling the plugin to force an upgrade. Doing this is a workaround for plugin authors who don’t manage their code correctly. [See our FAQ on http://www.wordfence.com for more info]

    Tools:View the file. Restore the original version of this file. See how the file has changed.
    Select for bulk repair
    Resolve:I have fixed this issue Ignore until the file changes. Always ignore this file.
    Modified plugin file: wp-content/plugins/wp-photo-gallery/readme.txt
    Filename: wp-content/plugins/wp-photo-gallery/readme.txt
    File type: Plugin
    Issue first detected: 15 mins ago.
    Severity: Warning
    Status New
    This file belongs to plugin “wp photo gallery” version “1.0” and has been modified from the file that is distributed by WordPress.org for this version. Please use the link to see how the file has changed. If you have modified this file yourself, you can safely ignore this warning. If you see a lot of changed files in a plugin that have been made by the author, then try uninstalling and reinstalling the plugin to force an upgrade. Doing this is a workaround for plugin authors who don’t manage their code correctly. [See our FAQ on http://www.wordfence.com for more info]

    Tools:View the file. Restore the original version of this file. See how the file has changed.
    Select for bulk repair
    Resolve:I have fixed this issue Ignore until the file changes. Always ignore this file.

    Modified plugin file: wp-content/plugins/wordpress-importer/readme.txt
    Filename: wp-content/plugins/wordpress-importer/readme.txt
    File type: Plugin
    Issue first detected: 15 mins ago.
    Severity: Warning
    Status New
    This file belongs to plugin “WordPress Importer” version “0.6.1” and has been modified from the file that is distributed by WordPress.org for this version. Please use the link to see how the file has changed. If you have modified this file yourself, you can safely ignore this warning. If you see a lot of changed files in a plugin that have been made by the author, then try uninstalling and reinstalling the plugin to force an upgrade. Doing this is a workaround for plugin authors who don’t manage their code correctly. [See our FAQ on http://www.wordfence.com for more info]

    Tools:View the file. Restore the original version of this file. See how the file has changed.
    Select for bulk repair
    Resolve:I have fixed this issue Ignore until the file changes. Always ignore this file.

    Modified plugin file: wp-content/plugins/sweetcaptcha-revolutionary-free-captcha-service/readme.txt
    Filename: wp-content/plugins/sweetcaptcha-revolutionary-free-captcha-service/readme.txt
    File type: Plugin
    Issue first detected: 15 mins ago.
    Severity: Warning
    Status New
    This file belongs to plugin “Sweet Captcha” version “3.1.0” and has been modified from the file that is distributed by WordPress.org for this version. Please use the link to see how the file has changed. If you have modified this file yourself, you can safely ignore this warning. If you see a lot of changed files in a plugin that have been made by the author, then try uninstalling and reinstalling the plugin to force an upgrade. Doing this is a workaround for plugin authors who don’t manage their code correctly. [See our FAQ on http://www.wordfence.com for more info]

    Also found this one.

    This file may contain malicious executable code/home/restoret/public_html/boards/rewrite.php
    Filename: boards/rewrite.php
    File type: Not a core, theme or plugin file.
    Issue first detected: 23 mins ago.
    Severity: Critical
    Status New
    This file is a PHP executable file and contains the word ‘eval’ (without quotes) and the word ‘urldecode(‘ (without quotes). The eval() function along with an encoding function like the one mentioned are commonly used by hackers to hide their code. If you know about this file you can choose to ignore it to exclude it from future scans.

    Yes, you have more malware to fix. You also have a theme issue. Your theme has not been updated in just over two years. No support has been given in over two years as well.

    I need to do some research before I can make a suggestion about the need go to to a new theme. Even if I find the theme still meets guidelines, it is only a matter of time before you will have to change for safety reasons. What do you think about changing themes now>

    Your site seems to have a lot of unusual subdirectories. Do you have a number of other sites in the same hosting account? Specifically what is in the /boards/ and /tags/ subdirectories?

    Thread Starter NikiSB

    (@nikisb)

    Yes. I have a forum. Punbb is installed in on the boards.restorethemagic.org and I think rewrite.php belongs to it. I’ve never really used it though.

    I’m not sure where the /tags/ directory is. I found the fastaccess file in my public_html directory where I renamed it.

    I am willing to go to another theme. But am having a hard time finding one that can be modded just right to look similar enough to the old one. Zero Gravity seems to work alright most of the time though so I can change to that one. Do you have any good recommendations?

    How can I remove the rest of the malware?

    At one point I had BBPress and Pressbuddy installs as well but had alot of stability issues with both pluggins and had a tags plugin installed with that. But that plugin was not in my backup.

    Download any subdirectories you are not using or hasn’t been kept up to date to a file on your workstation then delete the files you downloaded from the server. Check to make sure your site is still working (at least as well as it is now).

    A stock install only has three directories: wp-contents, wp-includes and wp-admin. I’m not saying you can’t have others but anything you leave should contain new up to date files.

    Download all the themes on the site to your workstation and delete the themes on the server. If you want to use Zero Gravity load a clean new copy to the server. Load a clean new version of Twenty Fifteen to use as a default.

    Check again to make sure your site is still working and then replace all the plugins. You can delete them one at a time and load new and check the site if you like. If you delete and reload the plugins using FTP all the options should stay as they were. If you delete and reload the plugins from the dashboard, you will probably loose the plugin options you configured.

    If you deleted everything but wp-content and wp-config.php earlier and installed new WordPress files then you should have a nice clean up to date site. It would be a good idea to run a new Wordfence scan to verify.

    Thread Starter NikiSB

    (@nikisb)

    Thank you for all your help. The site is now coming up clean in scans.

    Wow! It is very colorful.

    I’m glad you fixed it. Wordfence will help you keep it clean.

    It looks like you may still have some malware. I tried it with Internet Explorer. After it opened I clicked the logo and I got a popup that I couln’t close.

    Thread Starter NikiSB

    (@nikisb)

    I thought I had it clean. Woke up this morning and now the popups are coming up again. I’m really at a loss. Wordfence is coming up clean. My host is offering to terminate then recreate my account with them so everything is back to scratch but that seems pretty drastic. Do you have anymore suggestions?

    Thread Starter NikiSB

    (@nikisb)

    Since you double posted guess I can get away with it. I think I figured out the culprit to be the emailit share buttons plugin. After reloading the plugins again without it I seem to be not getting spam and I noticed in chrome when using adblock no popups or scripts are being blocked. Huh. Well do you have any recs for cute social media buttons under the posts?

    wslade

    (@wslade)

    I hate to be the one always giving you bad news but that plugin likely did not get installed with malware. I believe you when you say the plugin had malware but it probably became infected from some other source in your site. You reloaded all new plugins, right?

    Your site was damaged pretty badly and it is often difficult to find all the malware. If you haven’t noticed from the link attached to my name, I do this for a living.

    If I were you, I would take your host up on their offer. Especially if terminate and recreate means deleting and restoring from a known good backup. If they do a restore, your plugin configurations and everything will still be there.

    All those unused subdirectories will be there as well as a possibly unsafe theme. So there will be considerably more work to be done after the host finishes the restore before you can feel safe with your site.

    You mentioned that this seems drastic but I consider all the work you have already put into cleaning the site to be pretty drastic and it’s probably not fixed yet.

    If you really do not want to go with the host’s restore, I can help you scan for the rest of your malware. But here is why scanning and looking is so difficult. The average WordPress site has about 4000 files. Each file might average a 1000 lines of code. So the average WordPress site might have 4 million lines of code. It only takes one line of code for a hacker to have a backdoor into your site.

    If you have questions, just post back here.

Viewing 15 replies - 1 through 15 (of 15 total)

The topic ‘.fastinclude was not found on this server.’ is closed to new replies.