• Resolved billwb52

    (@billwb52)


    Need help with a malware problem. I have 2 websites, both have WP with Woocommerce plugins. My main site; a1rd.net has tradeadexchange.com popup malware either embedded on HostGator or my cPanel files. At random or after so many clicks only on my site (a1rd.net), This tradeadexchange.com malware will popup a page either to fool you to think you have a problem and to call an 800 number to fix, or some page to update your flashware.. It happens on other remote computers also; ONLY on my web site.. Popup blockers do not work, I have scanned my site with a malware plugins. I have tried to delete files and themes, also checked my registry. My other site is on the same hosting public.htp files and I have no problem with it! I have scanned My computer for grins but comes up blank! Any ideas or suggestions ???? Thanks!

Viewing 15 replies - 1 through 15 (of 20 total)
  • webdesignerchristian

    (@webdesignerchristian)

    disable all plugins and set theme to 2015 then test and reply

    Andrew Nevins

    (@anevins)

    WCLDN 2018 Contributor | Volunteer support

    Thread Starter billwb52

    (@billwb52)

    Someone replied to delete plugins and themes and try it. Well I deleted all from the WP side and still got one popup. Then I deleted all files from the themes and plugin folders from Cpanel except for one! So far no popups have occurred.. I will wait for just to make sure.. My next question, Should I re-install only the necessary themes & plugins to operate my site ?

    Thanks Bill

    webdesignerchristian

    (@webdesignerchristian)

    please reinstall all your themes and plugins. most likely the maleware was inside one of your plugins and placed there at initial breach. since you have closed the door and removed the infection you should be good to reinstall all your plugins… again reinstall plugins form reserve. do not ftp a backup. backup may be infected also. reisntall your theme. check site and you should be clean and functioning at 100%

    To avoid breach. always maintain updates for themes and plugins as well as the core.

    I would also install wordfence for security.

    Andrew Nevins

    (@anevins)

    WCLDN 2018 Contributor | Volunteer support

    Though it doesn’t sound like you dealt with the backdoor.

    webdesignerchristian

    (@webdesignerchristian)

    I am assuming bill scanned site, changed passwords and updated.

    Did i miss something @andrew?

    oh one more thing scan your computer. change email passwords too.

    Thread Starter billwb52

    (@billwb52)

    Well, After re-installing only woo commerce and max store. I still got popups from tradeadexchange.com again. It did not popup when I had 20-15 loaded.. Could it be embedded in an image or something else ? I do have amazon links on some products.. All of my products and images were still in folders. Do i have to start all over again and reload products and images ?? Any other things I can try ??

    webdesignerchristian

    (@webdesignerchristian)

    try this and look for tradeadexchange.com or eval(base64_decode
    https://wordpress.org/plugins/search-and-replace/

    Thread Starter billwb52

    (@billwb52)

    Here’s the only eval I can find; other does not show up on search.

    /public_html/wp-content/plugins/woocommerce/includes/shipping/flat-rate/includes/class-wc-eval-math.php

    /public_html/shimmer-wear.com/wp-content/plugins/woocommerce/includes/shipping/flat-rate/includes/class-wc-eval-math.php

    webdesignerchristian

    (@webdesignerchristian)

    did u alos search for the string tradeexchange?

    Thread Starter billwb52

    (@billwb52)

    Yes I have searched for tradeAdexchange but not able to locate any files. I cannot search the core files in Cpanel but I made sure there are no strange php files in my images and looked for suspicious php’s in folders. I deleted some more files and reloaded/Updated WP. And still got one popup from tradeAdexchange. I am experimenting now with what the public sees and what I see in WP Admin, I’m about to erase all of my files and reload everything again.. This malware is annoying

    webdesignerchristian

    (@webdesignerchristian)

    it may be embed into an image also

    Thread Starter billwb52

    (@billwb52)

    Well, I deleted WP and installed WP new and reloaded all of my products and slowly added images etc from my vendors. Went well for 2 weeks and that damn popup malware started again. I deleted the last several images I loaded and testing now.. One part of my site, I use some Amazon Associate links and photos to fill my page since I get a percentage on sales. Should I be suspicious of these or delete all linked products and photos ?

    Moderator t-p

    (@t-p)

    probably the backdoor is still open!

    also, when you’re done, you may want to implement some (if not all) of the recommended security measures.

    Thread Starter billwb52

    (@billwb52)

Viewing 15 replies - 1 through 15 (of 20 total)
  • The topic ‘Malware Popup’ is closed to new replies.