Skip Navigation

[Resolved] Trojan detected in Types files

This is the technical support forum for Toolset - a suite of plugins for developing WordPress sites without writing PHP.

Everyone can read this forum, but only Toolset clients can post in it. Toolset support works 6 days per week, 19 hours per day.

Sun Mon Tue Wed Thu Fri Sat
- 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 -
- 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 -

Supporter timezone: Asia/Kolkata (GMT+05:30)

This topic contains 4 replies, has 2 voices.

Last updated by Minesh 10 months, 3 weeks ago.

Assisted by: Minesh.

Author
Posts
#2684153

I just did a SUPERAntiSpyware scan of my site that's in development, and it flagged 2 Types plugin files as having "Trojan.Dropper/Gen-PHP":

\WP-CONTENT\PLUGINS\TYPES\APPLICATION\CONTROLLERS\API.PHP
\WP-CONTENT\PLUGINS\TYPES\APPLICATION\CONTROLLERS\CACHE\SHORTCODE_GENERATOR\TERMMETA.PHP

Is this something you're aware of? Is it really malware in your files? Either way, can I delete these files and replace them from a fresh download?

Also, how do I get notified when support replies to a ticket like this? I haven't been getting notifications.

Thanks.

#2684184

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

Hello. Thank you for contacting the Toolset support.

I see your name is already added for notification. Please let me know if you do not get the email notification.

Regarding the issue - it seems its due to the file names confuses the trojan detector software like api.php which I see is the part of the plugin file already.

However - please allow me to get in touch with concern person and I will get in touch with your as soon as I can.

#2684221

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

I checked with the concern person but we would like to have more information on the analysis, maybe even a copy of those files affected files.

We also would recommend replacing the files you shared with a fresh copy from the latest release of Toolset Types plugin for safer side. It could be possibly nothing issue or something but we can verify that after we get more information about the analysis on those files and copy of those files.

#2684330

Thank you. I ran another scan and it didn't find anything this time. False positive, maybe?

I'll replace the files, though. How do I reinstall without losing my data?

And how do I give you copies of the files?

Also, no, I'm still not getting the notifications.

#2684352

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

Thank you. I ran another scan and it didn't find anything this time. False positive, maybe?
===>
Yes - that could be possibly as I do not see any other user reported such issue as of now.

I'll replace the files, though. How do I reinstall without losing my data?
===>
You should just login to FTP and navigate to the said path and try to replace the existing file(s) with the new file(s). You can download the latest plugin files from your account's download section:
- https://toolset.com/account/downloads/

And how do I give you copies of the files?
===>
You can upload it on any file sharing service and send me the download link.

Also, no, I'm still not getting the notifications.
==>
That is really strange. I will enable the debug for notification.