I can see those ads. It looks like your website has been hacked.
There is a suspicious javscript file in the source coming from:
3uorg03dxfy.ru / jsi / ormes.js
Try running a scan with http://www.quttera.com/#
Otherwise, install and run https://ww.wp.xz.cn/plugins/gotmls/
Run a full scan.
Update (or reinstall WordPress)
Update all plugins
Install iThemes Security and lock down your site
Thread Starter
vchang
(@vchang)
I ran the scan on quterra.com and it comes back as negative on any issues. I also installed the plugin, gotmls, and it also says the site files are clean. Could it be the browsers’s extensions causing this?
Thread Starter
vchang
(@vchang)
Now I am not getting the pop up ads but I am seeing an outgoing call to a website from my real-time malwarebytes to some website gpy.diminishingunvalidated.com
I usually find that when a WordPress website is hacked to publish malicious ads that there is usually something extremely funky in the .htaccess file that triggers an external javascript. You may want to examine your .htaccess file to see if there is any malicious code in there.
Regards,
AJ
It’s definitely not a browser extension because I was seeing it as well.
It’s embedded in the source. GOTMLS and Quttera can miss these things sometimes.
Best bet is to re-install everything.
Dashboard -> Updates
– Reinstall WordPress
– Upgrade everything.
– Try re-installing themes as well (if you already have current version, download that version and unpack the files over the top of current install)
– Do the same for plugins
Thread Starter
vchang
(@vchang)
Definitely not a browser extension issue. I found the spyware code in an iframe tag in one of the pages. All is working now. Good thing I did not have to reinstall everything as a fresh copy.
I installed gotmls and wordfence and these seem to have fix some of the issues too. Thanks for all the helpful comments and tips. You guys are the best!
Thread Starter
vchang
(@vchang)
It was extra code in the Woocommerce Shop page. There should have been no code there but there was some code so I just deleted the code on the page. Unfortunately, I do no the code to post here anymore.