Home User profile
tagDiv Member
This user did not write anything. So we are just showing here some random text to make the profile page look nice :)
ganuk007
tagDiv Member

Hello Marco Calvo,

Attempting to delete that field won’t work; it won’t delete. If you try to delete it, it will automatically regenerate as it’s a Balada Malware Injector.

Therefore, you’ll need to reinstall the theme manually. Follow Step 5 & Step 6 as outlined above. & Before this don’t forget Step 2: Backup

Hopefully, this will work for you.

  • This reply was modified 2 years by ganuk007.
  • This reply was modified 2 years by ganuk007.
ganuk007
tagDiv Member

Hello everyone,

I managed to resolve this issue manually. Please follow the steps below to help address the malware problem:

Step 1: Identification
Firstly, locate the malware within the database. Look for a row in the wp-option table named td_live_css_local_storage that contains JavaScript code resembling fast.quickcontentnetwork.com within the option value.

Click here to see snaps

Step 2: Backup
Ensure you create a backup of your current site or application.

Step 3: Deactivate td-composer
Deactivate td-composer and proceed to delete it.

Step 4: Download the Newspaper zip file
Unzip and manually upload the plugin from the following path – Newspaper-tf > plugins > td-composer. If the issue persists, proceed to step 5.

Step 5: Manual Theme Reinstallation
Remove the theme from the server. Navigate to public_html > wp-content > themes and delete the “Newspaper” folder.

Step 6: Reinstall the Theme
Head to the WordPress dashboard, navigate to Appearance > Themes, click on Add New Theme, and install the theme.

Following these steps should help resolve the malware issue. Feel free to provide any feedback or if you need further assistance.

  • This reply was modified 2 years by ganuk007.
  • This reply was modified 2 years by ganuk007.
ganuk007
tagDiv Member

Hello Anamaria/tagdiv team,

I wanted to inform you that the same issue has occurred. I reported it to SiteGround, and they mentioned that there seems to be an issue within the theme itself—a malware presence in the database is causing unwanted redirects to other sites, classifying it as adware. Users are experiencing unwanted pop-ups and redirections when visiting our site. Specifically, there is a row in the wp-option td_live_css_local_storage that contains JavaScript code resembling fast.quickcontentnetwork.com within the option value.

Furthermore, there’s a problem with updating my theme to version 12.6.2. Whenever I attempt the update, it redirects me to the Dashboard instead of completing the process. Could you please assist me in understanding why this is happening? Your help would be greatly appreciated.

Viewing 3 posts - 1 through 3 (of 3 total)