I received this message from TagDiv support. Let’s hope it works:
Hi,
That is indeed the malware – https://labs.sucuri.net/blacklist/info/?domain=fast.quickcontentnetwork.com I found it as well on a few websites while I was investigating similar issues. Checking in the Live CSS option is a very important step in cleaning the malware, I’m not sure my colleagues from the forum didn’t mention it. We added a filter for the Live CSS in newer theme versions, which doesn’t allow malware to be entered there anymore. But if the website was infected while using an older theme version, updating the theme doesn’t solve the problem. What you have to do after updating the theme is open the Live CSS and press save – https://prnt.sc/a4XFrTI5j9tb That is it, the malware will be removed from there.
But I would still have a few suggestions based on what I encountered in other cases:
– In case you have not already, check in the plugins folder using a file manager (cPanel, FTP, etc.) to see if there are plugins there which you did not install. The plugins may not show up in wordpress but they could be there.
– Scan the website with wordfence.
– Check the website users.
The website does appear to be clean now – https://sitecheck.sucuri.net/results/https/www.marcocalvo.it There’s nothing in the Live CSS and no unusual scripts loading. If I can help with something let me know.
Regards.
Thank you Ganuk007,
I found the malware in the td_live_css_local_storage table. Do we need to delete all the content of the field or just the string:
(/style)(script src="https://fast.quickcontentnetwork.com")(/script)(style)
Dear Anamaria, you keep writing that you have solved the problem and we keep telling you that instead the problem has not been solved. How can we get through this stage? Is there any hope that you will listen to your users and finally commit to really solving the problem?
Thanks for the suggestion, but the theme is up to date. Yet there continue to be problems. I would be happy if you found a more effective solution, making a greater effort to solve a very serious problem. I also say this in your interest, I will not be able to advise my clients to adopt your themes if you do not solve these serious security issues. And maybe other web agencies will behave the same way too (if you do a search online, many users are complaining).
-
This reply was modified 2 years by
Marco Calvo.
Yes, I use both WordFence and the antivirus provided by SiteGround. But these tools are not reliable. Both say everything is OK, unfortunately, however, every now and then some users get hijacked to pornographic sites or sites containing malware. Perhaps the new version of tagDIV Composer also contains vulnerabilities.
Yes, I reinstalled WordPress, checked for unauthorized users, checked plugins, etc. Everything seems OK, but you still get hijacked occasionally to other sites.
Why isn’t a tool released that checks all the problems caused by the “tadDIV Composer” plugin? So many Internet sites have been damaged because of the incorrect design of this plugin.
I did everything you recommended, unfortunately, however, the problem was not solved.
The reason is simple. The file “no-img-post.png” missing in the ZIP archive “ThemeForest-5489609-newspaper-wordpress_theme” downloaded from Themeforest.net.
Translated with Google Translate.