Imunify 360 flags Helix Ultimate's default php as malware — how to fix it
The problem:
Imunify 360 (running on many Plesk/cPanel hosts) sometimes flags this file as malicious:
plugins/system/helixultimate/overrides/com_content/article/default php
The detection signature is usually something like:
SMW-BLKH-SA-CLOUDAV-php bkdr drpr
When this happens, Imunify quarantines or deletes the file, and your Joomla articles stop displaying properly on the frontend.
Important context:
- mySites.guru does NOT flag this file as malware* — because it isn't
- The file is legitimate JoomShaper code, GPL-licensed
- The detection appears to be a false positive on Imunify's signature database.
How to fix it (safe method):
- Verify it's the real file — download the latest Helix Ultimate Framework fresh from joomshaper.com, and optionally scan the zip with Bitdefender, VirusTotal, or another AV. And claude ai. If it comes back clean, you're good.
- Add the file path to Imunify's ignore/whitelist. BEFORE reinstalling:
- In Plesk → Security → ImunifyAV / Imunify360
- Find the detection in History or Quarantine
- Add path to Ignore List
- Reinstall Helix Ultimate through Joomla admin:
- System → Install → Extensions
- Upload the fresh Helix Ultimate plugin
- Wait for "Installation successful"
- Test: open your homepage, click an article, verify frontend loads correctly.
5.Verify persistence: wait 10 minutes and check via FTP that the file still exists on the server. If Imunify deleted it again, revisit the whitelist step.
Why this happens:
Complex PHP template code that dynamically generates HTML output (like Helix does) sometimes trips generic malware signatures. Commercial AV scanners occasionally match on patterns that look suspicious in isolation but are perfectly normal in context. This is a known trade-off of aggressive signature-based scanning.
Bottom line:
If you see this detection, don't panic — but do verify. Download the file fresh from the official source, cross-check with another scanner, whitelist the path, and reinstall. If a second-opinion scanner (mySites.guru, VirusTotal, Bitdefender) all come back clean, you're dealing with a false positive.
If you're not sure whether it's a false positive on your site (e.g. your site was recently compromised), you can also check the flagged file directly by comparing it with the copy inside a freshly-downloaded Helix Ultimate zip. If they match byte-for-byte, the file is clean.
Or ask your host to check the file when your not sure.
Quick database check after a suspected Joomla hack
Even after cleaning malicious files, attackers sometimes leave traces in the database. Three quick SQL queries in phpMyAdmin will tell you if anything is left behind.
Log into phpMyAdmin via your hosting panel → select your Joomla database → open the SQL tab. Run these three checks (use your actual database prefix from configuration file)
1.List all users, sorted by registration date. Watch for emails ending in ‘secure local, usernames like webmanager + a number, or accounts you don't recognise — typical signs of the SP Page Builder zero-day and similar attacks.
- List all accounts in the Super Users group. Ideally, only your own account appears here.
3.List all "Remember me" auto-login tokens. Each row here allows automatic login without a password — anything you didn't create is suspect.
If all three come back with only your own account and expected activity, combined with clean file scans, that's strong evidence the attacker didn't establish persistence.