I have a problem with the website www.f1miras14-kunstschmiede.de. The problem of website infection has already occurred several times.
I managed to create a backup and it worked, but the problem would return after two or three weeks. Today, even restoring a backup doesn't help.
f1miras14-kunstschmiede.de
Accepted answer
Marked as the solutionYes, I hope so. You can also use security protection tools/extensions, as well as server-level security tools, to provide additional protection and prevent the infection from happening again.
If everything is working fine now, please mark the question as complete by accepting any of our answers.
Thank you!
9 more replies
Hello,
We sincerely apologize for the inconvenience caused.
This issue has been fixed from SP Page Builder from v6.6.2 to v6.9.1. Once you upgrade to v6.9.1 or latest, this specific vulnerability can no longer be exploited.
However, if your site was compromised before upgrading, simply updating the extension will not remove any malicious files or backdoors that may have already been uploaded. If those files remain on the server, attackers may still be able to access your site. Therefore, it is important to perform a complete cleanup before considering the site secure.
Please follow the cleanup guide here: https://www.joomshaper.com/documentation/sp-page-builder/troubleshooting#how-to-clean-an-infected-joomla-4x-6x-site
Please, makesure your all extension including Helix Ultimate or Helix3 is up to date with latest version.
**Edit:
Please update your php version to latest like v8.1 or 8.3, Your site shows, current php version is not supported for current Joomla**
Please, let us know the update, We'll be happy to help.
Thank you.
If you don't update SPPB even with cleaned infection - malware code may return.
This is MUST HAVE step.
PHP version can be changed in Hosting Panel (cPanel or similar) or by Hosting Support.
I have .htaccess.json files and I can't delete them.
The problem is also that I cannot log in to the administrator panel to perform updates.
In that case ask Hosting Support for help.
From Hosting Panel (not Joomla Admin)
- File Manager / or / FTP - you should be able to delete all "weird & suspicus" files.
- You can change PHP version from current 7.x to PHP 8.2/PHP 8.3 (for example)
- Recover site from backup (5, 10 days old)
Sorry, but those steps are on your side.
I can't use FTP or access the files! I'm also trying to change the PHP version in cPanel, but it says it's not possible; I have a secure backup from a few months ago, but that hasn't helped.
You might find that there is nothing you can do to access FTP.
I'm deleting files from the 'image' folder, but they all come back after refreshing!
Cleaning server from hacker actions is not on our side. It's beyond typical (free) support.
Returning files means that hacker hidden extra file that recovers them. Quite popular.
Please ask hosting support to scan your site deeply, and delete all suspicus. It can be also beyond /public_html/. Yes, they should have Firewall tools for that.
2nd option, would be to zip whole website (all files), download zip to your computer and scan using good Antivirus software and Malwarebytes tool (free is OK). Then after removing all weird files, delete files on server and upload cleaned package. Then run Joomla > install firewall and scan site again, update etc. It should take you about 1-2 hours. But it's free, your time only.
Unfortunately, we live in a time when the number of attacks on websites (private, commercial, medical, goverment) is enormous.
I also can't delete the JSON file from the server.
In that case, Hosting Support should help, right. Create a support ticket with details for them.
Focus on things that YOU STILL CAN DO, not cannot.
Hello, it has been pointed out that the only thing that cannot be done is updating SP Page Builder. You can check this.
Please, check now, I have updated sp page builder pro to latest.
Thanks
Should the shaper_qubic device also be connected, or is it not possible to connect it?
Now that the specified files have been removed, the server and administrator passwords changed, Joomla updated, the PHP version changed, and so on, will the site work correctly?