F1miras14-kunstschmiede.de - Question | JoomShaper

is live, now with multi-currency selling.

F1miras14-kunstschmiede.de

K

Kluczycka

General 6 days ago

I have a problem with the website www.f1miras14-kunstschmiede.de. The problem of website infection has already occurred several times. I managed to create a backup and it worked, but the problem would return after two or three weeks. Today, even restoring a backup doesn't help.

0
15 Answers
Ziaul Kabir
Ziaul Kabir
Accepted Answer
Support Agent 5 days ago #234592

Yes, I hope so. You can also use security protection tools/extensions, as well as server-level security tools, to provide additional protection and prevent the infection from happening again.

If everything is working fine now, please mark the question as complete by accepting any of our answers.

Thank you!

0
Ziaul Kabir
Ziaul Kabir
Accepted Answer
Support Agent 6 days ago #234527

Hello,

We sincerely apologize for the inconvenience caused.

This issue has been fixed from SP Page Builder from v6.6.2 to v6.9.1. Once you upgrade to v6.9.1 or latest, this specific vulnerability can no longer be exploited.

However, if your site was compromised before upgrading, simply updating the extension will not remove any malicious files or backdoors that may have already been uploaded. If those files remain on the server, attackers may still be able to access your site. Therefore, it is important to perform a complete cleanup before considering the site secure.

Please follow the cleanup guide here: https://www.joomshaper.com/documentation/sp-page-builder/troubleshooting#how-to-clean-an-infected-joomla-4x-6x-site

Please, makesure your all extension including Helix Ultimate or Helix3 is up to date with latest version.

**Edit:

Please update your php version to latest like v8.1 or 8.3, Your site shows, current php version is not supported for current Joomla**

Please, let us know the update, We'll be happy to help.

Thank you.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 6 days ago #234530

If you don't update SPPB even with cleaned infection - malware code may return. This is MUST HAVE step.


PHP version can be changed in Hosting Panel (cPanel or similar) or by Hosting Support.

0
K
Kluczycka
Accepted Answer
6 days ago #234531

I have .htaccess.json files and I can't delete them.

0
K
Kluczycka
Accepted Answer
6 days ago #234532

The problem is also that I cannot log in to the administrator panel to perform updates.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 6 days ago #234534

In that case ask Hosting Support for help.

From Hosting Panel (not Joomla Admin)

  1. File Manager / or / FTP - you should be able to delete all "weird & suspicus" files.
  2. You can change PHP version from current 7.x to PHP 8.2/PHP 8.3 (for example)
  3. Recover site from backup (5, 10 days old)

Sorry, but those steps are on your side.

0
K
Kluczycka
Accepted Answer
6 days ago #234538

I can't use FTP or access the files! I'm also trying to change the PHP version in cPanel, but it says it's not possible; I have a secure backup from a few months ago, but that hasn't helped.

0
K
Kluczycka
Accepted Answer
6 days ago #234539

You might find that there is nothing you can do to access FTP.

0
K
Kluczycka
Accepted Answer
6 days ago #234533

I'm deleting files from the 'image' folder, but they all come back after refreshing!

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 6 days ago #234537

Cleaning server from hacker actions is not on our side. It's beyond typical (free) support.

Returning files means that hacker hidden extra file that recovers them. Quite popular. Please ask hosting support to scan your site deeply, and delete all suspicus. It can be also beyond /public_html/. Yes, they should have Firewall tools for that.


2nd option, would be to zip whole website (all files), download zip to your computer and scan using good Antivirus software and Malwarebytes tool (free is OK). Then after removing all weird files, delete files on server and upload cleaned package. Then run Joomla > install firewall and scan site again, update etc. It should take you about 1-2 hours. But it's free, your time only.


Unfortunately, we live in a time when the number of attacks on websites (private, commercial, medical, goverment) is enormous.

0
K
Kluczycka
Accepted Answer
6 days ago #234535

I also can't delete the JSON file from the server.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 6 days ago #234540

In that case, Hosting Support should help, right. Create a support ticket with details for them.

Focus on things that YOU STILL CAN DO, not cannot.

0
K
Kluczycka
Accepted Answer
5 days ago #234577

Hello, it has been pointed out that the only thing that cannot be done is updating SP Page Builder. You can check this.

0
Ziaul Kabir
Ziaul Kabir
Accepted Answer
Support Agent 5 days ago #234580

Please, check now, I have updated sp page builder pro to latest.

Thanks

0
K
Kluczycka
Accepted Answer
5 days ago #234581

Should the shaper_qubic device also be connected, or is it not possible to connect it? Now that the specified files have been removed, the server and administrator passwords changed, Joomla updated, the PHP version changed, and so on, will the site work correctly?

0