Spring Fresh Sale! - Up To 67% OFF BDIX Hosting + Free Domain
Malware Removal & Site Cleanup

How to Remove Malware from a Hacked Joomla Site

Discovering your Joomla site is infected is unsettling, but a methodical cleanup nearly always puts it right. The reliable approach is the same each time: contain the damage, find the malicious files, remove them, and then close the hole that let the attacker in. Rushing straight to deletion without that last step is how sites get reinfected.

Step 1: Contain it first

Before cleaning, change every relevant password — your Joomla admin, cPanel, database and FTP. A backup taken now (even of the infected site) preserves evidence and gives you a fallback. Take an offline full backup.

Step 2: Scan to find the infection

Run a server-side scan to locate malicious files quickly — see scanning with Imunify360. Note what it flags: unfamiliar PHP files, recently modified core files, and files in your images or tmp folders that should not contain code.

Step 3: Clean or restore

You have two routes:

  • Restore from a clean backup taken before the infection — the fastest, safest option if you have one. See restoring with JetBackup.
  • Clean manually — remove flagged malicious files, then reinstall Joomla's core files fresh from an official copy of your version to overwrite tampered ones, keeping your configuration.php and database.

Step 4: Check extensions and users

Vulnerable third-party extensions are a common entry point. Update or remove them, delete any you do not recognise, and check the admin user list for accounts you did not create.

Step 5: Close the hole and harden

Update Joomla and all extensions to the latest versions, since outdated software is the usual way in. Then follow our post-cleanup hardening checklist to prevent a repeat.

Frequently asked questions

How did my Joomla site get hacked?

Most often through an outdated Joomla core or a vulnerable extension, or a weak admin password. Keeping everything updated and using strong credentials prevents the large majority of infections.

I cleaned it but the malware came back.

That means the entry point is still open, or a hidden backdoor remained. Reinstall the core fresh, hunt for webshells and backdoors, and change all passwords again.

Should I just restore a backup?

If you have a clean, pre-infection backup, restoring is often the fastest and safest fix. Afterwards, immediately update and harden so the same flaw is not exploited again.

Was this article helpful?