How to Remove a Virus from Joomla 5: A Complete Step-by-Step Guide
Removing a virus from Joomla 5 should not consist solely of running a scanner and deleting the files it identifies. Effective malware removal requires checking the entire installation: system files, extensions, template, database, user accounts, scheduled tasks, server configuration, and other websites on the same hosting account.
This guide is intended for people with experience administering Joomla, databases, and servers. Deleting the wrong file or record may result in data loss or take the website offline.
Before you begin cleaning
Prepare access to the hosting control panel, SFTP or SSH, database, server logs, and Joomla administrator panel. You also need a secure device for changing passwords and a location outside the website’s public directory in which to store a backup.
Do not start cleaning without making a copy of the current state. Even an infected copy may help identify how the break-in happened, recover content, and restore files accidentally deleted during repair.
Step 1. Restrict access to the infected website
If the website redirects users, displays phishing content, distributes malicious files, or uses the server to send spam, temporarily restrict its availability. You can display a maintenance page, limit access to selected IP addresses, or ask the hosting provider to isolate the account.
Do not assume that Joomla’s offline mode will stop code running directly on the server, a malicious cron job, or a backdoor.
Step 2. Make a complete backup
Secure all files, the database, the configuration.php file, .htaccess files, PHP configuration, cron jobs, server logs, and messages received from the hosting provider. Also keep a list of extensions and users with backend privileges.
Store the backup outside the public directory and do not restore it without first analyzing it.
Step 3. Change all credentials
Using a clean, up-to-date device, change the passwords for the hosting control panel, SFTP and FTP, SSH, Joomla panel, database, email accounts, domain registrar, and backup services.
Do not use one password in multiple places. Enable two-factor authentication wherever it is available. Changing passwords alone will not remove a backdoor left on the server.
Step 4. Check user accounts
In the Joomla panel, check users who belong to the Super Users, Administrator, Manager, and other groups with backend access. Also verify user-to-group assignments directly in the database.
Remove accounts whose origin cannot be verified and change the passwords of legitimate administrators. Check whether a malicious component or scheduled task recreates a deleted account.
Step 5. Replace the Joomla core files
Download the exact same clean version of Joomla 5 from an official source. Compare the system files, then replace the modified items. Pay particular attention to the /administrator/, /api/, /includes/, /libraries/, and /plugins/ directories.
Do not overwrite the entire /images/ directory or the configuration.php file without analysis, as they may contain website data and settings required for it to work. Comparing file sizes is not enough—use checksums or tools that compare file contents.
Step 6. Reinstall extensions
Check every extension’s source, developer, version, installation date, compatibility with Joomla 5, and current status. Remove extensions that are unused, unfamiliar, illegal, or no longer maintained.
If an extension is suspected of being infected, remove its files and upload a clean version from an official source. Disabling a component alone does not remove malicious files that may have been left on the server.
Step 7. Check the template and its overrides
Compare the active template files with a version downloaded from the developer. Pay particular attention to files responsible for the header and footer, additional JavaScript, redirects, and elements loaded before the main content.
Also check the override directories. Malicious code may be located in a file that looks like a legitimate template customization.
Step 8. Check the images, media, tmp, and cache directories
Review the /images/, /media/, /tmp/, and /cache/ directories, as well as extension directories. Look for PHP files in locations mainly intended for images and caching, files with random names, additional .htaccess files, and scripts disguised as images.
Do not automatically delete all PHP files. Some extensions may create legitimate executable files, so each item must be assessed in the context of the entire installation.
Step 9. Review configuration.php
Check whether the configuration.php file has been modified. Look for code before or after the configuration class, additional include and require statements, references to unknown files, and unexpected changes to the log and temporary-directory paths.
After completing the repair, change the database password and update it in the configuration. Never publish the contents of this file, as it contains credentials.
Step 10. Check .htaccess and PHP configuration
Analyze the main .htaccess file and files in subdirectories. Look for rules that redirect users, hide spam from the administrator, run unusual extensions as PHP, or direct traffic to unfamiliar domains.
Also check .user.ini, php.ini, and settings that automatically prepend PHP files. Do not carelessly replace the entire configuration with a standard file—legitimate rules may handle SSL, redirects, or directory protection.
Step 11. Check automatically loaded extensions
Some Joomla elements run automatically and may not stand out in the standard extensions list. Check system plugins, plugins that run on every request, unusual libraries, and files added to directories loaded by the core.
If malicious code runs before the panel loads, a regular scanner operating from within Joomla may not detect it.
Step 12. Clean the database
The database review should cover users and groups, article content, modules with custom HTML, menu items, template configuration, active system plugins, the list of extensions, sessions, and scheduled tasks.
Look for unfamiliar JavaScript, iframe elements, unknown domains, encoded fragments, hidden links, and SEO spam content. Do not run a global find-and-replace operation without a database backup—it may damage legitimate data or formatting.
Step 13. Check scheduled tasks and cron
In Joomla, go to System → Manage → Scheduled Tasks. Verify the type, schedule, status, and history of each task. Remove or disable items you do not recognize, but first save their configuration for analysis.
Also check cron in the hosting control panel. If malware returns after a few minutes or hours, a scheduled task may be recreating the deleted files.
Step 14. Check the other websites on the account
Analyze all Joomla and WordPress installations, old website copies, test versions, subdomains, and unused directories. A forgotten installation with an old extension version may be the source of another infection.
Cleaning only one domain is not enough if the attacker still has access through another website on the same hosting account.
Step 15. Run a security scan
A scanner can help find known malware signatures, modified core files, suspicious functions, and domains included on warning lists. Treat the result as an aid to analysis, not as definitive proof that the website is clean.
A scanner cannot independently confirm that the database is clean, that no hidden user exists, that cron is not restoring the infection, or that all other websites on the hosting account are safe.
Step 16. Update and secure Joomla 5
After cleaning, update Joomla, extensions, and the template to supported versions. Remove unused items, limit the number of Super Users, enable two-factor authentication, and apply secure file permissions.
Set up regular backups stored off the server, file-change monitoring, updates, and notifications about failed logins. Also protect the administrator panel from unnecessary public access.
Step 17. Test the website after cleaning
Check the website in private-browsing mode, on a phone, and from another network. Test backend login, forms, message sending, redirects, media files, search, cache, and all key functions.
For the following days, monitor logs, resource usage, file modification dates, new users, and unexpected requests. The return of suspicious files means that the cause of the infection has not yet been removed.
Step 18. Ask Google to review the website again
If Google or a browser has marked the website as unsafe, request another review only after cleaning is complete, the exploited vulnerability has been closed, passwords have been changed, and the other installations have been checked.
Before doing so, check the security report in Google Search Console and describe the actions taken. A request made too early may be rejected if malicious content is still available.
Why does the virus come back?
The most common causes of reinfection are a backdoor left behind, an uncleaned database, another infected website on the hosting account, a compromised FTP account, a vulnerable extension, a cron job, an unknown Super User, or automatic restoration of an old backup.
The return of malware usually means that the entire infection mechanism has not been removed. In that situation, deleting individual files again may only delay the problem.
When should you commission professional malware removal?
Get help from a specialist if the infection keeps returning, the hosting provider has blocked the account, the website processes customer data, you do not have a reliable backup, you do not recognize most of the files, several websites are running on the account, or legitimate files cannot be clearly distinguished from malicious ones.