Semakin
Customer

Malware Removal and Website Reconstruction

Malware Removal and Website Reconstruction for Joomla and VirtueMart

Has your website been hacked? We can help.

Do you run a website or e-shop on Joomla and VirtueMart and noticed something is wrong? Pages redirecting to suspicious URLs, Google flagging your site as dangerous, or your hosting provider blocking your account? We deal with exactly these situations.

What we do

Analysis and malware removal

Every intervention starts with a thorough analysis. We don't just remove visible symptoms — we look for the actual attack vector and all traces the attacker left behind:

  • Web shells and backdoors — hidden PHP files in non-standard locations, often with disguised names or dot-prefixed, giving the attacker persistent access to the server.
  • Injected code in the database — malicious JavaScript inserted into menu item parameters, modules, or articles. Standard phpMyAdmin searches won't find these injections because they hide inside escaped JSON in the database.
  • Persistence mechanisms — modifications to .htaccess, .user.ini, crontab jobs, SSH keys, or Joomla configuration files that ensure the malware survives even after deleting visible files.
  • Contaminated backups — we verify whether the hosting provider's backups are also infected. In practice, we encounter cases where all available backups are compromised.

Website reconstruction

If the extent of the compromise is too large or the website runs on an outdated and vulnerable platform, we perform a complete reconstruction:

  • Migration to current Joomla — upgrade from Joomla 3 or 4 to the current version 5 or 6, including resolving incompatible extensions and templates.
  • Removal of vulnerable extensions — replacing components with a history of security flaws (SP Page Builder, unmaintained third-party templates) with secure alternatives or clean code.
  • Content migration — converting content from page builders into native Joomla articles that don't depend on vulnerable third-party components.
  • VirtueMart e-shop recovery — migrating products, orders, customers, and settings between VirtueMart versions, repairing media and categories.

Future security

After cleaning or reconstructing the website, we implement measures that reduce the risk of repeated attacks:

  • Updating all extensions and Joomla core
  • Removing unnecessary and unused extensions
  • Setting correct file and directory permissions
  • Protecting forms against spam (Turnstile, honeypot, timing checks)
  • Recommendations for regular maintenance

Why us

We're not a generic security firm. Joomla and VirtueMart is our daily work — we develop our own extensions for this platform, build websites and e-shops on it, and know it inside out, including database structure, routing, and the template system.

We've handled real-world compromise cases — from JavaScript injections via megamenu parameters in the database to multi-stage droppers with seven persistence mechanisms where all hosting backups were also contaminated. We know where to look and what to check.

How it works

  1. Get in touch — describe what's happening with your website, optionally send the URL.
  2. We analyse — we determine the extent of the compromise and propose a course of action.
  3. We clean or reconstruct — depending on the scope, we either remove the malware or rebuild on a clean, current platform.
  4. We deliver a secured website — with documentation of changes made and maintenance recommendations.

Contact

Is your Joomla website or e-shop compromised? Don't delay — the longer malware remains on your site, the greater the damage (loss of search engine rankings, customer data leaks, domain blacklisting).

Write to us or call. The initial assessment is free and non-binding.

Interested in working together?

Get in touch and let's discuss your project. We'll be happy to help you choose the right solution.