Skip to main content
mySites.guru

Active Joomla Extension security alerts: SP Page Builder zero dayGridbox: 23 criticalJCE 2.9.99.10Fabrik: unauth RCE

Clean a Hacked Site with Suspect Content and Hacked Files

Clean a Hacked Site with Suspect Content and Hacked Files

So it happened. Your site got hacked. Don’t panic. If you haven’t triaged the hack yet, start with our Joomla hacked-site guide for the first steps to take before you touch anything else. If you’re not 100% sure yet, start with how to tell if your WordPress site is actually hacked - it covers the signs vs. false alarms. For the full rundown on what happens when a WordPress site gets hacked or a Joomla site gets hacked, those guides cover warnings signs, consequences, and prevention - but this post is about the cleanup process using mySites.guru. If your Joomla site uses the Astroid Framework, check our Astroid vulnerability breakdown first - it covers the specific backdoors and cleanup steps for that attack. Extension vulnerabilities like the Novarain Framework exploit are another common entry point, particularly because shared library plugins like nrframework get bundled as silent dependencies that site owners don’t realise are there.

Why Should You Back Up First (and Not Restore)?

Do it now. Back up your site. Even if it’s hacked. Back up right now. Done? Good.

You’ll see people recommend restoring from your last clean backup. This should only be a last resort. Restoring wipes away evidence that someone experienced can use to understand how you were hacked in the first place. Worse, it re-introduces the same security hole that let the attacker in.

Want an expert to just fix it?

If you’d rather hand this off, visit fix.mysites.guru and submit a request. For a one-time set fee of GBP 120, Phil will clean your site, upgrade it, lock it down and hand it back secure. Non-subscribers get a free month of mySites.guru included.

How Do You Find the Hacked Files with mySites.guru?

mySites.guru has a set of tools built specifically for this. The platform checks every line of code in your webspace to show you what’s actually happening on your site.

mySites.guru audit toolbar showing the security scanning tools available for a connected site

The most popular tool for hack cleanup is the suspect content scanner.

How Do You Discover Suspect Content in Your Files?

After your site has been audited, you’ll find the suspect content tool in the “Hacked?” section of the Audit tab.

mySites.guru Audit tab showing the Hacked section with the suspect content Investigate button

Clicking Investigate loads a real-time scan of your files:

mySites.guru suspect content results listing flagged files with path, modified date, size, and action buttons

The tool shows the file path, filename, last modified date, size, and permissions. You get buttons to edit the file, view the suspect content matches, or delete the file entirely. Before deleting anything, make sure you know which results are confirmed hacks and which are pattern matches needing a closer look.

Click on a filename and the platform retrieves the file from your site, runs it against the pattern matching engine, and highlights the exact lines that look suspicious:

mySites.guru showing matched suspect code lines inside a hacked index.php file

How Do You Revert Core Joomla and WordPress Files?

In the example above, index.php has two lines of injected code. You could edit those lines out manually, but there’s a faster way.

The first tool in the Audit tab is the core file integrity check - it lists every core file (Joomla or WordPress) that has been modified since release. Click on a file and you get a side-by-side diff: the original on the left, your modified version on the right.

mySites.guru file diff view comparing original Joomla index.php with the hacked version, showing injected code highlighted in red

Click the blue arrow and the original file is restored in a single click - overwriting the hacked version and reverting all changes.

mySites.guru restore button confirming a core file has been reverted to its original version

What Other Audit Tools Help Investigate a Hack?

The suspect content scanner and core file diff are just two of the tools available. The full security audit toolset includes checks for:

mySites.guru Audit tab showing the full list of file-based security checks and diagnostic tools

Not every flagged file is malicious. Some are hidden dot-files left behind by tools or hosting providers that are harmless but worth knowing about. Work through each tool and you’ll know exactly what needs cleaning.

How Do You Set Up Monitoring to Catch Future Hacks Early?

Once your site is clean, set up monitoring so you’ll know immediately if something changes again.

mySites.guru lets you add unlimited sites and run unlimited backups, snapshots, and audits. The real-time file monitoring checks a configurable list of critical files on every page load and emails you if any of them are modified.

This matters because the first hack often leaves a dormant dropper behind, and a second wave reactivates it days or weeks after your cleanup to plant more backdoors. Continuous file-change monitoring is how you catch that return visit.

Finding a hack the same day it happens is a completely different situation from discovering it three months later.

⚠️ Always back up before making changes

Before editing or restoring any files, take a fresh backup. If something goes wrong during cleanup, you need a way to get back to where you started.

Run a free audit on your site to see what mySites.guru finds.


This is part of our WordPress and Joomla security guide for agencies.

Frequently Asked Questions

Should I restore from a backup immediately after my site is hacked?
No - restoring too early destroys evidence needed to identify the original vulnerability and will likely reintroduce the same security hole that allowed the hack in the first place.
How does the mySites.guru suspect content tool work?
It scans every file in your webspace in real time, flags files with suspicious code patterns, and lets you view the exact matching lines, edit files, or restore original core files with a single click.
Can mySites.guru alert me if files change after a hack is cleaned up?
Yes, mySites.guru monitors a configurable list of files on every page load and sends email alerts in real time if any of those files are modified.
What does it cost to have Phil Taylor fix my hacked site?
A one-time set fee of GBP 120. Phil cleans the site, upgrades it, locks it down, and hands it back secure. Non-subscribers also get a free month of mySites.guru.

What our users say

Krisztina
Krisztinafreelancer Joomla! dev
★★★★★

I've been using mySites.guru since 2015 - with the Audit tool, I was able to clean up a server with several hacked Joomla! websites. Then I started to discover other tools and I do the maintenance of 74 sites. Core and component updates take minutes on all of them, scheduled automatic backups and best practices keep data safe, ensuring peaceful sleep ;) Phil is responsive, I always got help when I needed, even if it was not strictly an issue with the service. Pricing is flexible, this has been my best investment ever. I could not live/work without it.

Read more reviews
Accredited Design LLC
Accredited Design LLCManaging Member
★★★★★

I've been with mySites.guru for years now, and it's a central function of my business. Managing multiple site updates at once has saved me untold hours of work to have otherwise needed to login to many sites individually. The other tools to remove unnecessary files, automate backups of websites and scan for malicious code are also extremely helpful. On many occasions, timely warnings from Phil Taylor about security holes in components, plugins and core CMS updates have saved me a lot of grief before bad things happened to my websites. When bad updates have already broken my websites, Phil was always two steps ahead and has surgically accurate information readily available to fix them. Sure, there are other similar services and self-hosted solutions out there, but having all of the things I've mentioned in one place and on one control panel are worth the price of admission in my book. Thank you Phil for all your hard work and for the service you provide to the Joomla and Wordpress communities!

Read more reviews

Read all 267 reviews →

Ready to Take Control?

Start with a free site audit. No credit card required.

Get Your Free Site Audit