J2Store plugin malware Topic is solved

Discussion regarding Joomla! 3.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Locked
jdmoet3
Joomla! Apprentice
Joomla! Apprentice
Posts: 30
Joined: Thu Sep 13, 2018 7:58 pm

J2Store plugin malware

Post by jdmoet3 » Sat Nov 14, 2020 5:28 pm

Hi, I have been using J2Store for my ecommerse needs.

However, all of sudden I get a message from my hosting company saying my site has malware and will be taken offline in 7 days. When I go through safeguarding maleware check, these file show up as having a problem. See iamge below.
Image

1 - is the only way to access these files via an FTP program?
2 - if I delete them (the site might break), will that solve the issues?
3 - an update is available, will paying for the update overite these file?

Many Thanks.
You do not have the required permissions to view the files attached to this post.

User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44096
Joined: Sat Apr 05, 2008 9:58 pm

Re: J2Store plugin malware

Post by Webdongle » Sun Nov 15, 2020 11:34 am

Deleting the files from the server will not wreck your site viewtopic.php?f=714&t=946026
http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: J2Store plugin malware

Post by mandville » Sun Nov 15, 2020 1:30 pm

are you sure it has malware? is your file scanner being to aggressive? are you using an insecure version ? https://www.j2store.org/blog/general/j2 ... y-fix.html
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}

jdmoet3
Joomla! Apprentice
Joomla! Apprentice
Posts: 30
Joined: Thu Sep 13, 2018 7:58 pm

Re: J2Store plugin malware

Post by jdmoet3 » Mon Nov 16, 2020 10:13 am

Hi,

I'm not sure what either.

My hosting company Siteground sent me an email adviising of malware. The only offer of help was to pay $199 to a patner company of theirs called Sucuri https://sucuri.net/website-security-platform/signup/. Does this sound right?

Here are some of the files they say are infected.

Code: Select all

URL	
Malware found in the URL: https://noordinarybookshop.co.uk/index.php?option=com_content&amp;view=article&amp;id=45&amp;Itemid=163	

Malware found in the URL (for Google's UA): https://noordinarybookshop.co.uk/	

Malware found in the URL: https://noordinarybookshop.co.uk/index.php?option=com_j2store&amp;view=producttags&amp;tag=appalonia&amp;Itemid=162	

Malware found in the URL: https://noordinarybookshop.co.uk/index.php?option=com_j2store&amp;view=checkout&amp;Itemid=190	

Malware found in the URL: https://noordinarybookshop.co.uk/index.php?option=com_users&amp;view=remind&amp;Itemid=101	

Malware found in the URL: https://noordinarybookshop.co.uk/index.php?option=com_content&amp;view=article&amp;id=259&amp;Itemid=101
I have a few system backups, would it better restore to an earlier date?

Thanks

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: J2Store plugin malware

Post by mandville » Mon Nov 16, 2020 12:29 pm

i would check the j2 forums for any similar incidents of this,
i also see that its picked up google UA code as malicious!?!
Malware found in the URL (for Google's UA): https://noordinarybookshop.co.uk/
i would ask the host to recheck their virus scanner or to enable it so you can run a scan with a different company.. securi offer a free scan along with other comapnies

go in via ftp/cpanel and clear your tmp folder and get them to recheck
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}

jdmoet3
Joomla! Apprentice
Joomla! Apprentice
Posts: 30
Joined: Thu Sep 13, 2018 7:58 pm

Re: J2Store plugin malware

Post by jdmoet3 » Mon Nov 16, 2020 1:39 pm

@mandville - Thanks very much for the quick response.

Unfortunately, Its virtually impossible to get in touch with Siteground on this issue. When I fix the issues they ask me to request another scan of the site. No other contact details. :(

I will follow your advice as soon as I can get past their automated systems.

Thanks again.

User avatar
Webdongle
Joomla! Master
Joomla! Master
Posts: 44096
Joined: Sat Apr 05, 2008 9:58 pm

Re: J2Store plugin malware

Post by Webdongle » Mon Nov 16, 2020 4:00 pm

jdmoet3 wrote:
Mon Nov 16, 2020 10:13 am
...

I have a few system backups, would it better restore to an earlier date?

...
Not if you've been hacked. You could have backed up hack files.
http://www.weblinksonline.co.uk/
https://www.weblinksonline.co.uk/updating-joomla.html
"When I'm right no one remembers but when I'm wrong no one forgets".

jdmoet3
Joomla! Apprentice
Joomla! Apprentice
Posts: 30
Joined: Thu Sep 13, 2018 7:58 pm

Re: J2Store plugin malware

Post by jdmoet3 » Thu Dec 03, 2020 9:23 am

Thanks for all your help.
I have had to pay a company to purge the site of the affected files.
Hope all will be good now.
Best...

User avatar
mandville
Joomla! Master
Joomla! Master
Posts: 15152
Joined: Mon Mar 20, 2006 1:56 am
Location: The Girly Side of Joomla in Sussex

Re: J2Store plugin malware

Post by mandville » Thu Dec 03, 2020 10:08 am

i hope that during the cleaning process you got advised to update your site and any extensions.
HU2HY- Poor questions = Poor answer
Un requested Help PM's will be reported, added to the foe list and possibly just deleted
{VEL Team Leader}{TM Auditor }{ Showcase & Security forums Moderator}


Locked

Return to “Security in Joomla! 3.x”