Thanks, I did not know that (that tools.php) can be used to do a snapshot. Never actually seen what it looks like, never started it, just removed from the site.
It is a shared server. The pasword, although not easy, could have been cracked by some automated procedure.
Changed them all today, for site, for ftp for hosting control panel.
The site is up and running now, fully restored. What they did this morning was to insert some malware. Several members who know my private email address reported that their computers are warning them about malware (the hackers placed it in index.php, even word "Russia" was readable among other things)
|