Thanks for your reply.
Yes, I did that and also a few other things, followed all steps.
I also change ftp, db, passwords.
I've also checked .htaccess file and config.php file as well and I don't see any modifications.
I've also use this template tool if the malicious code was int he template but still doing the same.
https://vborg.vbsupport.ru/showthread.php?t=281080
and that tool "teamps" is still there.