Hackers inserting ajax-2.php into /public_html directory
My webhosting provder detected (don't know how) that my site has been hacked, files that they found were malicious.
ajax-2.php
that VB Maintenance -> Diagnostics -> Search for suspicious Files also found, in 2 locations:
/public_html/ajax-2.php
/forums/admincp/ajax-2.php
There is ajax.php but that one came with site install and is 44KB long.
The hacked ajax-2.php is 22KB long, opened it, says "Created by BLACK-ID".
My provider sad I should change (their) CPanel password, and I did.
Also changed VB admin password.
However, I am almost sure that the file appeared again, after password change. Permissions are "644" as all regular files.
Anything can be done? If they can bring that file, they can bring anything.
(There is no "install" directory, installation was done as a paid service by VB Engineer.)
It is VB 4.2.2. patch 1
|