On day 1, hackers came and left ajax-2.php and another file that seems to does mail spamming at 9:08 pm.
Shortly after that, webhosting informed me there were 2 files they detected, quarantined them, and asked me to change password.
Later that day, deleted files at 9:05pm and changed password at 9:10pm.
In the meantime, at 9:08pm, hackers came (2 minutes before password change) and left the files again.
That is why I believed they have some other way, through VB, but seems not, that it was the site itself.
There are no strange files after site (not VB) password change.
|