I don't know.. Very hard to troubleshoot without all the info. I must have missed where you told us about ajax-2.php being there.

Sometimes in here it takes a bunch of people guessing because we do not have all the info when something like this can usually be figured out in 5 minutes if we were to look ourselves.
If you suspect your site was hacked then simply fixing the htaccess will not keep them out. You need to figure out how your site or server was comprised or if it is still vulnerable. I would address this asap. Usually a hacker breaks into a site to do more than just delete the contents of an htaccess file.