Make sure you delete your whole /install folder as that is how he hacked your site!
And, as Richie says, you should .htaccess protect your /admincp. Make sure that is a unique username/password (don't use the same as your /admincp login like some admins do as that will NOT make it secure if they have your admin login details!). Actually, read all that Richie wrote as it is very good advice.
|