Without knowing what exactly you asked your provider, what you did in cpanel, and what exactly their answer was we really can't comment properly. No offense, but from the course of this thread I tend to believe that there may be some misunderstandings on your part.
It really seems your site (including the database, not only the files!) was never properly scanned for hidden backdoors etc. after the first attack. As others have speculated, I would assume that all those attacks may be follow-ups. Whatever your password, however secure, if there's some sort of backdoor present, it won't help you (since they don't have to get in, they are already in - all the time). But all of this has nothing to do with config.php, really.
|