Check all users with Admin permissions. BUT if you find any extra ones just remove all permissions - don't delete the user, because you will be able to check what they have done!
Also, check for any unusual products and plugins and be aware that the hacker will probably have installed some sort of backdoor in the database, so simply replacing all the files won't necessarily solve the problem.
|