that exploit is typically installed through FTP rather than a server exploit. I would change your password, have your host find out what IP address modified the files (there will be a GET followed by a PUT), then find all of the files that the IP address modified. Typically, they will only modify domains in the root of each domain name, and usually only index.html and index.php
__________________
SnapReplay.com a different way to share photos - iPhone & Android
|