Hacked again. This time one of my sites on a shitty shared hosting account. It is a simple Wordpress blog.
This is what the virus wrote on my index.php file:
And this is what they wrote to the .htaccess file:
It wrote this to all of the approximately 6 Wordpress blogs on this account. I went in, edited all of the index.php files, edited the .htaccess files as well, changed the Cpanel password, changed the wordpress password, even changed my fucking email password.
Today, it's right back there again. The .htaccess file remains unchanged, but the Index.php shows the exact same shit. I have to ask those more knowledgeable than I on this subject, there's probably a really easy solution to this, but how are they still editing the file? Do they have another sleeper file somewhere that I didn't delete? It has to be some type of program on my server that keeps overwriting the index.php file, right? Is it implanted in one of the many php files?
Any help would be appreciated.