Our site has been hacked somehow and a number of files (Index.php) have been added that redirect customers to Spam sites. .htaccess files have been renamed. I've been through every directory and manually removed the files, updated .htaccess to disallow access, changed the file attributes to remove write access and changed all Admin & FTP passwords.
2 days later the site was hacked again. So I did the same thing again all over again.
2 days later the site was hacked again. I've just finished cleaning it for a 3rd time
Can anyone suggest how I can stop this as it's getting painful
