if you htpasswd protect comus then its still fine to use, the only exploited file was menu.php sitting in the admin dir.
have the host clean up the box as well, prolly a shitload of backdoor files on it and switching scripts wont help in that case as the new ones will easily get compromised as well.
__________________
icq:148573096 skype:dabone2 email:boneless(a)mgpteam(.)com
|