1) change your password to something secure with letters, numbers and symbols
2) run an antivirius on your server. If you do not have one or see it, ask your host.
3) have your host setup SSH, cPanel and FTP logs and send them to you nightly and check for anyone logging in that is not you.
Or instead of #3, you can setup a whitelist IPs and only allow yourself. Not recommended if you travel or your IP changes often.
That will be $500, please send paypal
