It's possible that the VPS/VM/root password was sniffed, guessed or otherwise acquired. If so then, short of nuking it from orbit, the only way to be sure is an OS reinstall, change and secure new passwords and start the blogs from scratch if no backups exist.
Otherwise, if you simply try and 'fix' a contaminated install, you take the risk that you can track down every possible change the hacker may have made.
|