Thanks for answers. It infects not only WP sites, but all sites (it adds some code to the index.php and main.php files, I also found malicious code in 404.php's but im not sure wheter is belongs to Blackhole exploit), but it seems that this code is added by some other source (could be some script) because right after I delete this code and save file it is back after few minutes when I reopen it.
Anyway I did following. Re-installed all WP's, then upgraded all WP's and plugins. Reuploaded backups of other non-WP sites and changed FTP password. Since then everything seems fine. It took me whole day to solve it.
Btw. my host replied only with pre-made email what they send to people whos sites were hacked. Really helpful.
|