If U cleaned and locked, speak with your host why files got replaced, its not in our domain . Basically its wrong apache config or they use suphp so process (shell scripts) run under user.
The problem is the cleaning. No one has really posted a good cleaning process. Its hopping out of the TP folder. You can delete the whole tp folder and install from scratch, it comes back. The backdoors or scripts are still outside of the tp folder. Yes there are hacked tp files, but thats not the backdoor.
Lets not forget the original problem was the hacked update. This "Hack" that "keeps coming back" means it wasnt cleaned off the server properly. Yes we can "lock it". But it doesnt mean the "hack" is off your server. I dont believe for a second that this hack has anything to do with our original server security/configuration.
Once this tp updater hack gets on your server, your basically fucked. because the timestamps of the hacked files match on all domains on a server. Even on fresh tp installs. and by fresh, i mean deleting the tp folder completly AND toplist folders, its back a day later.
I have something for anyone to try... move your domain to a virgin server, install Smart thumbs, trade pulse from scratch, import your thumbs from another smart thumbs and a exported tradeslist, check your toplist codes before you import them, see your problem dissappear.
Has anyone tried this besides me and see it come back? I would like to hear this....
I know that your files where hacked and im not blaming you for that, but sorry, I have a tough time with your statment, this gives me the impression that your passing the cause of this problem to our servers config or hosting admin.
Im not trashing you, but I dont see any problem with TP being hacked when your server is actually clean. The problem is getting your server clean. A lock.php isnt going to take out the backdoor on your server.