Hi.
Let me explain what's going on.
This hack is still old hack. Fucking hacker left 'backdoors' on the servers that allows him to manipulate files on a server, like changing filter.php and scanner.
If you see any iframes on your main page, it means you have this backdoor(s). If you clean up the server from backdoor and update TP, NO MORE hacks will be possible.
I repeat, latest builds are 100% secure.
The problem is detection these backdoor files and remove'em. It's *.php files, 99% of them are encoded by Ion cube or Zend encoder. I can do this work for you, but I need either ftp access or ssh access, the last one is more desired.
Contact me directly if you think you hacked -
kildoozer@scriptpulse.com