Same thing happened here…files changed around 1pm today. Modified theme files with visitorTracker code in Header and Footer. Created a folder called /temp_data/ along with image file and user.php.
Was able to restore from a backup and also changed file permissions for now until better solution is found. Hopefully someone can figure out how they got in or what is going on. Is the exploit in core wordpress files? Plugins maybe?