Hello,
Yes, t31os_, that is my bigger concern. The POST to the install.php file. As far as I can see, the WordPress documentation doesn’t state to remove the install.php file, but it certainly makes sense to do it.
But I am trying to confirm this is how the attacker corrupted this blog, but somehow managing to POST back to the install and make it look like it was a fresh install, in turn, wiping everything out.
David