there seems spam e-mails being sent out site, not e-mail address, link site. the page links not 1 placed there, though "simple enough, go ftp, delete page , change passwords" ... nope. went ftp, , file doesn't seem exist. the link below, warning - spam page on site without permission, make sure pc thoroughly protected before following link. any tips? tlc-sussex(dot)com/christianslump/ edit - oh joy - it's redirecting 404. have changed password hosting account yet? now. how site coded? suspect controller files have been heavily modified. update: i'm asking on how site coded. i'm guessing either framework or sort of content management system (cms, joomla or drupal) programmer of site, or perhaps key user maintaining site? oops.. see wordpress cms site, , i'm guessing key admin updating site. somewhere 1 of php controller files has been hacked, , needs replaced. did install site, or did else it. can replace wordpress core...