Putting this code in your public_html/.htaccess will prevent anyone accessing php.ini by web: <Files php.ini> order allow,deny deny from all </Files>
Than you very much to all, i've tried manny changes to the script but yet it still got hacked now i'm moving my site to a new hosting company.. Let's see now..
it's been three days since i move my site to a new web hosting company, so far it's not hacked.. seems like my prior web hosting company got hacked..
Just try to transfer your site to other good hosting company. I am sure that your current hosting provider has no sufficient security.