You have to upgrade your website to the latest Magento version. In my case I have a test VDS which is not public, but can be accessed by IP address from everywhere. Well, I found it was attacked with success. A file in root allows to upload files in root, overiding the good ones. Magento version 1.8.1.