Thanks - already tried the ... - all it brought up was a few jpgs uploaded to the forums that have additonal dots after them. (oh and isn't it just 'locate ...' ? - no /
The site that was hacked in clean - nothing suspicious in there, as afar as I can tell. Checked dates etc.
Also checked the crons - again nothing suspicious under root, other users such as apache, admin etc., have nothing set up.
Basically I have checked everything, I can think of and so am in need of a spark of wisdom from somewhere LOL