Well if they can change your index.php they might have uploaded more shells on your site - that is usually the case, unless speedbus also checks for malicious shells?