If you read that article correctly you will note that it speaks of 1.4.2... In 1.4.1.6 there is no ajax file manager anymore for the reasons you encountered (actually that tis the only change between 1.4.1.5 and 1.4.1.6 at all). If it is still there you did not upgrade correctly.
Anyway, proper server permission should not even allow accessing these files.
So again, see the security category articles and the there in linked forum topics about these hackes (assuming it is the same).