Thanks for sending me your login info (also, thanks for making a donation, that really help me keep this project going!)
I found the backdoor in alot.php along with hundreds of HTML files in the /public_html/swollen/ directory. I suspect that whole swollen directory was plated there using that alot.php file, this file is self updating and self replicating and it’s linked to by all those HTML files.
I have added this new threat to my definition updates so you can now remove the threat using my plugin but I would suggest just deleting that whole “swollen” folder via FTP.
You should also delete that backup file made by BackupBuddy and then make a new backup of you site without that infected folder.