Ok, thanks for the advice.
I just wanted to figure out how to make sure that when I change the passwords/users, all of the doors have been closed. I tried once and somehow he wriggled back in and changed the passwords on me.
My hosting service tells me that we’ve kept him out, but I don’t understand how he’s uploaded new stuff if the host site FTP has been changed.
http://codex.wordpress.org/Resetting_Your_Password
PS: I know about these and used the first method, yet the designer somehow changed the passwords back again.
I have the same thing happening, a rogue designer has hijacked my site.
I read the above link, but this designer has the reset passwords going to his own name.
Also, he is an intelligent guy, he probably knows all of these reset methods and is using them on me (I already changed the passwords but he changed them again!!)