No, it wasn’t spam. We found the following code in our admin.php file just above the system path:
include('inc/lib/cache.php');
We removed cache.php, css.php, png.js, as well as several other files that looked suspicious.
Two of the pages of the site had content about ‘Ambien’, and the Google results mentioned Ambien as well. This is completely unrelated to out site content.
We are using MSM. The main site was infected. It has been online since March. The 2nd site is the registration site. It just officially launched 2 weeks ago. It was not infected, as far we can tell. Registration is an important function for the site, so it cannot be turned off.
The forum module is not installed. Commenting was not turned off on all channels. But it is now.
Our host (Dreamhost) isolated some suspicious files, and we have gone through the site carefully, removing a few other files that look suspicious. They also had us change our file permissions from 777 to 755 and 666 to 644.
We are uploading fresh EE files, and changed our hosting, FTP, and SuperAdmin passwords.
We checked these files as I saw mentioned elsewhere in the forum, and admin.php looked to be the only one infected.:
* index.php
* admin.php
* system/index.php
* system/expressionengine/config/config.php
If you think there is something further we should do, please let me know.
Susan