Here's what happened. vBulletin was recently hacked and they sent out an alert* to all users of vB, unfortunately I missed the alert sent to this site. Had I seen it I would have alerted my webmaster and he would have installed a patch that would have protected the site.
Now he is checking the site as the malware can be installed into files and activated at a later date.
So that's what happened.
* [TABLE="class: tborder, align: center, border: 0, cellpadding: 4, cellspacing: 0"]
[TR]
[TD="class: thead"]vBulletin News: Security Patch released for vBulletin 5.1.4 - 5.1.9[/TD]
[/TR]
[TR]
[TD="class: alt2 smallfont"] A security issue has been reported to us. This issue could allow access to run server shell commands as the apache user.
We have released security patches for vBulletin versions 5.1.4 through 5.1.9 to account for this vulnerability. It is recommended that all users update as soon as possible. If you're using a version of vBulletin 5 older than 5.1.4, you should upgrade to the latest version as soon as possible.
[/TD]
[/TR]
[/TABLE]