So one of the sites I designed has been the victim of a variant of the pharmacy hack. If you search for 'primaloft' on Google, you can see that the search results list all these drugs in the site's description. It looks like it's Google-specific right now as the Bing results are fine.
I've tried to sniff out any suspicious php files, and I'm in the process of replacing any snippets or modules I've added to the site. I also made the index.php, index-ajax.php and htaccess files read-only.
I used this tool:
http://redleg-redleg.com/file-viewer/ to see how the page source looks to the googlebot, but I don't see anything amiss anymore, yet the search listing doesn't change.
Still, something is still continuously generating random php files all over the site structure though. Each php file (named atom.php or json.php or a few other names) is very small, ~1.3kb, and just looks like some base_64 code.
Unfortunately, I don't know how far back this problem goes, and the site has not been backed up as well as it should've been (completely my fault). Does anyone have any experience with this kind of hack? Are there certain snippets/modules that are more vulnerable that I should start with?
Many thanks in advance.
I'm running Evo 1.0.5.