Yes, I myself ran into this problem, as I understand it, are you on a shared host? Are you possibly on rackspacecloud?
this is where I came across this problem, the first thing you need to do right away is to report it to the host, this is a hosting problem, and I suspect that the malware has accessed your server at ftp level.
make sure that you do not have anything writable by chmod 777, if it should be writable by your application, make it 775
Hope this helps, good luck.
source share