okay, so all the files are gone from the index, but if you view "new site" (edit: which is now gone, i'm assuming someone is playing around), the same injected URL is on the main index page. on top of that, the iframe is on pretty much every page i can pull up.
for the love of god, turn off the server, start over, and use a prebuilt site.
edit2: can i see the contents of the php files in /uploads ? (nevermind, the hack comes with its own file manager.)
Interesting, when I tried to open the forums my browser interfered and gave me a big warning, and said that just visiting the site could infect a pc.
How does such an infection happen, is it the usual Javascript/ActiveX/Flashplayer exploit or something more nasty? I thought about playing around using a VM, but then again.. didn't want to push my luck