
Arggggg. Okay, after saying a few choice words, I promptly called godaddy. The first thing we did was reset passwords for both my user account and my ftp. I also arranged for their security guys to do daily probes of my website to help insure this doesn't happen again (oh, at a minimum fee but I felt the cost was worth it).
Anyway, I spent all day Friday trying to figure out where the evil code had been installed on my website but as I know just enough to be dangerous, I couldn't find anything suspicious on my main pages. I did, however, have a ton of files that were out of order and not necessary so I figured I'd clean up the site first and go from there.
The next day I got a more helpful e-mail from godaddy and one of the tips they had was for me to do a google search using the phrase "what is the status of www.ciaragold.com". I did and the google search showed warning labels on three of my pages. In so doing, it told me where to search. So, once again, I went into my site and cleaned house some more. I got rid of all my pdfs (as this was the source of most of the malicious stuff) and I have disabled my links page as this was another area of concern.
Now, the real question is: how long will it take before google allows folks to go back to my site? And was I able to get it all.
So - advice to those of you that maintain your own websites. Change your ftp password often. If you don't really visit the site very often or make changes very often, I suggest a sitescanner service. I don't know how this person found me, but ....they did and if they found me, they can find you too.