CHECK YOUR PHP.INI FILE AS WELL!!!! It enables remote debugging! Make sure to clear out your php.ini file.
Also make sure you change ALL your passwords. It has a MD5 Cracking Script that cracks your current passwords.
This script embeds an iframe within your site from another site “” and this could possibly hijack any other current sessions that your browser has open (such as to Facebook, Twitter, etc.)
Clear your cookies and change the passwords for everything you have and especially those things that were currently open at the time that this occurred.
ALSO NOTE: This may be a vulnerability within WordPress itself because we did not have the plugin mentioned above.