I'd also check your forum/includes directory...on 4 of the sites there has been an exploit script in there, title of 2011.php