No, nor can they upload files (not that UBB.threads should let admins upload images that aren't images) without FTP access.
The virus in question would be in the data.hta file that should also be located in that directory... the PHP script just serves it up with the right content type as to ensure IE's infected...