So...just as an update...somehow my host was accessed and an additional file was included in the global.php (what looked like randomly buried in a directory of my wiki). But....changed all my passwords, reverted that file to the original, and the hack was back in a different manner in 30 minutes (new filenames and locations, same content...).
Still working with my host on this one...but any suggestions (along with pointing and laughing) are welcome.
--------------- Added [DATE]1278999435[/DATE] at [TIME]1278999435[/TIME] ---------------
Another update...everything I can figure out on my own (no help from host :/ ) is that my ad server (OpenX) was compromised with some sort of exploit that allows uploading of files (??), both times it happened there were many large POST requests to a known problem .php file in OpenX. I should've upgraded sooner.
This was a pretty insidious hack that attempted to hide itself from human users and display pharmacy pages to web search bots...but was clearly targetted at vBulletin. So anyone running OpenX I would encourage you to upgrade ASAP.
Thanks for letting me vent here.