This is known malware, I have seen it several times before and it is in my library of exploits. Use the standard vBulletin recommendations for eliminating an intrusion. It will work if you follow each step carefully.
Then please read the following two blog posts:
http://www.vbulletin.com/forum/blogs...ve-been-hacked
http://www.vbulletin.com/forum/blogs...vbulletin-site
Also please see these recent security announcements:
http://www.vbulletin.com/forum/forum...-1-vbulletin-5
http://www.vbulletin.com/forum/forum...d-all-versions