From what I can tell looking at other posts by dave, and others the problem isn't in the files, it's in the site.
There's a good chance that one of our members visited a site that contains malware, then somehow transferred it to the server (it's possible, although unlikely)
There was a site up for EVER called jl.chura.xxx (google it if you want info. The extension was .pl) that was up for almost ten years spreading a mutex that would infect all html files on both your system, and any page you visited. It's since been shut down (to my knowledge) but that gives you a good example of how this could happen, and what you're looking at.
I highly doubt that anyone's able to sneak anything past us since most of the time we're checking the files among multiple members, and we use many different methods of "reading" to disassemble, and determine what's inside the files. Packed or not.