After looking through some past days where it was attacked, I found a lot of lines in the log that look like this
Code:
79.135.181.122 - - [27/Feb/2008:07:22:23 -0500] "GET /components/com_jcalpro/images/minipics/.info.php?id=head%20-1%20paster.txt%20%3E%3E%20/data/9/0/74/154/563806/user/575230/htdocs/site/administrator/includes/pcl/index.html HTTP/1.1" 200 - "-" "googlebot"
There are several of these lines, all beginning with the jcalpro component and at the end they all have a different index.html listed, and these were the files changed.
Could this be when I was under attack?