In all likelihood they have been hacked and then the script kiddie has run riot since their admin folder is in the default place. Going to the admin folder results in problems with SEO too in the auto_load functions so I am guessing that it's a hack and then break the server to stop anyone else. A quick scan before my ip got blocked (that was ME not a bad guy) showed an odd port open on 2222 which is listed as a rootkit shell port but then it could just be SSH bein forwarded to a non obvious port.
http://www.google.co.uk/search?hl=en...t+2222+rootkit
lists quite a few rootkits there. I think they need professional help, and probably shouldn't be posting here either, more int he security section.
Philip.