Very important that you develop complete confidence that there isn't anything wrong with your product. It's not uncommon, in fact it's very common, for compromise kits for websites to take measures to avoid detection. A common one is only serving the malicious content when a specific referrer is present (I've seen this be Yahoo Search in the case of compromised Drupal installations multiple times, not really sure why…
> It might be wise to engage a security firm to conduct an investigation if you don't have in-house expertise in this area.
Any good security firms you recommend for a small to midsize website?