ok, found a solution: posted by just_rob @
http://www.reddit.com/r/web_design/comments/kqx8/every_site_hosted_by_inmotion_has_been_hacked/
side notes: this worked for inmotion hosting and I had to remove the whole section. lines 27,28,29,30,31.
just_rob:
"Figured it out -
...Go to /wp-admin/index.php in your file manager for the affected site, open it in the built in editor, locate the is_user_admin block on line 27, remove that and the window screen or whatever (can't find it again). Save the file, login through the wp-admin. Update the wordpress version.
It seems when they replaced the wp-admin/index.php with a generic up-to-date version of it which includes a call that isn't in some versions. By removing it, it doesn't seem too critical, and updating the WordPress version should make everything "back to normal" "