Changing the subject would be a good idea. There is no proof of SME Server being infected and the 'seems' is no excuse to finger point directly to SME Server up front.
I assume you have checked your Joomla versions and plugins (as indicated by Stefano), and extensively searched the Joomla forums and followed up on all their (security) advisories?