It´s not that hard to get infected sites up and running (see the link posted above, you just need to edit two entries in your database). But still, I would have expected to see some proactive reaction from theme developers that distribute yellow pencil to clients…
A quick guide on how to update (or better remove) the Yellow Pencil Plugin would be very helpful. It seems to be bundled with your theme and is not part of the standard plugin procedure 🙁