This hack has been around a while and mentioned in a number of threads here, search for mod_auth_form.so
There is a fake version that gets loaded and causes the likes of 'googlebot' to get a different page than other browsers.
In the first instance comment out (or remove) the loading of that module in your apache/conf/http.conf;
remove the file from the modules directory and then work on all the other security suggestions in threads here to clean up and lock them out.