It's a pity you don't disclose which malware specifically the sites were distributing. As a user who may have been affected prior to google flagging it, it's frustrating to have no information on what to look for.

I think that you should direct your frustration towards the php.net admins and not Google.

It's linked further down the page.

