The antivirus is most likely not a "false-positive" if its an iframe injectable...
Does MS Security essentials show you the link/script that you are being directed to?
You are going to need to find the link in one of your templates / raw files and get rid of it. If its in a raw file, your FTP/cPanel details are most likely compromised. A template/style edit would mean an administrator account is/was compromised.
|