Unless you've had a hack through the server and you have infected php files, the most common one is
eval(base64_ code, search your vbulletin php files for this (or better still use the admincp>maintainance>diagnostics>suspect file versions and then just search those files that show up as suspect for the eval code change this link to be your website and forum and it will take you straighjt to the diagnostics
http://www.YOURSITE.com/forum/adminc...p?do=doversion