That's right Lynne. However I could not find on the source of the page, nor on clientscripts any wierd script containing the url. Can it be encrypted somehow, if so, how to detect it?
I am using a slightly modifed template based on of the default style.
I should also mention that the site has been defaced a while ago but I managed to remove all the traces of base64_decode injected to the template table.
|