An encoded javascript was detected, which is being used to hide a malicious iframe. That iframe is being used to redirect the browser to spam and to other types of malware (fake av and exploit kits).

Note that any PHP file could be compromised by this type of malware.

Affecting: Any web site. Often on outdated WordPress, Joomla and osCommerce sites.

Clean up:

Loads malware from multiple sources:
(and many other domains).

Malware dump (sample of malware):

"%7!%0|%f~%8?%6&"]);var b=[],c="&!^<^]