more info:
It's inserts an IFRAME that links to a page with a pretty nasty ActiveX exploit. The code was added to any of my TGP script generated pages across four different domains, a different TGP script on fifth domain on the same box was unaffected.
It seems that a hole in my trade script was the initial access point. They were literally minutes ahead of me updating the trade script to a more secure version.
Give me about 20 minutes in a locked room with the asshat(s) responsible.
