I looked in the HTML code for the main page and found over 100 instances of redirects. These are all grouped together and are designed to redirect your browser if certain hyperlink tags are clicked. I'm fairly confident that these redirects were planted along with the "iframe" that we discovered several weeks ago.
I don't remember seeing these a couple weeks ago, but I wasn't looking for this type of HTML entry (I was looking specificallly for references to to an iframe with a specific filename)
I'm not sure how you happened on these as I couldn't find any reference to their hyperlink tags, i.e. how you managed to get to one of these redirects. Without the hyperlink tag, the only way to activate the redirect is to physically type in the correct url address.
Do you remember how you were able to get the redirect to pop up, i.e. what hyperlink you clicked on??
Anyway,
Sysco needs to search the original source HTML for the following text;
<a href="http://www.ez.org/images/online
He'll see immediately what I'm talking about. I would delete all of these occurances in the main page.
ALSO, remove the /images/online folder from the web sites directory. If you look there, You'll see were all these redirects are actually going to.
Waiter
PS - I'd be very curious as to how the source code became infected, This may be left over from the original problem we had with some ads that were placed a few weeks ago
Anyway, double check you backup copies and make sure they are not infected..