It is likely malicious code in little bits of Javascript. WordFence may be able to tell you the specific files, but, to keep them from coming back, you need to update everything, delete unused themes like old exploitable default themes, and upgrade to current php. And report whatever affiliate is doing this to any program where you see the affiliate ID.
Hope this helps. Good luck.
|