I posted this on another thread here in the WP Forums:
I solved the problem. Instead of going through every single file and deleting every infected WordPress install and js file (Which I have spent most of my day doing) I found this site which provided a script to debug the malicious code on my server.
I hope this helps anybody who encounters the problem.
Marco
The site has fixed. And I have changed the FTP password.
But I don’t understand how can the virus find the password? Is there dictionary attack technique?