Most site viruses (if PHP) would use an iframe tag (<iframe> ...</iframe>). Search the code for it and delete it manually. Just my two cents.