according to our provider's support service, it was the Neorecruit component that was responsible, but of course they could be wrong.
I e-mailed you the same day as my original post in this forum asking if you could send me the files to upgrade to 1.4.4, but didn't receive an answer. Is it possible to send me the 1.4.4 files so I can upgrade our site?
Just wanted to let you all know that our website (with NeoRecruit 1.4.3) has been under css attack and was used to send thousands of unwanted emails. They used the NeoRecruit component to get in, but it was also made possible through a "allow_url_fopen setting" in the php.ini file. Apparently most providers do not activate this setting, but unfortunately ours did.
All is back to normal now, but be aware of the possible risk!