Also, maybe check wp-content/themes/theme-name/header.php and see if there is anything different there than what you see in your source. Usually malicious redirects are js that look like gibberish
Also, is that last line of js after html tag supposed to be there?..
|