Looks like a site defacer, if reloading the database solved the problem, it is likely that it was an injection attack. One that I know about is they piggyback a link onto the meta "Description" in vboptions though it could be almost anything in the database, they target the code that is loaded by the index.php. Efficient bastards that they are ... HTH