I completely replaced the extlib, lib, schemas, tmpl and tools folders from original copies (fresh from the download with no changes). I also replaced every .cgi file. The only thing that I didn't replace was my plugins folder since it would be a P.I.A. to redo. No dice, the stupid page is still there.
I can only get rid of it by editing the list_blog.tmpl file to remove the line
CODE
<TMPL_VAR NAME=NEWS_HTML>
So you may be right about the redirect coming at the server level. I've also written to support with my hosting company to see if they see any suspect activity.
After some reasearch, I'm convinced that is exactly what is going on.
The site it's pulling is:
http://digimedia.com/ I did some Googling and what's happening is a well-known spyware exploit from these monsters. I'd know exactly what to do if I was only seeing this problem on my PC. But it happens from my Mac, too. *And from someone else that I asked to take a look* I created a priv-less username/password and asked someone to login and they see the redirected page too! Which means it's on my server somehow and considering the fact that I do 98% of my uploading from my Mac I have no idea how it got there. Not to mention the fact that my server is Linux!
At this point I know this isn't a bug report (I didn't know when I originally posted) so a mod is free to move the thread. But don't delete it, as this may happen to someone else and I plan to blog about it when I find out exactly what is going on.
I'm waiting for my host to answer.