Thanks for your help Bruce.
I am in the process of upgrading my forum. As I was trying to remember which .asp file contains the database password connection string I came across this...

I don't know how many pages this code has infected but I am assuming that an upgrade should fix the problem? It's obvious to me now that the forum was indeed hacked.
Which file has the database password? so I can progress with the upgrade.
You had said in a previous post: "The most likely cause of code injected in to posts is not your web host
but browser plugins or internet security software running on your own
computer which are placing JavaScript and other code in to web pages."
This problem is not local...other forum users also get this spammy code injected into their posts. The only browser that seem to not inject this code is Internet Explorer...all other browsers Safari, Firefox, Opera etc. seem to have this issue.
Edited by slappyJ - 29 January 2016 at 10:00pm