Hi all,
In some way that I can't understand, a custom block (cookie warning block) that contains the "cookies warning code", is edited.
Usually an external link is added to this code, to a website that is on the eset antivirus blacklist.
What steps should I follow to find out who or how this is done?
You can start by identifying which security updates you didn't apply. And apply them.
If you figure out which security hole they exploited you might be able to figure out where the attack originated from by analysing the server logs but that is unlikely to help you.