Your site has been compromised.
Someone has placed a javascript at the top of your home page (and possibly other pages) that attempts to run a trojan virus.
The javascript attempts to open an iframe from another site. By saving the javascript with the ".gif" file extension, it relies on the browser to run the script automatically.
You'll need to make sure that your site is secured. To start with, change your login and password as soon as possible.
Search for any and all instances of the following code then delete it.
Code:
es/img/ken.gif></script>
Check your server logs. They may provide an IP address that you can pass along to your Server Administrator or host.