<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: How to get rid of JS/Tenia.d</title>
	<atom:link href="http://www.donnaville.com/2009/03/28/how-to-get-rid-of-jsteniad/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.donnaville.com/2009/03/28/how-to-get-rid-of-jsteniad/</link>
	<description>sugar and spice and everything groovy</description>
	<lastBuildDate>Tue, 07 Sep 2010 20:15:33 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
	<item>
		<title>By: John</title>
		<link>http://www.donnaville.com/2009/03/28/how-to-get-rid-of-jsteniad/comment-page-1/#comment-65246</link>
		<dc:creator>John</dc:creator>
		<pubDate>Thu, 25 Jun 2009 03:01:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.donnaville.com/?p=3095#comment-65246</guid>
		<description>I got the same i-frame crap on my drupal site.  I upgraded from my 5.1 version to 5.1.8 to fix it.  Thanks for your info; it helped identifying what was going on.</description>
		<content:encoded><![CDATA[<p>I got the same i-frame crap on my drupal site.  I upgraded from my 5.1 version to 5.1.8 to fix it.  Thanks for your info; it helped identifying what was going on.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Silvano</title>
		<link>http://www.donnaville.com/2009/03/28/how-to-get-rid-of-jsteniad/comment-page-1/#comment-49038</link>
		<dc:creator>Silvano</dc:creator>
		<pubDate>Thu, 09 Apr 2009 14:09:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.donnaville.com/?p=3095#comment-49038</guid>
		<description>Hey, I got the same problem and I lost my 4/10 pagerank

I found two interesting things:

1 - the cracker modified my .htaccess to send all bots (google, yahoo, etc) to his website

2 - he changed the file wp-content/cache.php to work as a PHP shell

So if you didn&#039;t notice these, get rid of them ASAP.

Thanks for the post! It really helped me.</description>
		<content:encoded><![CDATA[<p>Hey, I got the same problem and I lost my 4/10 pagerank</p>
<p>I found two interesting things:</p>
<p>1 &#8211; the cracker modified my .htaccess to send all bots (google, yahoo, etc) to his website</p>
<p>2 &#8211; he changed the file wp-content/cache.php to work as a PHP shell</p>
<p>So if you didn&#8217;t notice these, get rid of them ASAP.</p>
<p>Thanks for the post! It really helped me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Donna</title>
		<link>http://www.donnaville.com/2009/03/28/how-to-get-rid-of-jsteniad/comment-page-1/#comment-48721</link>
		<dc:creator>Donna</dc:creator>
		<pubDate>Thu, 02 Apr 2009 21:48:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.donnaville.com/?p=3095#comment-48721</guid>
		<description>I&#039;ve never read that book but for a short while I had been reading an interesting blog from an actual cyber sleuth!  He used to investigate criminals online-- their facebook/myspace pages as well as uncovering other online activities.  It was a great Web site but somehow I lost the link and couldn&#039;t remember the name of him or his blog.  Oh well.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve never read that book but for a short while I had been reading an interesting blog from an actual cyber sleuth!  He used to investigate criminals online&#8211; their facebook/myspace pages as well as uncovering other online activities.  It was a great Web site but somehow I lost the link and couldn&#8217;t remember the name of him or his blog.  Oh well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve Ragan</title>
		<link>http://www.donnaville.com/2009/03/28/how-to-get-rid-of-jsteniad/comment-page-1/#comment-48673</link>
		<dc:creator>Steve Ragan</dc:creator>
		<pubDate>Wed, 01 Apr 2009 12:57:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.donnaville.com/?p=3095#comment-48673</guid>
		<description>Of course you can&#039;t be certain that that is an actual person at that actual address. I&#039;ve never heard of address verification for domain registration.
Well, whomever it is, I&#039;m pretty sure that he&#039;s been shut down already. I went to grab the content of that URL directly (in a safe, non-browser way) and I got a 404. The same person is listed for similar domains too like google-analyze.org and google-analyze.cn
I love cyber-sleuthing - it&#039;s like a hobby you could say :)
Ever read The Cuckoo&#039;s Egg by Clifford Stoll?
It&#039;s the story of the original computer sleuth. Interesting read - well, if you&#039;re a geek.</description>
		<content:encoded><![CDATA[<p>Of course you can&#8217;t be certain that that is an actual person at that actual address. I&#8217;ve never heard of address verification for domain registration.<br />
Well, whomever it is, I&#8217;m pretty sure that he&#8217;s been shut down already. I went to grab the content of that URL directly (in a safe, non-browser way) and I got a 404. The same person is listed for similar domains too like google-analyze.org and google-analyze.cn<br />
I love cyber-sleuthing &#8211; it&#8217;s like a hobby you could say <img src='http://www.donnaville.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
Ever read The Cuckoo&#8217;s Egg by Clifford Stoll?<br />
It&#8217;s the story of the original computer sleuth. Interesting read &#8211; well, if you&#8217;re a geek.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Donna</title>
		<link>http://www.donnaville.com/2009/03/28/how-to-get-rid-of-jsteniad/comment-page-1/#comment-48640</link>
		<dc:creator>Donna</dc:creator>
		<pubDate>Tue, 31 Mar 2009 17:09:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.donnaville.com/?p=3095#comment-48640</guid>
		<description>Thanks Steve for that info--- I wish there was a way to press charges or alert the authorities...</description>
		<content:encoded><![CDATA[<p>Thanks Steve for that info&#8212; I wish there was a way to press charges or alert the authorities&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Donna</title>
		<link>http://www.donnaville.com/2009/03/28/how-to-get-rid-of-jsteniad/comment-page-1/#comment-48639</link>
		<dc:creator>Donna</dc:creator>
		<pubDate>Tue, 31 Mar 2009 17:07:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.donnaville.com/?p=3095#comment-48639</guid>
		<description>I was using Norton but it never picked up the trojans on my computer so I uninstalled it and am now using BitDefender.</description>
		<content:encoded><![CDATA[<p>I was using Norton but it never picked up the trojans on my computer so I uninstalled it and am now using BitDefender.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: B. Davis</title>
		<link>http://www.donnaville.com/2009/03/28/how-to-get-rid-of-jsteniad/comment-page-1/#comment-48600</link>
		<dc:creator>B. Davis</dc:creator>
		<pubDate>Mon, 30 Mar 2009 13:21:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.donnaville.com/?p=3095#comment-48600</guid>
		<description>My Kaspersky anti-virus software caught it.</description>
		<content:encoded><![CDATA[<p>My Kaspersky anti-virus software caught it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve Ragan</title>
		<link>http://www.donnaville.com/2009/03/28/how-to-get-rid-of-jsteniad/comment-page-1/#comment-48597</link>
		<dc:creator>Steve Ragan</dc:creator>
		<pubDate>Mon, 30 Mar 2009 12:58:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.donnaville.com/?p=3095#comment-48597</guid>
		<description>FWIW - here&#039;s some info on what you had.
Googled the URL in that iframe and came up with this -

Date:                   2009/03/26_00:00    
Domain:                 google-stat.com/tomi/?t=2   
IP:                     202.73.57.6 
Reverse Lookup:         dyn6-b57-access.superdsl.com.sg 
Malware Description:    Luckysploit 
Registrant:             johnvernet@gmail.com


Some info on Luckysploit here - 
http://www.finjan.com/MCRCblog.aspx?EntryId=2213


And info on the slimeball who registered the domain -

whois google-stat.com

Registrant:
    Private person
    Email: johnvernet@gmail.com
    Organization: Private person
    Address: 350 Lynn Dr
    City: Sylvan Springs
    State: AL
    ZIP: 36604
    Country: US
    Phone: +7.4955123456 
    Fax: +7.4955123456</description>
		<content:encoded><![CDATA[<p>FWIW &#8211; here&#8217;s some info on what you had.<br />
Googled the URL in that iframe and came up with this -</p>
<p>Date:                   2009/03/26_00:00<br />
Domain:                 google-stat.com/tomi/?t=2<br />
IP:                     202.73.57.6<br />
Reverse Lookup:         dyn6-b57-access.superdsl.com.sg<br />
Malware Description:    Luckysploit<br />
Registrant:             <a href="mailto:johnvernet@gmail.com">johnvernet@gmail.com</a></p>
<p>Some info on Luckysploit here &#8211;<br />
<a href="http://www.finjan.com/MCRCblog.aspx?EntryId=2213" rel="nofollow">http://www.finjan.com/MCRCblog.aspx?EntryId=2213</a></p>
<p>And info on the slimeball who registered the domain -</p>
<p>whois google-stat.com</p>
<p>Registrant:<br />
    Private person<br />
    Email: <a href="mailto:johnvernet@gmail.com">johnvernet@gmail.com</a><br />
    Organization: Private person<br />
    Address: 350 Lynn Dr<br />
    City: Sylvan Springs<br />
    State: AL<br />
    ZIP: 36604<br />
    Country: US<br />
    Phone: +7.4955123456<br />
    Fax: +7.4955123456</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://www.donnaville.com/2009/03/28/how-to-get-rid-of-jsteniad/comment-page-1/#comment-48565</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Sun, 29 Mar 2009 16:15:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.donnaville.com/?p=3095#comment-48565</guid>
		<description>What do you use for anti-virus?</description>
		<content:encoded><![CDATA[<p>What do you use for anti-virus?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael</title>
		<link>http://www.donnaville.com/2009/03/28/how-to-get-rid-of-jsteniad/comment-page-1/#comment-48563</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Sun, 29 Mar 2009 13:42:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.donnaville.com/?p=3095#comment-48563</guid>
		<description>I have never understood the spammer mentality</description>
		<content:encoded><![CDATA[<p>I have never understood the spammer mentality</p>
]]></content:encoded>
	</item>
</channel>
</rss>
