I don’t know the source of this virus currently. All I know is that everyone I have talked to so far that has this issue has been on a Layered Tech box, either directly, in the case of Woopra or through resellers. I have not found any other information of it effecting other hosting providers yet.
But I am only stating what I know to be true and trying to help people stop it on their own because god knows that these support desks are going to have their hands fulls.
I think this started with Refresh, the Georgian Hacker, but now a few other hackers are getting in on the action.
I guess this is still going on. Just to let everyone know. I had one of these guys hack one of my blogs. If you have a WordPress forum installation, disable it, and research if it is one of the forum plugins that has a security issue. If so, there could be your problem.
After I took the forum off the blog that got hacked, it stopped getting hacked.
Follow Me