Description:
Malicious javascript added to many sites using the domains iopap.upperdarby26.com, skyefenton.com, propertyfiend.com and ldela.org as the source of the malware. Some random javascript files were used. For example:
http://iopap.upperdarby26.com/FIFO.js
http://iopap.upperdarby26.com/Web_Ring.js
http://iopap.upperdarby26.com/Real-Time.js
http://iopap.upperdarby26.com:8080/index.php
http://iopap.upperdarby26.com/Applet1.html
http://study.ldela.org:8080/Webcam.js
http://kollinsoy.skyefenton.com:8080/
http://inc.propertyfiend.com:8080/LCD.js
Clean up:
This javascript is added without any obfuscation to the index.php and the .js files. Just removing that from there should clean the problem.
Malware dump:
< script src = " http:// iopap.uppperdarby26.com / FIFO.js "