Dear Users,

Since yesterday I am getting strong alerts which indicate that the portal Incometax.gov.in is apparently infected with “Mal/Badsrc-C” also known as HTML_AGENT.APAY”

These alerts are reported by the leading spyware solution “Spyware Sweeper” of Webroot Software Inc, USA.

According to SOPHOS – Mal/Badsrc-C is a malicious web page that has been compromised to load a script from a malicious website. The same can be viewed at:

sophos.com/security/analyses/viruses-and-spyware/malbadsrcc.html

According to Trendmicro – This malicious HTML script may be hosted on a Web site and run when a user accesses the said Web site. It redirects an affected user to another URL ………../vv.js. This is a malicious script detected by Trend Micro as JS_DLOADER.JYT. The said script, in turn, downloads a Trojan that is detected as TROJ_AGENT.WPA. The same can be viewd at:

trendmicro.com/vinfo/virusencyclo/default5.asp?VName=HTML_AGENT.APAY

I request all the concerned officials to look into the matter and strongly advise every user to get a good and exclusive spyware remover (and that is different from a traditional virus scanner) installed and sweep your machine fully and mount all the shields while online.

Thanking You

http://lohni.sulekha.com/blog/post/2008/06/indication-of-a-malicious-java-script-at-incometaxindia-gov-in.htm