<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How to Remove reycross.com WordPress Malware</title>
	<atom:link href="http://www.kallasoft.com/how-to-remove-reycross-com-wordpress-malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.kallasoft.com/how-to-remove-reycross-com-wordpress-malware/</link>
	<description>Commercial-Friendly Open Source Software Development</description>
	<lastBuildDate>Fri, 05 Mar 2010 13:52:55 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Larry Furman</title>
		<link>http://www.kallasoft.com/how-to-remove-reycross-com-wordpress-malware/comment-page-1/#comment-2249</link>
		<dc:creator>Larry Furman</dc:creator>
		<pubDate>Mon, 28 Dec 2009 17:56:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.kallasoft.com/?p=1127#comment-2249</guid>
		<description>Find and sed are unix / linux tools. Have you tested this in a terminal wind on Mac OSX? What about MS Windows?</description>
		<content:encoded><![CDATA[<p>Find and sed are unix / linux tools. Have you tested this in a terminal wind on Mac OSX? What about MS Windows?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Larry Furman</title>
		<link>http://www.kallasoft.com/how-to-remove-reycross-com-wordpress-malware/comment-page-1/#comment-2248</link>
		<dc:creator>Larry Furman</dc:creator>
		<pubDate>Mon, 28 Dec 2009 17:56:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.kallasoft.com/?p=1127#comment-2248</guid>
		<description>Find and sed are unix linux tools. Have you tested this in a terminal wind on Mac OSX? What about windows?</description>
		<content:encoded><![CDATA[<p>Find and sed are unix linux tools. Have you tested this in a terminal wind on Mac OSX? What about windows?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Riyad Kalla</title>
		<link>http://www.kallasoft.com/how-to-remove-reycross-com-wordpress-malware/comment-page-1/#comment-2245</link>
		<dc:creator>Riyad Kalla</dc:creator>
		<pubDate>Sun, 27 Dec 2009 22:33:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.kallasoft.com/?p=1127#comment-2245</guid>
		<description>Jonathan I hope you guys got everything cleaned out OK? If you run the command given anyway, it&#039;s more or less a no-op if there are no matching hacked scripts so it&#039;s relatively harmless if you just wanted to run it to be safe. But if you already got things cleaned up then you should be OK.</description>
		<content:encoded><![CDATA[<p>Jonathan I hope you guys got everything cleaned out OK? If you run the command given anyway, it&#8217;s more or less a no-op if there are no matching hacked scripts so it&#8217;s relatively harmless if you just wanted to run it to be safe. But if you already got things cleaned up then you should be OK.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Riyad Kalla</title>
		<link>http://www.kallasoft.com/how-to-remove-reycross-com-wordpress-malware/comment-page-1/#comment-2244</link>
		<dc:creator>Riyad Kalla</dc:creator>
		<pubDate>Sun, 27 Dec 2009 22:31:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.kallasoft.com/?p=1127#comment-2244</guid>
		<description>Codrut,

I&#039;m not sure which part of WordPress generates the RSS feed content, so I&#039;m not sure where to look to clear that out -- but you execute that line of code I provided from a Unix/Linux command line from the root directory of where your wordpress install lives -- it will scan *every* file looking for the pattern of the injected infected content and replace it with nothing -- effectively removing it.

It should clean it out from wherever the RSS infection is taking place as well.</description>
		<content:encoded><![CDATA[<p>Codrut,</p>
<p>I&#8217;m not sure which part of WordPress generates the RSS feed content, so I&#8217;m not sure where to look to clear that out &#8212; but you execute that line of code I provided from a Unix/Linux command line from the root directory of where your wordpress install lives &#8212; it will scan *every* file looking for the pattern of the injected infected content and replace it with nothing &#8212; effectively removing it.</p>
<p>It should clean it out from wherever the RSS infection is taking place as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Malware attacks on WordPress</title>
		<link>http://www.kallasoft.com/how-to-remove-reycross-com-wordpress-malware/comment-page-1/#comment-2233</link>
		<dc:creator>Malware attacks on WordPress</dc:creator>
		<pubDate>Sun, 27 Dec 2009 14:21:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.kallasoft.com/?p=1127#comment-2233</guid>
		<description>[...] Riyad Kalla of the blog/website Kallasoft has written one helpful post How to Remove reycross.com WordPress Malware. [...]</description>
		<content:encoded><![CDATA[<p>[...] Riyad Kalla of the blog/website Kallasoft has written one helpful post How to Remove reycross.com WordPress Malware. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathan Soroko</title>
		<link>http://www.kallasoft.com/how-to-remove-reycross-com-wordpress-malware/comment-page-1/#comment-2232</link>
		<dc:creator>Jonathan Soroko</dc:creator>
		<pubDate>Sun, 27 Dec 2009 14:00:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.kallasoft.com/?p=1127#comment-2232</guid>
		<description>We seem to have been hit earlier - we discovered it in older posts only. And that accidentally by looking for an old post. 
But this is helpful - seeing another variation on the problem. 
JS</description>
		<content:encoded><![CDATA[<p>We seem to have been hit earlier &#8211; we discovered it in older posts only. And that accidentally by looking for an old post.<br />
But this is helpful &#8211; seeing another variation on the problem.<br />
JS</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Codrut Turcanu</title>
		<link>http://www.kallasoft.com/how-to-remove-reycross-com-wordpress-malware/comment-page-1/#comment-2188</link>
		<dc:creator>Codrut Turcanu</dc:creator>
		<pubDate>Mon, 21 Dec 2009 20:04:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.kallasoft.com/?p=1127#comment-2188</guid>
		<description>Hey, I&#039;m having similar problems... my RSS feed link got infected too

Any idea how to remove that too?

Also where and how do I include this text? [I&#039;m not a tech guy]

find . -name &#039;*.*&#039; -exec sed -i &#039;s///g&#039; {} \;

Thank you</description>
		<content:encoded><![CDATA[<p>Hey, I&#8217;m having similar problems&#8230; my RSS feed link got infected too</p>
<p>Any idea how to remove that too?</p>
<p>Also where and how do I include this text? [I'm not a tech guy]</p>
<p>find . -name &#8216;*.*&#8217; -exec sed -i &#8217;s///g&#8217; {} \;</p>
<p>Thank you</p>
]]></content:encoded>
	</item>
</channel>
</rss>
