forum for IT geniuses
ftfy
Yet more goofiness: all the download links for all the trojaned files are hosted at some guy's house. He's using a D-Link router presumably and using the DynDNS service that D-Link provides. The machine that he's hosting the trojan on is running Debian 6.
what country
BTW: If you highlight the text you will see hidden messages in all posts. For some reason they are invisible?
OK. The crappy skyline banner seems to be the #1 way to find these sites. I've added a bunch more to the OP. I'm gonna contact all the sites (the English ones at least) and ask what is going on.
My guess is the person/group doing this is using some vulnerability in Apache to gain access to these sites and this is the result of not keeping your servers up-to-date. And yes, it's all the same person/group doing this, the trojan link leads back to the same D-Link DynDNS result.