Guys, be careful about surfing around on Wordpress sites today (or for the next few days, probably). It looks like quite a few Wordpress sites and blogs have been hacked. See here for more information. And here.
More discussion amongst Wordpress users here.
Edit: if you are the owner of a blog/site that's been hacked, check near the bottom of that discussion! They tell you how to fix it. There's also some good information here and here, though it's not as detailed.
GoDaddy is reporting that it's due to a handful of sites having outdated software, but I've run into at least 3 infected blogs today. The problem is, it's hard to tell which ones are infected when I have a million tabs open and I have to crash the browser to get away from the "Warning: Your computer is at risk of malware attacks!" scare messages.
I did manage to finally get a site to stay open long enough to look at the code, and found a line that looks like the Javascript script shown here. With the kp.php file included.
If you encounter an infected site, you may get a popup telling you that you have malware or are at risk. You will then be directed to a scanning program on a website, or something that looks an awful lot like a virus scanner finding a lot of bad things in your computer. DO NOT BELIEVE IT. This is a ploy to get you to download their program, which IS actually spyware/malware.
If you are told that you have malware or spyware by a program that doesn't quite look like your normal virus program, DO NOT LET IT DOWNLOAD ANYTHING TO YOUR COMPUTER. And definitely don't let it install anything! If possible, don't even click on anything in the popup window. (Yes, including the "x" in the corner...it could be the equivalent of clicking the "OK" button in some cases.) Instead, crash your browser using CTRL-ALT-DELETE and then start anew with a fresh browser session if possible. You may lose any tabs you have open, but you'll be safe.
The one I kept running into looked a lot like the virus/malware my sister and her family were infected with last year. (i.e., Internet Security 2010.) It was nasty and really hard to clean out.
If you don't think your computer is infected, but keep running into the problem described above, consider editing your hosts file to block the malware sites involved. The malware site I keep being redirected to is "www1.protectsys28-pd.xorg.pl" (don't visit that site, okay.) I've also seen "www3.workfree36-td.xorg.pl" (and don't visit that one, either.)
If you believe that you have been infected, please go here and follow the instructions. This is what I use! It's a long process to clean your computer out, but I've used the MajorGeeks Malware Removal Guide a bunch of times for friends and relatives and my own computer, and it's really helpful. It does work, it just takes time and effort to clean everything out.
If I could recommend installing and running one program in that guide, I would tell you to get MalwareBytes Anti-Malware. It's a really good program. It won't catch everything, but it will clean out most things.
Heck, even if you don't think you've been infected, it's a good idea to install it and run the program on a monthly basis...or even more often.
Be safe.