Form letter - website exploit/malware distribution

With the rash of exploits out there for Adobe products, that is a lot of FTP password data being stolen on client PCs making for large amounts of malware distribution and other problems.

We have written the form below and allow you to reuse it and modify it to your needs to send to clients if you see a google alert on their domains.
We may modify this letter a bit adding bits of other data and possibly some recommended Anti virus solutions if we need based on input from clients.
Feel free to use the content of the forum post about the adobe exploits as well, or take the two posts here and there and merge them into a single mail as you see fit.

Letter:

Dear customer,

We have found that your website “Domain name” is being used for malware distribution. Google safe browsing is showing your domain name on their website and giving alerts to visitors to your site. Please see below link

Firstly, please scan your local system with some good anti virus and make sure, you have no virus and malware on system. Then you need to download all your data from server and scan it with Anti virus. After that please make sure, no unknown IFRAME, malicious script or code files in your data. Then delete all data from FTP and reupload your scanned files, at minimum replace and OVERWRITE any files changed since you last uploaded. Also change your FTP password after scanning for problems and update your Adobe software, as recent exploits have used Adobe Flash, Shockwave, and PDF Reader to steal passwords from users, see this link for information on updating your computer:

http://support.jodohost.com/showthread.php?t=16921

After cleaning your site up, report to google webmaster that you have scanned your data and now your data is safe. Please see the below link for google webmaster:

Google Search Central (formerly Webmasters) | Web SEO Resources  |  Google for Developers
1- Click on Sign in to webmaster tool
2- Enter any of your gmail account details.
3- Click on Add a sites button.
4- Enter your website name and press enter.
5- Now, you need to verify that you are a site owner. Select any method from Verification method drop box.
5- Follow google instruction for domain verification.
6- After verification, you will see such message “This site may be distributing malware. More Details”
7- Click on More Details.
8- Click on Request a review.
9- Select “I certify that I have removed badware or badware links from my site, according to StopBadware.org’s Security Tips For Websites.”
10- Click on request a review.

After that google will review your website again. If everything is good now, google will remove your domain from malware distribution domain list. As per Google, review can take up to 30 Days but we have seen google review websites within 24 hours after reporting. After this your domain will not show Red alert pages on Mozilla Firefox, of Microsoft IE8.

With Regards,

Signed

Note - If you don’t find a Virus/Trojan/Spyware on your computer, it means your AV may not have signature to detect this particular infection. We suggest to use alternative AV software until you are able to find an infection.