There is currently active an “exploit” of web servers labeled “LizaMoon”.
The attack perhaps is originating from Romania. It has the ability to add an extra line at the end of a web pages you might visit that causes anyone visiting the web site to be hijacked and sent to a web site that announces your computer is infected, and you must immediately turn over your Credit Card number in order to buy their Anti Virus service to deinfect your computer. (Your computer is not infected until after you install their fake software)
The fake antivirus site looks like this:

Don’t do that :)
If you did do that already, call your credit card company ASAP.
From what I’ve read so far, it looks to be exploiting a hole in Microsoft SQL server and/or IIS. I don’t think it can affect this server, but I’m snooping around. I’ve seen some weird stuff in my logs the past few days and several infected web sites. The ones I’ve found are mostly derelict and I get no response to my emails alerting them to their problem.
*** Update ***
I now understand the attack, more or less. They are using an SQL injection attack to append their script invocation at the end of random text fields that would then echo the script, causing people to be redirected to the site stealing people’s credit cards with the fake anti-virus program.
As such, it probably could affect any web server which isn’t defensive enough about protecting against SQL injection. WordPress is the only part of the stuff on this web site I didn’t write, so I don’t know if it is vulnerable.
The good news is that much of the world can’t see this web site. If you go to Malaysia or Romania, you won’t be able to see this web site, sorry. :) I’m a bit anal retentive about not exposing the web site to people who hate Americans and are beyond the reach of the US Law enforcement. I don’t think this web site is vulnerable, but my antenna is definitely up.
This kind of fraud has been around for a while (probably different ones, but the same genre), and I’ve seen them in action. Often, you get hijacked to a site and a “scan” begins instantly, along with the hype to “upgrade” (i.e., buy) the wonderful software now! I think I’ve seen popups purporting to offer the same kinds of “services” for the unwary fish. My reaction to absolutely any and every unexpected redirect is to kill the pages, if not the whole browser immediately. I wouldn’t read a popup, even if sent from God. I don’t trust anyone on the Internet.
—
On a slightly related note, I’ve had to deal with a small number of annoyingly persistent Chinese servers port-scanning my computer, 10 to 30 or so times per day. I sent abuse complaints to them and was ignored or the mail was returned. I wound up blocking the whole server each time to put an end to it. Seems to me our Nanny State government ought to be raising some hell with China over this. Oh, I forgot. They Own us. Never mind.