Yesterday I received an email to notify me of a case that looked like a malicious Google sponsored ad result. I tried to make sense of it, unraveling some obfuscated JavaScript, then stages of Batch and PowerShell (with some interesting code comments), leading to an InnoSetup installer of an unexpected SVN application -- a bundle pre-packaging the legitimate software, but with a modified malicious DLL.

