This malware attack has recurred again today, starting nearly 24 hours ago - same site, different files.
This time I'm seeing that the "query string" solution is still working, but it doesn't clear the cache.
My problem is that:
ppm install http://www.sisyphusion.tk/ppm/Cairo.ppd
installs an older version of the Cairo ppm package than is currently on the server.
It accesses an outdated (non-existent) Cairo.ppd, and installs outdated (non-existent) binaries.
Out of curiosity I tried:
ppm install http://www.sisyphusion.tk/ppm/Cairo.ppd?no=cache
but the ppm utlity croaks on that. Besides, it still would have installed the cached binaries.
I haven't tried
wget --no-cache yet as that cleared the cache last time.
Instead, I've decided to leave the cache uncleared in case it helps my ISP (who I've contacted again) remove the malware.
My ISP did not respond last time ... let's see what happens this time.
This update is largely for my own records - but I'm also submitting it in case someone has something to add.
Cheers,
Rob