I think a possible way to stop affiliate code replacements would be for all affiliates to be allowed to make domain aliases for the sites they're promoting...
Example :
You are an affiliate promoting cumfiesta.com .. when you link to the site like this cumfiesta.com?affid=mrcool then these thieves script see that the infected computer is loading the cumfiesta.com domain and then maked the replacement of the affid...
The affiliate could then reg his own domain for this site.. like cumfiestatour.com (nastydollar then need to add this as an alias to cumfiesta.com) then the trojan script can't recognize the domain and can't make any affid replacement..
|