Google is going to start reporting whether sites have been hijacked to distribute malware. In short, they're testing websites using virtual machines inside their labs, and if they install malware, they'll be marked in the search results as malicious, and they won't be indexed.
I think it's a great idea, but it only goes so far. Not everyone gets to websites from search engines... so what about malware sites linked from e-mails and what not? Well, Google should share this information with the group that populates data for the IE7 Phishing Filter, so that Microsoft can extend IE7 in Windows Vista SP1 to protect users before the site even loads.
Will Google do it? Probably not. But they should. What do you think?