Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Protection available since | 30 April 2009 09:55:44 (GMT) |
| Last updated | 29 October 2009 15:35:32 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/JSRedir-R is a malicious script likely to have been injected into a defaced web page to load remote malicious content when the page is viewed. Analysis of many defaced sites has shown that many examples of Troj/JSRedi-R are buggy and do not work.
Websites affected with Troj/JSRedir-R may also see detections of Troj/PHPMod-A.
Working copies of Troj/JSRedir-R will redirect users to a Chinese Domain (hosted in Russia) and then via a series of PDF and SWF exploits attempt to install malware detected as Troj/Daonol-Fam.
For more information on this threat see the SophosLabs Blog.

