Home Malware Programs Trojans Troj/JSRedir-GZ

Troj/JSRedir-GZ

Posted: July 2, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 19
First Seen: July 2, 2012
Last Seen: October 14, 2024
OS(es) Affected: Windows

Troj/JSRedir-GZ is a Trojan that spreads via spam ADP (a payroll processing company) emails. Two types of the ADP spam emails are spreading on the Internet. One is fairly a plain text message with the subject 'ADP Funding Notification - Debit Draft' instructing recipients to click a link to view a supposed transaction report. The second is more professional looking and offers to human resource specialists that ADP is updating its security processes and a recipient needs to login and be instructed on the new procedures. The links included in all of the malicious messages redirect affected PC users to hijacked websites that try to load a malicious JavaScript that has all of the significant signs of the Blackhole Exploit Kit. The malicious JavaScript is detected as Troj/JSRedir-GZ.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



rrggyt.html File name: rrggyt.html
Size: 850B (850 bytes)
MD5: 0994d1b78069fed714b86f26793ffac6
Detection count: 74
Mime Type: unknown/html
Group: Malware file
Last Updated: July 4, 2012
Loading...