In the comments and in other places, I’ve seen a lot of folks breathe a sigh of relief that they finished cleaning out the JSRedir-R / Gumblar.cn infection, only to shortly thereafter find they got reinfected. It looks like reinfection is happening through compromised desktop computers that seek out FTP username and password information [...]
