This has been known about for some time.
A website infected with Asprox will force the user’s browser to download JavaScript code that will attempt to exploit browser flaws to install other Trojan software and perhaps steal user credentials. The best defence is not to enable javascript in your browser.
For those of us running a web server, HP have produced a tool that can be used to check whether the server is vulnerable to SQL injection - more details
here.
Edit: It would appear that the attackers are not just after .asp pages, they are now targetting Cold Fusion applications, see
SANS