Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    May 2012
    S M T W T F S
    « Apr    
     12345
    6789101112
    13141516171819
    20212223242526
    2728293031  
  • About Us
    Malware Blog > Porn Sites Lead to MBR Rootkit

    Websites related to pornography that appear to be compromised were found by Trend Micro engineers loading malicious JavaScript which redirects users onto malicious domains that ultimately lead to the download of an MBR rootkit (TROJ_SNOWAL.A)onto the affected system.

    The malicious JavaScripts are now detected as the following:

    The abovementioned malicious scripts all follow a similar routine: upon execution, it checks for the date on the target system then generates a URL based on the date obtained. It then creates an IFrame, which would redirect the user to the generated URL. The URL then leads to the download of a malicious file, which in turn downloads an MBR rootkit.

    Steps on how to identify and fix files infected by TROJ_SNOWAL.A can be found in the Virus Encyclopedia.
    On the other hand, the Smart Protection Network protects users by detecting the malicious JavaScript which leads to the download of the rootkit, therefore preventing the rootkit from being downloaded onto users’ systems in the first place.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    3 Responses to “Porn Sites Lead to MBR Rootkit”

    Trackbacks

    1. TrendMicro (TrendMicro)
    2. TrendMicro (TrendMicro)
    3. cybasurfa (cybasurfa)


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice