Press Release
Promise of Secure Porn Browsing Lures People into Installing Rootkit, Trojan
NetBrowserPro misdirects users
FOSTER CITY, CALIF. - March 28, 2007 - When: Discovered March 28, 2007
What: NetBrowserPro, a Web browser, promises secure porn browsing, but
installs a rootkit and a Trojan called MovieCommander. Moviecommander is
disguised as a fake media codec. A rootkit is a set of tools intended to
conceal running processes, files or system data from the operating system.
When the user installs the NetBrowserPro from Browsezilla.org with the 121.exe
file, they agree to allow the program to update and modify itself without
notification and have third party applications interact with the browser. Many
of the photo galleries linked from the browser will redirect the end-user to an
unintended location, which is potentially a security threat.
Who: FaceTime Security Labs, the threat research and remediation arm of
FaceTime Communication discovered the browser.
Why: Individuals are increasingly creating fake browsers to deceive
users and direct Internet traffic, based on FaceTime research. With fake
browsers and other adware, they can gain control of computers by tricking the
user, instead of exploiting more complex software vulnerabilities. Users can
also fall victim to data and identity theft or violations of privacy when using
rogue browsers.
The FaceTime research team offers a detailed accounting of the infection and
the possible motives at blog.spywareguide.com/2007/03/netbrowserpro_the_porn_browser.html
About FaceTime Communications
FaceTime enables the safe and productive use of greynets like instant
messaging, Skype, web conferencing and P2P file sharing. Ranked number one in
market share among instant messaging management vendors for the third
consecutive year, FaceTime's award-winning solutions are used by more than 800
customers including nine of the ten largest U.S. banks. FaceTime Security Labs
delivers the industry's first IMPact Index, which assesses "point-in-time"
risks posed by viruses, worms and other malware propagating through greynet
applications. FaceTime supports or has strategic partnerships with all leading
public and private IM network providers, including AOL, Google, Microsoft,
Yahoo!, IBM and Jabber.
FaceTime is headquartered in Foster City, California. For more information visit http://www.facetime.com or call 888-349-FACE.
PR Contact:
Joshua Barnes
A&R Edelman
650-762-2865
joshua.barnes@ar-edelman.com
|