Gootkit Malware
April 8, 2010
The Gootkit malware places obfuscated malicious JavaScript into a website's web pages. To clean the website, the website needs to be reverted to a clean backup or the malicious code needs to be removed from the web pages and or JavaScript files. The malware gains access to the website through FTP credentials that have been compromised by malware located on a computer that has accessed the website via FTP. To prevent the website from being reinfected the FTP password needs to be changed and the malware removed from the infected computer before it used again to again to access the website via FTP.
Recent Script Format On Web Pages:
Recent Domains Used by the Malware: safniiyew.com, sadahesz.com
Recent Virus Scan Identifications: JS:Redirector-CB