|
Analysis showed the site had been hit by Gumblar, which finds its way into inadequately secured servers and then downloads malware onto computers visiting those sites.
Gumblar emerged in mid-2009, and was thought to be responsible for around one-third of all malware delivered in May 2009. Its name comes from gumblar.cn, the domain it originally used to deliver malware to PCs.
The original purpose of the malware was to redirect Google searches to malicious sites and to search for usernames and passwords that could be used to compromise other servers. More recent variants may also capture credit card numbers.
Gumblar was the most active botnet during 2009, according to Cisco subsidiary ScanSafe.
NineMSN is a joint venture of Microsoft and PBL Media. When Websense discovered the infection it informed Microsoft and the compromised banner ad was removed.