A TREND MICRO BLOG

UPDATE: I have been speaking to the folks from Razer, as soon as they were aware of the issue, they took down the support website and are working really hard to rectify things. It’s really great to see a company that have the safety of their customers so uppermost in their minds.

__________________________________________________________________________________________

The support website at gaming hardware manufacturer Razer, has been compromised to distribute malware.

 

Razer, in their own words are “the worldwide leader in terms of professional gaming peripherals. While we are light years ahead of our competitors in terms of technology, design and ergonomics“.

 

A large amount of the device drivers offered for download at the Razer support site were infected with a Trojan TROJ_DROPPER.JIZ. The Trojan delivers the original installer but then goes on to drop a copy of WORM_ASPXOR.AB in the System directory. The malware had very low detection rates, with only 7 out of 41 vendors offering generic detection.

 

I have informed Razer of this compromise and they have immediately taken the support website down for the time being. I am hoping to hear back from them once their root cause analysis is complete.

 

razer

 

It is unclear how long the problem has been ongoing, so in the meantime, if you downloaded anything from Razer recently, head over to HouseCall and run a full system scan and clean up if necessary. Manual clean-up instructions can be found here.


Bookmark
| More

This entry was posted on Monday, 21. September 2009 and is filed under "Site Compromise, malware". You can follow any responses to this entry with RSS 2.0. You can leave a response here, or send a trackback from your own site.

11 Comments

  1. [...] a researcher with Trend Micro. After hearing comments from concerned customers, Trend researchers took a look at Razer’s drivers. They downloaded eight infected drivers, and immediately contacted Razer. [...]

  2. [...] the leading manufacturers of gaming mice, was giving out malware with their drivers, according to a post on security firm Trend Micro’s [...]

  3. [...] the leading manufacturers of gaming mice, was giving out malware with their drivers, according to a post on security firm Trend Micro's [...]

  4. [...] the leading manufacturers of gaming mice, was giving out malware with their drivers, according to a post on security firm Trend Micro’s [...]

  5. [...] with Trend Micro. After hearing comments from concerned customers, Trend researchers took a look at Razer’s drivers. They downloaded 8 infected drivers, and immediately contacted Razer. [...]

  6. [...] the leading manufacturers of gaming mice, was giving out malware with their drivers, according to a post on security firm Trend Micro's website.According to Trend Micro, a large number of the device [...]

  7. [...] the leading manufacturers of gaming mice, was giving out malware with their drivers, according to a post on security firm Trend Micro’s [...]

  8. [...] firmware beinhalten den Trojaner Aspxor.abDie Infektion wurde durch Getroffende gemeldet,wonach Trend Micro die Sache untersuchte,dabei ist fesstgestellt dass eine grosse anzahl von Treiber infiziert ist und [...]

  9. [...] This post was mentioned on Twitter by Rik Ferguson and 5箱/takahisa watanabe. 5箱/takahisa watanabe said: Razer downloads distributing malware http://bit.ly/3xKCgU [...]

  10. [...] [...]

  11. [...] aparentemente inofensivas puede ocurrir una catástrofe inesperada. Leer más información en el blog de Trend Micro. Etiquetas: malware, troyano, virus Si te parecio interesante la entrada, puedes considerar [...]

Leave a comment

XHTML allowed tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Spam protection


© Copyright 2010 Trend Micro Inc. All rights reserved.
Legal Notice. Disclaimer