On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

November 10th, 2008

CNET Download.com not so 'spyware-free'

Posted by Ryan Naraine @ 8:30 am

Categories: Anti Virus, Browsers, Malware, Privacy, Research, Responsible disclosure, Spam and Phishing, Spyware and Adware, Viruses and Worms

Tags: Adware, Kaspersky Lab, Malware, CNET Download.com, Spyware, Adware & Malware, Spyware, Cyberthreats, Viruses And Worms, Security, Ryan Naraine

On its home page, CNET’s Download.com promises that all software available on the site “has been tested to ensure it’s 100% free of spyware, viruses, and other malware.”     Unfortunately, there appears to be a kink in the system that allows the display of a known adware program called AntiVirus Defender.

According to malware researchers at Kaspersky Lab (disclosure: my employer), the adware program is appearing as a recommendation in Download.com’s Anti Virus Software tab (see screenshot below):

CNET Download.com not so ’spyware-free’

Kaspersky Lab discovered the issue while downloading a piece of software and being redirected to the Downloads.com recommendations page.  We’re not sure if this is something that slipped through the cracks at Downloads.com or whether the site was compromised. CNET has been notified.

The moral of this:

You’re security conscious and you want to protect your computer. You’re looking for useful utilities. Download.com assures users that all programs available via the website have been analysed, and don’t contain any malicious code. So maybe you relax your vigilance. But with both businesses and bad guys making use of sponsored links on sites like download.com and Google, you’ve got to stay very alert indeed to make sure that you don’t get caught out. 

* Image source: Viruslist.com analyst’s diary.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 7 Talkback(s)
RE: CNET Download.com not so 'spyware-free'
have downloaded many things from download np have directed others to the site also. I use avast and have had np's verse nortons lol.... what a joke.. verse other sites download is safer if u get redirected u dont go to it unless ur blonde lol honk honk... (Read the rest)
Posted by: goose58431 Posted on: 12/04/08 You are currently: a Guest | | Terms of Use
Anyone else notice the irony of the name?  MGP2 | 11/10/08
RE: CNET Download.com not so 'spyware-free'  aliendogstar | 11/11/08
winrar is spyware-free  sixit | 11/17/08
RE: CNET Download.com not so 'spyware-free'  tonybonnet | 11/13/08
RE: CNET Download.com not so 'spyware-free'  oregonnerd13 | 11/19/08
RE: CNET Download.com not so 'spyware-free'  edkofc4@... | 11/26/08
RE: CNET Download.com not so 'spyware-free'  goose58431 | 12/04/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More