On CBS.com: Watch Exclusive CSI Cross Over Video
BNET Business Network:
BNET
TechRepublic
ZDNet

December 16th, 2008

Google sponsored links spreading (scareware) rogue AV

Posted by Ryan Naraine @ 10:55 am

Categories: Anti Virus, Botnets, Browsers, Data theft, Exploit code, Malware, Phishing, Rootkits, Spyware and Adware, Viruses and Worms

Tags: Google Inc., WinRar, Malware, Site, Spyware, Adware & Malware, Cyberthreats, Security, Viruses And Worms, Ryan Naraine

Malware hunters at Websense Security Labs have discovered legitimate Google sponsored links being used to plant scareware programs (rogue anti-virus applications) on the computers of Windows users.

In a blow-by-blow description of the rogueware attack, Websense researcher Elad Sharf shows how an innocent Google search for the Winrar file archiver and data compression utility can lead to a fake C|Net downloads.com page hosting a legitimate version of Winrar, with a nefarious twist:

Google sponsored links spreading (scareware) rogue AV

According to Sharf, the installer also drops a malicious file named explore.exe in the Windows system32 folder, and then runs the executable. The malicious file is associated with the icon used by Winrar SFX archives, and it binds to the system’s start-up.

The malicious explore.exe file proceeds to change the hosts file to point popular home page sites to a fake Microsoft Security Center site and displays displays a message box at one minute intervals.

This is how the scam works: after installing the infected program, users are interrupted with message boxes at one minute intervals. Thinking that the system has been infected, and irritated at the constant interruption, they might next search for information about the infection using the text that appears in the pop-up message. Finding legitimate forums discussing this infection, they will find confirmation that they are infected. The malware itself offers a fake remedy in the form of a pointer to a fake site. Users with any of the sites in the modified hosts file as their home page, or users who try to access any of those sites, are redirected to a site that pretends to be a Microsoft security center alert.

The end result is the user is tricked into running a security scan using this rogueware and receiving confirmation that the machine is indeed infected.  The criminals then attempt to sell a disinfection tool to remove the malware they installed on the victim’s machine.

Ugly stuff.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 21 Talkback(s)
RE: Google sponsored links spreading (scareware) rogue AV
How does one get rid of this virus? (Read the rest)
Posted by: Stev08 Posted on: 12/29/08 You are currently: a Guest | | Terms of Use
When will we put TEETH into laws on this.  No_Ax_to_Grind | 12/16/08
Err.. When Hades hosts the Winter Olympics.  Wolfie2K3 | 12/17/08
Nothing new  Joe_Raby | 12/16/08
Ask Google this question:  Joe_Raby | 12/16/08
Searching on "capons" will get you, too  ejhonda | 12/16/08
Really. Interesting notion...  zdnet@... | 12/16/08
Oops, was supposed to be reply to No_Ax  zdnet@... | 12/16/08
There can be safeguards  Michael Kelly | 12/16/08
As a business yes!  No_Ax_to_Grind | 12/16/08
Google ad links spreading IE7 exploits  Joe_Raby | 12/16/08
"Windows is not done  GuidingLight | 12/16/08
RE: Google sponsored links spreading (scareware) rogue AV  NStalnecker | 12/16/08
And...  thx-1138_@... | 12/17/08
Bring back Blue Frog!!  Joe_Raby | 12/16/08
RE: It happened to me.  richbraz0238@... | 12/16/08
You paid $149.00 for a reinstall??  Rubix_z | 12/18/08
Depends on the size of the job  Sparhawk_z | 12/18/08
$149 for a reload is **NOTHING**  TG2 | 12/18/08
You were dishonest, You got caught  bcarpent1228@... | 12/16/08
RE: Google sponsored links spreading (scareware) rogue AV  fairportfan | 12/17/08
RE: Google sponsored links spreading (scareware) rogue AV  Stev08 | 12/29/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here