|
|
|
Windows Secrets Newsletter • Issue 217 • 2009-10-08 • Circulation: over 400,000 |
|
AD
|
|
Table of contents TOP STORY: Sponsored search results lead to malware KNOWN ISSUES: More tips for avoiding Windows 7 upgrade bumps WACKY WEB WEEK: Almost all spam traced to a single country LANGALIST PLUS: Make sure your private data's snoop-proof WOODY'S WINDOWS: Free MS Security Essentials are worth trying PERIMETER SCAN: Take steps to secure your home network's router |
|
ADS
|
|
TOP STORY Sponsored search results lead to malware
By
Susan Bradley
The ads served by Bing and Google along with your search results are linking more and more often to sites trying to infect your machine. Neither Bing nor Google effectively prescreens these bogus advertisers, so it's up to us to detect and avoid them. You may recently have used either Google or Microsoft's new Bing search engine to find the popular Malwarebytes Anti-Malware utility. If so, chances are good that the sponsored ads alongside your search results contained links to the very malware that the security tool is designed to remove. The three largest search sites — Google, Yahoo, and Bing — regularly sell security-related keywords to criminals looking to trick you into downloading and installing fake anti-malware products. The crooks then steal your personal information or hold your system for ransom before letting you remove their malware from your machine. The search providers have been aware of this for years. To their discredit, they've done little to end the practice, even though it's in their power to do so. The reason? They're making money hand over fist from those sponsored text ads and don't want to kill the goose that lays the golden eggs. Case in point: A Windows Secrets reader searched Bing for Malwarebytes Anti-Malware. He clicked the first link displayed and ended up on a site that installed a rogue antivirus program on his PC. (See Figure 1.) ![]() Figure 1. Malicious sponsored ads are interspersed with links to legitimate companies when you query search engines for the Malwarebytes security program. Rather than getting a tool to clean up a friend's infected computer, this Web surfer ended up having to disinfect his own. He and several other people I've heard from recently were hit with the result of search services' selling sponsored links without validating those links' legitimacy. As search terms become popular, scammers jump at the chance to have their bogus ads appear among the results. To get their deceptive ads into these highly visible search results, these criminals simply buy these high-traffic terms from the search engines. Big-name sites still serving up malicious ads Another form of dangerous Web ads appears on otherwise legitimate sites. WS contributing editor Scott Dunn described a year and a half ago in an April 17, 2008, Top Story infectious Flash ads that achieved space on well-known sites. I also reported on drive-by malware downloads in the June 11, 2009, Top Story. In the most-recent case, NYTimes.com and other established sites hosted malware-infested ads. The New York Times described the attack in a Sept. 14 article. When malicious ads — or "malvertisements" — enter the rotation on these sites, your system may become infected if you merely view the page. This is especially true if your versions of media players based on Java, Flash, or QuickTime are out-of-date. It's getting so bad that even top officials at Google acknowledge the problem, though they haven't yet taken steps to halt it. Eric Davis, head of anti-malvertising at Google, stated at the 2009 Virus Bulletin Conference that the industry needs to work together to combat this problem. As reported by Dennis Fisher on Kaspersky Lab's Threat Post site, Davis called for the creation of an industry clearinghouse that would certify ad servers. Such an organization would allow all search vendors and other sites to use online-ad agencies without fear that a malicious ad would insert itself into rotation. Microsoft has decided to use the courts as a weapon against malicious advertisers. A Sept. 18 Associated Press article posted on the MSNBC site states that the company is attempting to go after several suspicious ad vendors. Even using Yahoo or a smaller search index won't prevent such attacks, because second-tier engines have been hit with malicious ads, too, as a Sept. 25 story by Deborah Hale on Incidents.org reported. Ways to fight back against online attack ads Following my investigation of the malicious ads on Bing, I contacted the Microsoft Security Response Center, which can be reached via secure at microsoft.com. Within a few days, the offensive ads were removed. However, searching on the term malwarebytes combined with such words as virus and antivirus continued to return dubious destinations in Bing's sponsored-links section. The same type of ads appears among Google results when you search on similar terms. Depending on the location you search from, you may see a link to Cyberdefender.com among the results. This company is listed on the hpHosts site as selling fraudulent software. I reported this site to Google via a Web form on the Google site. But to date, no action has been taken to remove this and related malicious links. Unfortunately, balancing the scales of justice takes time. What can you do in the meantime to help protect yourself from these malicious ads?
Susan Bradley recently received an MVP (Most Valuable Professional) award from Microsoft for her knowledge in the areas of Small Business Server and network security. She's also a partner in a California CPA firm. |
|
ADS
|
|
KNOWN ISSUES More tips for avoiding Windows 7 upgrade bumps
By
Dennis O'Reilly
For most PC users, the migration to Microsoft's new version of Windows will go smoothly — with a little preparation. Spending a few minutes getting your system ready before you insert that Windows 7 installation disc may save you hours of troubleshooting and repair afterward. The countdown to Microsoft's official Windows 7 launch to consumers on Oct. 22 has begun. As WS contributing editor Scott Spanbauer described in his Oct. 1 Top Story, taking some time to prep your system prior to the upgrade can go a long way toward ensuring a fruitful Win7 experience. In addition to Scott's pointers, our readers know of one or two other tips you can add to your Win7 upgrade preparations. Tom Rosania points out one way to avoid applications that won't activate:
Other clutter to clean out prior to Windows 7 Scott's article listed several areas to clean prior to upgrading Vista to Windows 7. But Victor Sacco would like to add a couple of nooks and crannies to the list:
The Known Issues column brings you readers' comments on our recent articles. Dennis O'Reilly is technical editor of WindowsSecrets.com. |
|
WACKY WEB WEEK Almost all spam traced to a single country
|
|
BONUS DOWNLOAD
|
|
PERMALINKS Use these permalinks to share info with friends We love it when you include the links shown below in e-mails to your friends. This is better than forwarding your copy of our e-mail newsletter. (When our newsletter is forwarded, some recipients click "report as spam," and corporate filters start blocking our e-mails.) The following link includes all articles this week: http://WindowsSecrets.com/comp/091008 Free content posted on Oct. 8, 2009:
You get all of the following in our paid content:
Thanks in advance for your support! |
|
YOUR SUBSCRIPTION The Windows Secrets Newsletter is published weekly on the 1st through 4th Thursdays of each month, plus occasional news updates. We skip an issue on the 5th Thursday of any month, the week of Thanksgiving, and the last two weeks of August and December. Windows Secrets is a continuation of four merged publications: Brian's Buzz on Windows and Woody's Windows Watch in 2004, the LangaList in 2006, and the Support Alert Newsletter in 2008. Publisher: WindowsSecrets.com LLC, Attn: #120 Editor, 1700 7th Ave., Suite 116, Seattle, WA 98101-1323 USA. Vendors, please send no unsolicited packages to this address (readers' letters are fine). Editorial Director: Brian Livingston. Senior Editor: Ian Richards. Editor-at-Large: Fred Langa. Technical Editor: Dennis O'Reilly. Program Director: Tony Johnston. Web Developers: Dan Engler, Damian Wadley. Research Director: Stephanie Small. Research Analyst: Allison Espiritu. Copyeditor: Roberta Scholz. Contributing Editors: Susan Bradley, Scott Dunn, Michael Lasky, Woody Leonhard, Ryan Russell, Scott Spanbauer, Robert Vamosi, Becky Waring. Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, Support Alert, LangaList, LangaList Plus, WinFind, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of WindowsSecrets.com LLC. All other marks are the trademarks or service marks of their respective owners. HOW TO SUBSCRIBE: Anyone may subscribe to this newsletter by visiting our free signup page. WE GUARANTEE YOUR PRIVACY: 1. We will never sell, rent, or give away your address to any outside party, ever. 2. We will never send you any unrequested e-mail, besides newsletter updates. 3. All unsubscribe requests are honored immediately, period. Privacy policy HOW TO UNSUBSCRIBE: To unsubscribe from the Windows Secrets Newsletter,
|