Industry News

-   Industry News (http://www.webhosting.info/news/)
-   -   Panda Software Finds Yahoo!, MSN and Google, 'Cloned' (http://www.webhosting.info/news/1/panda-software-finds-yahoo!,-msn-and-google,-cloned_1003054529.htm)

03rd October 2005 09:13 AM

Panda Software Finds Yahoo!, MSN and Google, 'Cloned'
 

Panda Software, a developer of virus and intrusion prevention solutions, today announced that it has identified PremiumSearch (adware), a new malicious code that takes advantage of some of the most popular Internet search engines.

According to the company, this cybercrime attack mimics the actions of the worm detected last week that altered the sponsored links in Google searches. In this case the infection originates from visits to a certain web page, when users are redirected from other pages containing warez (illegal software versions) or pornography. In addition to PremiumSearch, this page also installs an application, 'WorldAntiSpy' on a victim's computer, along with a variant of Smitfraud, leading users to believe they have been infected by a series of threats and will have to pay to disinfect them. 

Exploiting some of the vulnerabilities most frequently used by spyware, PremiumSearch installs a malicious BHO (Browser Helper Object). It then installs a 'Google' toolbar (which does not come from Google but has been created by a third party), and modifies the HOSTS file. The BHO also changes the browser home page to the PremiumSearch search engine, even if a user specifies another. These modifications direct users that request MSN, Yahoo! and Google to spoof versions which are indistinguishable from the originals, other than the fact that the first results displayed have been altered (the remaining results are the same as for the genuine pages). The same occurs with searches launched through the spoof Google toolbar. The web page from which the spoof versions are obtained are hosted in the USA as per PandaLabs.

"These actions are financially motivated and aim to exploit the popularity of these search engines to increase visits to the pages with the altered results. To avoid this kind of attack, it is vital that users have reliable antivirus protection and keep their systems up-to-date, as the vulnerabilities used have often been in existence for some time," said Luis Corrons, Director of PandaLabs.



The time now is 10:39 PM (EST)

Copyright© 2003, WebHosting.Info - A Directi Service.