Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

July 21st, 2011, 08:29 GMT · By

Millions of Computers Infected with Click Fraud Trojan Found by Google

SHARE:

Adjust text size:


Google addresses concerns abouts its malware warnings
Enlarge picture
Google claims the owners of hundreds of thousands of computers infected with a click fraud trojan were helped by the malware warning it started displaying on its website.

The company offered a few other details about the trojan that led to the unprecedented decision to alert users via its website.

"The malware appears to have gotten onto users' computers from one of roughly a hundred variants of fake antivirus, or 'fake AV' software that has been in circulation for a while," Google said.

The company notes that it's not aware of a common name for the trojan discovered by its engineers while investigating unusual search traffic. This means the piece of malware is not widely detected yet and is only picked up by generic signatures.

Nevertheless, the trojan is relatively widespread, Google claiming that "a couple million machines are affected by this malware" and that hundreds of thousands of users have already been warned.

The company tried to address concerns expressed by various people that its warnings might be later spoofed by cyber criminals to distribute malware.

"We've heard from a number of you that you're thinking about the potential for an attacker to copy our notice and attempt to point users to a dangerous site instead. It's a good security practice to be cautious about the links you click, so the spirit of those comments is spot-on," Google security engineer Damian Menscher wrote.

"We thought about this, too, which is why the notice appears only at the top of our search results page. Falsifying the message on this page would require prior compromise of that computer, so the notice is not a risk to additional users," he explains.

Of course that's not necessarily true. Let's imagine a rogue link on a legit compromised site which takes users to a spoofed Google search results page displaying the fake warning with another link to a fake antivirus product. That would make for a pretty powerful social engineering attack.

TELL US WHAT YOU THINK:

2,171 hits · 2 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Google Warns Users About Malware Infection

Click Fraud Trojan Distributors Borrow Scareware Techniques

New Scareware Campaign Uses Fake Firefox Security Alerts

Fake Firefox and Chrome Warning Pages Distribute Malware

READER COMMENTS:


Comment #1 by: AC on 02 Aug 2011, 05:01 UTC reply to this comment

PPT vs PPC
PREPARE FOR THE SEARCH ENGINE REVOLUTION!
EXPOSING SEARCH ENGINES CLICK SCAM.
PAY FOR TIME IN POSITION not CLICKS!
ONLY TIME IS MONEY, CLICK IS THE EVEL TRICK!
PPT/PPP/PPT&P vs PPC
PAY-PER-TIME / PAY-PER-POSITION / PAY-PER-TIME-IN-POSITION / PAY-PER-TIME-&-POSITION
BIGGEST SCAM OF ALL TIMES: GOOGLE SOLD US ON “CLICKS” AND “AD NON-SENCE”
LETS BAN PPC
PPC IS THE ROOT OF ALL EVIL
“ Take the course opposite to custom and you will almost always do well. ”
— Jean Jacques Rousseau
PPC is Google’s tax on small businesses under Wall Street protection.
I repeatedly explain that less government/google’s PPC/”google’s tax on small businesses” on the web means more money left in the private sector, where it is more likely to create jobs and generate wealth.


Comment #2 by: AC on 02 Aug 2011, 05:02 UTC reply to this comment

Hi there,
I suggest new and completely different solution, which can be used by all search engines. We need to stop search engine from keeping on stealing our hard earned advertiser’s money.
The solution is very simple, as all right solutions:
STOP PAYING FOR CLICKS and COUNTING THEM!
LETS COUNT TIME OF BEING AT A SPOT and PAY ONLY FOR TIME.
Every spot and time on search result page can have its value
due to special location, and particular prime time.
This will allow for an auction among the advertisers to get particular time or spot for a particular duration, knowing how many clicks this spot brings. Simple as that!
AND THIS WILL ALMOST ELIMINATE THE CLICK FRAUDS!
The only way and interest to create fraudulent clicks it will allow for is for search engines to raise value of a particular spot or prime time by forging number of clicks this spot and prime time brings. However, it will not bring us that much of a growing trouble, and search engines can be easily punished for those kinds of bad click tactics.
Now they simply continue making their dirty money by letting us to click on each other ads, creating automatic click bots and capitalizing on it BIG TIME in billions. We can be leaving those billions in small business pockets and it’s up to us to vote for this in every blog possible. Lets spread the news.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM