Vulnerabilities / Threats
7/20/2011
02:24 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Google Warns Searchers Of Windows Malware Infection

Google has started alerting users running Windows about a specific form of local malware it can detect through network traffic flows.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
Hundreds of thousands of people using Google Search have seen this message atop a search results page recently: "Your computer appears to be infected." While finding malware on one's computer can be disconcerting, it's also disconcerting to consider that Google appears to know what's on your computer.

In fact, Google doesn't know about your applications, apart from those you use to access Google services on the Internet. If the company has identified malware on your computer, it's because your computer is probably infected with malware that hijacks Google search results and redirects search traffic to websites for payment.

For years, Google has presented alerts about websites in its search index that it believes may have been compromised to serve malware. It has also provided open-source Web security research tools such as skipfish, ratproxy, and DOM Snitch. This is the first time Google has applied its knowledge of Internet network traffic to identify malware on its users' local computers.

Google security engineer Damian Menscher said the company's security team discovered unusual search traffic while performing routine maintenance on one of its data centers. "After collaborating with security engineers at several companies that were sending this modified traffic, we determined that the computers exhibiting this behavior were infected with a particular strain of malicious software, or 'malware,'" he explained in a blog post.

The malware prompts infected Windows computers to send traffic to Google through proxy servers. Google is detecting traffic that comes from these servers and notifying users sending the traffic that their computers appear to be infected.

Google says that that several million PCs appear to be affected, that it has warned several hundred thousand people, and that the source of the infection appears to be one of roughly a hundred variants of fake antivirus software. The company says it is not aware of a specific name for the fake antivirus software responsible for the infection.

Google advises that users utilize current antivirus software to scan for an infection and to be wary of inadvertently installing fake antivirus software in an attempt to correct the problem. If legitimate antivirus software fails to fix the issue and Google searches still bring a warning message, Google provides instructions for manually cleaning one's Windows hosts file, through which the malware redirects Web requests.

Black Hat USA 2011 presents a unique opportunity for members of the security industry to gather and discuss the latest in cutting-edge research. It happens July 30-Aug. 4 in Las Vegas. Find out more and register.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8921
Published: 2015-03-01
The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuration option, which makes it easier for remote attackers to capture credentials by c...

CVE-2014-9676
Published: 2015-02-27
The seg_write_packet function in libavformat/segment.c in ffmpeg 2.1.4 and earlier does not free the correct memory location, which allows remote attackers to cause a denial of service ("invalid memory handler") and possibly execute arbitrary code via a crafted video that triggers a use after free.

CVE-2014-9682
Published: 2015-02-27
The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function.

CVE-2015-0655
Published: 2015-02-27
Cross-site scripting (XSS) vulnerability in Unified Web Interaction Manager in Cisco Unified Web and E-Mail Interaction Manager allows remote attackers to inject arbitrary web script or HTML via vectors related to a POST request, aka Bug ID CSCus74184.

CVE-2015-0884
Published: 2015-02-27
Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.