Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

7/20/2011
02:24 PM
Connect Directly
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Google Warns Searchers Of Windows Malware Infection

Google has started alerting users running Windows about a specific form of local malware it can detect through network traffic flows.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
Hundreds of thousands of people using Google Search have seen this message atop a search results page recently: "Your computer appears to be infected." While finding malware on one's computer can be disconcerting, it's also disconcerting to consider that Google appears to know what's on your computer.

In fact, Google doesn't know about your applications, apart from those you use to access Google services on the Internet. If the company has identified malware on your computer, it's because your computer is probably infected with malware that hijacks Google search results and redirects search traffic to websites for payment.

For years, Google has presented alerts about websites in its search index that it believes may have been compromised to serve malware. It has also provided open-source Web security research tools such as skipfish, ratproxy, and DOM Snitch. This is the first time Google has applied its knowledge of Internet network traffic to identify malware on its users' local computers.

Google security engineer Damian Menscher said the company's security team discovered unusual search traffic while performing routine maintenance on one of its data centers. "After collaborating with security engineers at several companies that were sending this modified traffic, we determined that the computers exhibiting this behavior were infected with a particular strain of malicious software, or 'malware,'" he explained in a blog post.

The malware prompts infected Windows computers to send traffic to Google through proxy servers. Google is detecting traffic that comes from these servers and notifying users sending the traffic that their computers appear to be infected.

Google says that that several million PCs appear to be affected, that it has warned several hundred thousand people, and that the source of the infection appears to be one of roughly a hundred variants of fake antivirus software. The company says it is not aware of a specific name for the fake antivirus software responsible for the infection.

Google advises that users utilize current antivirus software to scan for an infection and to be wary of inadvertently installing fake antivirus software in an attempt to correct the problem. If legitimate antivirus software fails to fix the issue and Google searches still bring a warning message, Google provides instructions for manually cleaning one's Windows hosts file, through which the malware redirects Web requests.

Black Hat USA 2011 presents a unique opportunity for members of the security industry to gather and discuss the latest in cutting-edge research. It happens July 30-Aug. 4 in Las Vegas. Find out more and register.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-23281
PUBLISHED: 2021-04-13
Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability. IPM software does not sanitize the date provided via coverterCheckList action in meta_driver_srv.js class. Attackers can send a specially crafted packet to make IPM connect to ro...
CVE-2021-27598
PUBLISHED: 2021-04-13
SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of missing authorization check in the servlet.
CVE-2021-27600
PUBLISHED: 2021-04-13
SAP Manufacturing Execution (System Rules), versions - 15.1, 15.2, 15.3, 15.4, allows an authorized attacker to embed malicious code into HTTP parameter and send it to the server because SAP Manufacturing Execution (System Rules) tab does not sufficiently encode some parameters, resulting in Stored ...
CVE-2021-27601
PUBLISHED: 2021-04-13
SAP NetWeaver AS Java (Applications based on HTMLB for Java) allows a basic-level authorized attacker to store a malicious file on the server. When a victim tries to open this file, it results in a Cross-Site Scripting (XSS) vulnerability and the attacker can read and modify data. However, the attac...
CVE-2021-27602
PUBLISHED: 2021-04-13
SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are translated to drools rule when published to certain modules within the application. An attacker with this authorization can inject malicious code in the sour...