WARNING! Rogue WinRAR.exe Promoted using Google AdwordsBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
Internet security & monitoring for networks - Dld trial!   Get A Free iPod   Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
2009/12/24 0:00:00
2009/11/20 17:37:24
2009/11/20 17:37:24
2009/11/20 15:43:34
2009/11/20 15:43:34
Our Partners
Downloads
Adware - Spyware : WARNING! Rogue WinRAR.exe Promoted using Google Adwords
Posted by Max on 2009/1/20 14:01:08 (1090 reads)
Adware - Spyware

win.rar GmbH, official publisher of the WinRAR compression program and RARLAB products warns users of fraudulent Google AdWords: "We have been informed that someone has fraudulently placed Google AdWords in our name and is directing users to a faked page of download.com. This page offers a modified WinRAR installation file (winrar.exe) for downloading," says Öncül Kaya, Managing Director of win.rar GmbH in describing the case. "To remove the file that is actually infected with malware, the scammers offer to sell users an 'anti-spyware solution' through a further link."

After installing the modified WinRAR, a malware is executed which opens a pop-up every minute with the content "intervalhehehe". When the alarmed user resorts to searching for the text in Google, he finds forum entries which confirm the problem's existence. Through a manipulation of the local host file, the user is directed to a counterfeit page of the "Microsoft Security Center" which offers a free "scan". The free scan naturally reveals an attack by "intervalhehehe" and immediately offers an "anti-spyware solution" for € 39.95 from the fraudulent IT security firm.

The security company Websense has reported on the case in greater detail and with screenshots in their Security Labs Blog: http://securitylabs.websense.com/content/Blogs/3264.aspx

The counterfeit Download.com page with the WinRAR file infected with malware can be found at:
dreamcentury.cn/winrar.htm <-- WARNING ! THIS WEBSITE HOSTS THE INFECTED FILE

"The problem is that anyone can actually place Google Adwords for other companies which are generally not checked for accuracy or authenticity. As soon as a site is blocked, another one appears to take its place," Öncül Kaya comments.

About WinRAR

WinRAR is a 32-bit Windows version of the RAR Archiver, the powerful archiver and archive manager. RAR files can usually compress content up to 30 percent more effectively than ZIP files. WinRAR's most important functions include extremely powerful document and multimedia file compression, processing of other archive formats, long filename support, programmable self-extracting archives (SFK), damaged archive repair, authenticity verification, embedded file comments, and archive encryption. The command line version of RAR is available for Linux, DOS, OS/2, FreeBSD and MAC OS X. Pocket RAR, the free WinRAR version for Pocket PCs, WinRAR for U3, and the new WinRAR Unplugged complete the WinRAR product range.

About win.rar GmbH
win.rar GmbH, has been the official distributor of WinRAR and RARLAB products since February 2002 and handles all support, marketing, and sales related to WinRAR &rarlab.com. The company is registered in Germany and is represented worldwide by local partners in more than 70 countries on six continents. winRAR's declared objective is to provide first-class quality support and to optimize their software to meet the requirements and in accordance with the feedback of their customers. For more information about WinRAR and win.rar GmbH go to http://www.win-rar.com.




Other articles
2009/11/3 14:55:39 - BitDefender Top Ten Malware Threats for October 09
2009/11/3 14:29:38 - Nov. 09 Microsoft Security Intelligence Report
2009/10/7 15:19:17 - StopSign AntiVirus and Anti-Malware is Windows 7 Compatible
2009/10/7 15:11:26 - New Outlook Backup and Migration Software By Disk Doctors
2009/9/30 4:20:57 - Microsoft Security Essentials, FREE Security Tool Just Released
2009/9/28 14:31:52 - New Rogue Antispyware Cloaked To Infects Computers
2009/9/9 4:31:49 - Trend Micro Proves Leadership in URL Filtering and Web Security
2009/9/9 4:16:20 - New Free Tool to Clean Conficker Once and For All
2009/9/1 8:37:11 - Kaspersky Internet Security 2010 and Kaspersky Anti-Virus 2010 Out Now
2009/9/1 7:54:50 - NEW P2P Advertising Network Protects Users Against Lawsuits And Identity Theft

The comments are owned by the poster. We aren't responsible for their content.