SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

Bogus installs expose U.K. users to malware

Bogus installs expose U.K. users to malware

By:  John E Dunn  On: 15 Nov 2007 For: TechWorld.com (SS) 

Statistics from security firm Webroot suggest attackers are leaning on the idea of passing off or packaging malicious functions with what appear to be legitimate programs

Security-related tatistics from security vendor Webroot suggest malware distributors are increasingly using "passing off" techniques to get their programs on to the PCs of U.K.-based users.

The idea of passing off, packaging malicious functions with what appear to be legitimate programs, is nothing new. But Webroot's latest analysis of U.K.-based spyware, Trojans and system monitors, shows that users are now being hit with a range of sometimes self-inflicted woes as a matter of course.

The top three adware programs for October were the Comet Cursor, a browser plug-in that masquerades as a mouse pointer utility, but which also tracks IP addresses and cookies; CoolWebSearch, a Google browser redirection pest that claims to be a way to improve searching; Starware Toolbar, a pop-up blocker that displays its own ads. All would likely have been installed by users who did not understand what they were signing up for.

In the category of 'system monitors', the picture is much the same, with many of the top programs mentioned, 007 Spy, Nok-Nok, and Win-Spy Monitor, being programs that claim to have a legitimate purpose, that of monitoring keystrokes on a PC for the purposes of surveillance. These programs don't necessarily pass themselves off in an inaccurate way, but are open to abuse if installed on a PC without the owner's knowledge. Even the Trojans noted by Webroot, with Zlob and Trojan.Gen at the head of the list, will likely have found a home by packaging themselves with another apparently useful download.

The figures for October 2007 come from the company's Phileas bot, an automatic malware tracking system that spiders for web threats in real time, and which can relate these to specific geographical areas. The figures measure threats directed against users, rather than specific reports.

"The technology behind spyware has become so far advanced, and is moving so quickly, that manual detection methods utilised by many security companies and freeware providers can't keep up with it," said Webroot's CEO, Peter Watkins.

That said, the company's October statistics suggest that most of the malware that affects U.K. users is remarkably old, in some cases years old. The Comet Cursor and Starware have been in circulation since September 2006, while the CoolWebSearch dates back to February 2004, circumstantial evidence that users are sometimes installing malware themselves in a way that circumvents security software.


Sign up for our Newsletters












Print |  Views: 473   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




John E Dunn John E Dunn is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

One in 310 Canadian Windows PCs have malware
One in 310 Canadian Windows PCs have malwareMicrosoft breaks out Canada-specific data from its Security Intelligence report for the first time, revealing the top unwanted software categories. Guess what topped the list?
Top cyber-crook targets for 2008
Top cyber-crook targets for 2008A look at five online security predictions for 2008
Protecting your PC from three serious Internet risks
Protecting your PC from three serious Internet risksThe same Internet connection that lets you reach out and touch millions of Web servers, e-mail addresses, and other digital entities across the globe also endangers your PC and the information it contains about you. Here's how to stymie the three gravest Internet risks.
What I learned about business process optimization at Woodbine
it sounded like a great it industry name, but i just couldn’t put my money down on “redeploy,” one of horses competing at

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.