The Inquirer-Home

Ad firms are offering HDD malware

HDD Plus drive-by downloads
Mon Dec 13 2010, 14:30

A COUPLE OF high profile advertising networks have been accused of letting a brand of malware slip through on their banner ads.

According to a blog post from Armorize, an application security firm, both Doubleclick and rad.msn.com - two of the biggest ad servers - were being used to shill drive-by malvertising to unsuspecting web users.

The adverts are offering HDD Plus, a predictably swineish piece of malware, said the security firm.

HDD Plus pretends to be the solution to your computer optimisation problems, but in reality is more likely to cause them. Once installed it insists on starting itself when the computer is booted up, makes a nuisance of itself and proves particularly difficult to boot off your machine.

Nice then that users are being exposed to it while wandering through what they thought were pretty friendly websites.

"Over the past few days, we saw the quick spread of HDD Plus--a malware that (somehow) gets installed on victim computers, and holds the computer hostage by displaying threatening message (that the system is failing), asking you to purchase a license so HDD Plus will fix the problems," the firm blogged.

"We've realized that one of the means for HDD Plus to spread, was via drive-by download malvertising through (at least) DoubleClick and rad.msn.com, which are both the world's largest ad serving platforms."

Armorize said that when a surfer visited an affected web site with banner ads from the two firms they are served a malicious javascript from ADShufffle.com. This, it added, then starts a drive-by download process and installs HDD Plus to the user's computer without even telling them.

In fact, the firm explained that it would be installed, "without having the need to trick the victim into doing anything or clicking on anything". Apparently, "Simply visiting the page infects the visitors."

Although Armorize named a number of websites through which the malware might be spreading, it also said that it had discussed the issue with a number of them. µ

 

Share this:

Comments
Infected link?

Guys

Read the article - clicked the link to the blog - AVG Security warning popped up. "Exloit JSE Web Start (type 1066)"

Won't be doing that again.

posted by : AC, 14 December 2010 Complain about this comment
The s#h#i#t hits the fan

Ghostery finds 10 malicious cookies on this web page and I don't know how many megabytes of malicious ads are being blocked by Adblock Plus. If Doubleclick is that bad (and I do not question that), then why does the Inq spread this Kot?

posted by : Till Eulenspiegel, 13 December 2010 Complain about this comment
Self-protection is free

Just Google for "hosts file updater" and download it (I use the Cnet download site). Run it every time you log on to your computer, or once a day if you log on and off more often. This will update your hosts file (from MVPS.org - a well-known and respected professionals' site) to block thousands of known malicious sites, as well as lots of advertisers like Doubleclick and rad.msn (which means faster Web browsing.

This works regardless of which browser you choose.

posted by : Morely the IT Guy, 13 December 2010 Complain about this comment
aboutus
Advertisement
Subscribe to INQ newsletters
Advertisement
INQ Poll

Facebook starts selling shares

Will you buy Facebook shares?