Saturday, February 18, 2006

How spyware gets installed

Search (using, for example, Google) for "midi file." One of the suggested destinations is

musicrobotTo make some money, musicrobot works with "advertising networks." Note, for example, the Google ads down the right side.

The banner at the top is a Macromedia Flash presentation from the advertising network FASTCLICK.COM.

When the musicrobot home page was opened, a pop-under ad window was also opened.

The pop-under ad is also a Macromedia Flash presentation from the advertising network FASTCLICK.COM.
(Note: Whenever you encounter an ad like this, always close the window using the "X" in the upper right-hand corner.)

FASTCLICK.COM provided to musicrobot the following HTML code to include on their web page:

[!-- FASTCLICK.COM POP-UNDER CODE v1.8 for (12 hour) --]
[script language="javascript"][!--
var dc=document; var date_ob=new Date();
dc.cookie='h2=o; path=/;';var bust=date_ob.getSeconds();
if(dc.cookie.indexOf('e=llo') [= 0 && dc.cookie.indexOf('2=o') ] 0){
dc.write('[scr'+'ipt language="javascript" src="');
dc.cookie='he=llo; path=/; expires='+ date_ob.toGMTString();} // --]

[body bgcolor="#FFFFFF" text="#000000" onload="document.forms[0].terms.focus()"]
[!-- FASTCLICK.COM 728x90 and 468x60 BANNER CODE for --]
[script language="javascript" src=""][/script]
[noscript][a href="" target="_blank"]
[img src=""
width=728 height=90 border=1][/a][/noscript]
[!-- FASTCLICK.COM 728x90 and 468x60 BANNER CODE for --]

All you need to recognize is that is running javascript that links you to

If you use musicrobot to search for "we will rock you", the among the results is a link to By itself, this web site is harmless.
The actual link from is of the form

That is, you are sent to first, where you are confronted with an offer from, the same source as the earlier pop-under ad. The ad is usually for smileys, ecards, cursors, screensavers or some other thing cute and not obviously malicious.

If you accept the offer, you are asked if you want to install this software. Carefully review what you are accepting. The terms will insist that the software does not gather any personally identifiable information. The terms will also say that the software gathers your IP address. You should know that the IP address is used to identify you and your habits. Carefully consider whether you consider this to be personal identification.


Post a Comment

<< Home