DriveCleaner and my missing BitTorrent Client
Last night (30th August 2007) one of our researchers received a nice surprise when attempting to download the latest version of BitTorrent from the official website, www.Bittorrent.com. After entering the site, clicking on the link in the top right corner “Get BitTorrent”, instead of the BitTorrent download page a nice pop-up message appeared on screen informing him of Adult content on his PC.
The message was easily recognisable as a pop up from one of the many rogue malware products out there. On this occasion the offender was Drive Cleaner 2006. The pop up appears to be the result of a banner referral on the download page. Following the TCP steam, we were able to see the following referrer string, sending traffic to www.drivecleaner.com. DriveCleaner and my missing BitTorrent Client
