Festive search words are a favorite with scammers as a lure to their offerings, as my colleague David Marcus recently warned us about Halloween-themed threats.

In recent research, we have found that search results for “scary halloween pumpkin designs” could lead users to a hijacked web page that hosts rogue security products.

Results for Halloween related keywords

Redirected page that has the link to malware

Upon clicking the hyperlink, the user sees a website hosted on xxx.allxxxxxshxxx.com. The site presents a fake “Windows Security Alert” window that is identical to the scam reported by McAfee Labs’ Avelino Rico Jr. in his recent blog. The “alert” warns visitors of fake infections and requires the victims to download a tool to remove them.

FakeAlert window

What happens after installing this tool is the same as many other rogue AV or FakeAlert stories we’ve reported. This malware is now detected as FakeAlert-JW Trojan.

Watch out for this and other malware during Halloween season, and keep your security products updated.