Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Antivirus 2009 Hijacks The Google Web Site


  • Please log in to reply
34 replies to this topic

#1 Grinler

Grinler

    Lawrence Abrams


  •  Avatar image
  • Admin
  • 44,969 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:09:11 PM

Posted 29 June 2008 - 01:56 PM

A new Rogue anti-spyware program called Antivirus 2009 was released this weekend that for the most part, acts just like all the rest. It displays false results, it is advertised through misleading web sites, comes bundled with malware, displays fake results, and requires you to first purchase the software before you can remove anything. What makes this rogue a bit different, though, is how it hijacks the Google homepage and search results by inserting an advertisement for Antivirus 2009.


Google Homepage Hijack

Now, this is not the first time this is happened, but it is uncommon enough that it warrants discussing. When Antivirus 2009 is installed, it will install a Internet Explorer browser helper object called C:\Windows\System32\winsrc.dll. This program will automatically load when Internet Explorer starts, and when you visit certain sites, it will insert its own information into the web pages that are retrieved. Currently the information that is inserted into the Google home page and search results is a misleading advertisement for Antivirus 2009. The current text of the advertisement is:
Google Tips

Google has detected unregistered Antivirus 2009 copy on your computer. Google recommends you to activate Antivirus 2009 to protect your PC from malicious intrusions from the Internet.
The advertisement is actually one big link that if clicked will bring you to a page at the hxxp://microsoft.browserprotectioncenter.com/ site that says you are infected and should purchase Antivirus 2009.


BrowserProtection.com Advertisement

The tactic being used by this Rogue is to trick the infected user into thinking a well known and highly trusted brand, like Google, is actually endorsing their products. In reality, though, this is just another scam being used to steal your money. If you are infected with Antivirus 2009, you should use the following guide to remove the malware for free. If you have already paid for the software, please contact your credit card company immediately and dispute the charges.



BC AdBot (Login to Remove)

 


#2 sandra08

sandra08

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:08:11 PM

Posted 09 July 2008 - 10:12 AM

I discovered this injection on one of our clients this morning and, with your help, was able to completely remove Antivirus 2009.
Great article and instructions :thumbsup:

#3 xbunnyx

xbunnyx

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:eastbourne
  • Local time:02:11 AM

Posted 18 July 2008 - 05:46 AM

Hi I just joined to say thankyou soo much for the guide to remove antivirus 2009. It was very easy to follow and it worked. :-) It was driving me mad and blocking nearly every site i went onto :-( Cant thankyou enuf xx

#4 otteradmin

otteradmin

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:09:11 PM

Posted 29 July 2008 - 03:43 PM

Just wanted to say thanks to Grinler, Eaglehawk2 and anyone else that may have contributed to resolving this very annoying issue. It showed up on my CEO's laptop today and this information really saved the day!

Thanks again,

otteradmin

#5 prando

prando

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:06:41 AM

Posted 01 August 2008 - 07:56 AM

Wow, thanks a lot for the assistance, it was fantastic. I was perplexed as i thought my system might need complete formatting.
Good job..
Great doing guys..


--Prando

#6 ecafy

ecafy

  •  Avatar image
  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:08:11 PM

Posted 04 August 2008 - 08:58 AM

You guys are awesome! Zapped that Power Antivirus 2009 quickly & easily. Thanks so much!

#7 samuel3

samuel3

  •  Avatar image
  • Members
  • 2,368 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:11 AM

Posted 05 August 2008 - 03:48 PM

Cheers for the info.

#8 colle1986

colle1986

  •  Avatar image
  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:08:11 PM

Posted 13 August 2008 - 12:37 PM

thx for info.........

#9 pouringreign

pouringreign

  •  Avatar image
  • Members
  • 231 posts
  • OFFLINE
  •  
  • Local time:09:11 PM

Posted 13 August 2008 - 06:50 PM

Excellent explanation-I have many friends who have gotten the antivirus 2008. I would like to send them your explanation and give you credit for it, if its okay.

#10 pouringreign

pouringreign

  •  Avatar image
  • Members
  • 231 posts
  • OFFLINE
  •  
  • Local time:09:11 PM

Posted 13 August 2008 - 06:52 PM

Also would you recommend people change their homepage from goggle?

#11 thelittleduck

thelittleduck

    Bleepin' Idiot


  •  Avatar image
  • Members
  • 1,009 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Pond
  • Local time:01:11 AM

Posted 15 August 2008 - 02:16 PM

Also would you recommend people change their homepage from goggle?



You mean google. Goggle was an extremely dangerous site to visit. I think it may have been abandoned, but it contained may viruses, including downloading the rogue SpySheriff. I takes/took advantage of the very typo you've made.

Edit: I confirm the site is abandoned, but it could be used for criminal behaviour in the future, so don't go there.

Edited by KingOfIdiocy, 15 August 2008 - 06:04 PM.


#12 Lukepd

Lukepd

  •  Avatar image
  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:11 AM

Posted 26 August 2008 - 08:04 AM

rogue antiviruses are so morally corrupt! Well there are worse things in the world... but these people need to get a life!

#13 Bloody Eddie

Bloody Eddie

  •  Avatar image
  • Members
  • 2 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bangalore, India
  • Local time:06:41 AM

Posted 30 August 2008 - 08:37 PM

Kick A$$.. :thumbsup:
Thanks and Regards,

Eddie

#14 samuel3

samuel3

  •  Avatar image
  • Members
  • 2,368 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:11 AM

Posted 31 October 2008 - 10:11 AM

What do you type in google for this to come up?

So i can avoid it.

Edited by samuel3, 31 October 2008 - 10:13 AM.


#15 jacks

jacks

  •  Avatar image
  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:08:11 PM

Posted 14 November 2008 - 05:54 AM

Thanks for the info... cheers !! :thumbsup:




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users