Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.![]() ![]() |
Jun 29 2008, 01:56 PM
Post
#1
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 31,601 Joined: 24-January 04 From: USA Member No.: 3 |
A new Rogue anti-spyware program called Antivirus 2009 was released this weekend that for the most part, acts just like all the rest. It displays false results, it is advertised through misleading web sites, comes bundled with malware, displays fake results, and requires you to first purchase the software before you can remove anything. What makes this rogue a bit different, though, is how it hijacks the Google homepage and search results by inserting an advertisement for Antivirus 2009. Now, this is not the first time this is happened, but it is uncommon enough that it warrants discussing. When Antivirus 2009 is installed, it will install a Internet Explorer browser helper object called C:\Windows\System32\winsrc.dll. This program will automatically load when Internet Explorer starts, and when you visit certain sites, it will insert its own information into the web pages that are retrieved. Currently the information that is inserted into the Google home page and search results is a misleading advertisement for Antivirus 2009. The current text of the advertisement is: Google TipsThe advertisement is actually one big link that if clicked will bring you to a page at the hxxp://microsoft.browserprotectioncenter.com/ site that says you are infected and should purchase Antivirus 2009. The tactic being used by this Rogue is to trick the infected user into thinking a well known and highly trusted brand, like Google, is actually endorsing their products. In reality, though, this is just another scam being used to steal your money. If you are infected with Antivirus 2009, you should use the following guide to remove the malware for free. If you have already paid for the software, please contact your credit card company immediately and dispute the charges. -------------------- |
|
|
|
Jul 9 2008, 10:12 AM
Post
#2
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 9-July 08 Member No.: 221,398 |
I discovered this injection on one of our clients this morning and, with your help, was able to completely remove Antivirus 2009.
Great article and instructions |
|
|
|
Jul 18 2008, 05:46 AM
Post
#3
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 18-July 08 From: eastbourne Member No.: 223,519 |
Hi I just joined to say thankyou soo much for the guide to remove antivirus 2009. It was very easy to follow and it worked. :-) It was driving me mad and blocking nearly every site i went onto :-( Cant thankyou enuf xx
|
|
|
|
Jul 29 2008, 03:43 PM
Post
#4
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 29-July 08 Member No.: 226,122 |
Just wanted to say thanks to Grinler, Eaglehawk2 and anyone else that may have contributed to resolving this very annoying issue. It showed up on my CEO's laptop today and this information really saved the day!
Thanks again, otteradmin |
|
|
|
Aug 1 2008, 07:56 AM
Post
#5
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 27-May 08 Member No.: 212,079 |
Wow, thanks a lot for the assistance, it was fantastic. I was perplexed as i thought my system might need complete formatting.
Good job.. Great doing guys.. --Prando |
|
|
|
Aug 4 2008, 08:58 AM
Post
#6
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 4-August 08 Member No.: 227,476 |
You guys are awesome! Zapped that Power Antivirus 2009 quickly & easily. Thanks so much!
|
|
|
|
Aug 5 2008, 03:48 PM
Post
#7
|
|
![]() Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,916 Joined: 13-June 08 Member No.: 215,975 |
Cheers for the info.
|
|
|
|
Aug 13 2008, 12:37 PM
Post
#8
|
|
|
New Member ![]() Group: Members Posts: 3 Joined: 29-July 08 Member No.: 226,126 |
thx for info.........
-------------------- |
|
|
|
Aug 13 2008, 06:50 PM
Post
#9
|
|
|
New Member ![]() Group: Members Posts: 9 Joined: 12-March 06 Member No.: 58,918 |
Excellent explanation-I have many friends who have gotten the antivirus 2008. I would like to send them your explanation and give you credit for it, if its okay.
|
|
|
|
Aug 13 2008, 06:52 PM
Post
#10
|
|
|
New Member ![]() Group: Members Posts: 9 Joined: 12-March 06 Member No.: 58,918 |
Also would you recommend people change their homepage from goggle?
|
|
|
|
Aug 15 2008, 02:16 PM
Post
#11
|
|
![]() Forum Regular ![]() ![]() ![]() Group: Members Posts: 340 Joined: 15-April 08 From: Donnie Darko Land Member No.: 203,315 |
Also would you recommend people change their homepage from goggle? You mean google. Goggle was an extremely dangerous site to visit. I think it may have been abandoned, but it contained may viruses, including downloading the rogue SpySheriff. I takes/took advantage of the very typo you've made. Edit: I confirm the site is abandoned, but it could be used for criminal behaviour in the future, so don't go there. This post has been edited by KingOfIdiocy: Aug 15 2008, 06:04 PM -------------------- Just because you're paranoid, doesn't mean they are not out to get you.
|
|
|
|
Aug 26 2008, 08:04 AM
Post
#12
|
|
|
New Member ![]() Group: Members Posts: 8 Joined: 21-February 08 Member No.: 191,579 |
rogue antiviruses are so morally corrupt! Well there are worse things in the world... but these people need to get a life!
|
|
|
|
Aug 30 2008, 08:37 PM
Post
#13
|
|
|
New Member ![]() Group: Members Posts: 2 Joined: 30-August 08 From: Bangalore, India Member No.: 234,710 |
Kick A$$..
-------------------- Thanks and Regards,
Eddie |
|
|
|
Oct 31 2008, 10:11 AM
Post
#14
|
|
![]() Forum Addict ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 1,916 Joined: 13-June 08 Member No.: 215,975 |
What do you type in google for this to come up?
So i can avoid it. This post has been edited by samuel3: Oct 31 2008, 10:13 AM |
|
|
|
Nov 14 2008, 05:54 AM
Post
#15
|
|
|
New Member ![]() Group: Members Posts: 4 Joined: 20-October 08 Member No.: 248,206 |
Thanks for the info... cheers !!
-------------------- |
|
|
|
Nov 19 2008, 10:58 AM
Post
#16
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 19-November 08 Member No.: 258,380 |
I only joined this forum to thank you for your help.
I have sucessfully deleted the antivirus2009 , thanks to you. ![]() Gur a maith agat Grinler. This post has been edited by taytomyname: Nov 19 2008, 11:00 AM |
|
|
|
Nov 29 2008, 12:21 AM
Post
#17
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 28-November 08 Member No.: 262,127 |
|
|
|
|
Dec 1 2008, 01:42 PM
Post
#18
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 1-December 08 Member No.: 263,580 |
I just got this rogue. trojan yesterday. I tried to come here but it blocked my access to this site. I was however able to get to download.com and get Stopzilla and malwarebytes.
It wouldnt let me run malwarebytes, so I ran stopzilla and it seemed to work right away. After running stopzilla I was able to run malwarebytes. This is a tough one, because it blocks most sites with any information on how to get rid of the virus. I got lucky by reading enough in an off topic forum to get rid of it. I contacted trendmicro and the engineer told me this week there has been a huge number of these types of infections. May be a good idea to print out fix instructions and stick it in a drawer somewhere just to have. I have only one computer so it was pretty frustrating hunting down links while being redirected from every "proven" forum. Just thought I would share with you all. Good luck! edited to say: I was on a site about movie clips, something about the hbo series true blood as I remember it. The box came up saying i had a virus, and I have seen plenty of these things and have always hit X and they go away. I hit X and it launched. The Trend Micro guy told me clicking any part of the box will launch it. So for now I would just close my browser if I see anything similar to this. This post has been edited by JCtitan: Dec 1 2008, 01:46 PM |
|
|
|
Dec 24 2008, 03:08 AM
Post
#19
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 24-December 08 Member No.: 273,472 |
hi
here is a different take on it if you google search "pg equine rescue" and click on the link you get the antivirus 2009 site. i have tried it on a few different computers and same thing but i can go there direct from through other sites. i ran malware programs and it was not the computers infected it is google it's self that seems to be infected. i only figured it out when the owners of the computers told me they just used googles auto complete searches to get to the site. i tried a google search on a clean computer and bingo. i suppose they are using googles spiders to clone sites great site keep up the great work |
|
|
|
Dec 26 2008, 01:11 AM
Post
#20
|
|
|
New Member ![]() Group: Members Posts: 11 Joined: 16-December 08 From: Virginia Member No.: 270,122 |
hi Thanks to this forum, on Christmas Eve my brother helped me vanquish the trojans from that rogue antivirus 2009/2008/360 et al. I think Goggle has a problem, or it seems to have a problem. So Malware Bytes has been installed on my PC. It took care of the problem completely. I agree, Goggle is the problem. Every other site with Goggle ads seem to have problems of some kind. here is a different take on it if you google search "pg equine rescue" and click on the link you get the antivirus 2009 site. i have tried it on a few different computers and same thing but i can go there direct from through other sites. i ran malware programs and it was not the computers infected it is google it's self that seems to be infected. i only figured it out when the owners of the computers told me they just used googles auto complete searches to get to the site. i tried a google search on a clean computer and bingo. i suppose they are using googles spiders to clone sites great site keep up the great work -------------------- TANSTAAFL
|
|
|
|
Jan 7 2009, 08:39 AM
Post
#21
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 7-January 09 Member No.: 279,449 |
Great article Grinler! One question, how is this contracted and how can I educate an end user on how to avoid contracting this?
Many thanks, CMS |
|
|
|
Jan 7 2009, 09:56 AM
Post
#22
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 31,601 Joined: 24-January 04 From: USA Member No.: 3 |
This infection has so many attack vectors that there is no one way they may have gotten it.
Here are some of the attack vectors:
-------------------- |
|
|
|
Jan 9 2009, 10:56 AM
Post
#23
|
|
![]() Distinguished Member ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 627 Joined: 15-November 07 From: North Carlona Member No.: 169,959 |
Well, thats something you need to keep a clsoe eye on. I've never checked (For obvious reasons) but I hear goggle is a huge infecting site. Thats something you have to keep an eye on.
|
|
|
|
Jan 11 2009, 08:49 PM
Post
#24
|
|
|
New Member ![]() Group: Members Posts: 2 Joined: 5-January 09 Member No.: 278,616 |
you have to be careful getting music off limewire alot of the songs are infected with this virus.
|
|
|
|
Jan 14 2009, 05:31 PM
Post
#25
|
|
|
New Member ![]() Group: Members Posts: 1 Joined: 14-January 09 Member No.: 282,697 |
Thank you for your help.
I have run the malware program and removed the rouge file. I do not beleive Antivirus was installed but the google page still displays the Antivirus 2009 link. What is the best way to remove this? Thank you again, |
|
|
|
Jan 18 2009, 10:50 PM
Post
#26
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 21,869 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
Hi jdamit As this is not the malware removal section you need to open a Topic in the Am I Infected forum in the Security section. You will get help there.
This post has been edited by boopme: Jan 18 2009, 10:51 PM -------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... Become a BleepingComputer fan: Facebook |
|
|
|
Jan 22 2009, 01:45 AM
Post
#27
|
|
|
New Member ![]() Group: Members Posts: 2 Joined: 21-January 09 Member No.: 285,643 |
This solution did not work for me. Scans, removes, restarts, and everything is the same. Also "install this program and then use it" seems like an odd guide to removing a specific malware.
|
|
|
|
Jan 22 2009, 06:48 AM
Post
#28
|
|
|
New Member ![]() Group: Members Posts: 2 Joined: 22-January 09 Member No.: 285,766 |
Hi there,
I am a little confused. I appear to - about every other search on google - get shown websites that clearly do not match the search results, often with supposed antivirus websites instead of news.bbc.co.uk which it should say, for example. This seems to be my only symptom and when I go to the google homepage there is no big 'google tips' notification and I have not noticed any other things different with my pc apart from this occasional google search issue. Reading a few reports about this antivirus thing, including your own which most others seem to reference, I'm not entirely sure whether the problem must be with my computer or with google itself. I have the latest mcaffee software. Should I be concerned? Thanks for any help you could offer. |
|
|
|
Jan 22 2009, 10:14 AM
Post
#29
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 21,869 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
Hello wanny,please refer to post #26
EDIT: roaky you should also post there. This post has been edited by boopme: Jan 22 2009, 10:16 AM -------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... Become a BleepingComputer fan: Facebook |
|
|
|
Jan 22 2009, 05:25 PM
Post
#30
|
|
|
New Member ![]() Group: Members Posts: 3 Joined: 20-January 09 Member No.: 285,259 |
This solution did not work for me. Scans, removes, restarts, and everything is the same. Also "install this program and then use it" seems like an odd guide to removing a specific malware. I followed the instruction 2 days ago, and did not work. Did the virus change ? |
|
|
|
Jan 22 2009, 05:27 PM
Post
#31
|
|
|
New Member ![]() Group: Members Posts: 3 Joined: 20-January 09 Member No.: 285,259 |
This solution did not work for me. Scans, removes, restarts, and everything is the same. Also "install this program and then use it" seems like an odd guide to removing a specific malware. I followed the instruction 2 days ago, and did not work. Did the virus change ? Please help how to remove this. Is only Internet Explorer that is affected? Does anybody know that if I remove my IE, will it solve the problem? |
|
|
|
Jan 22 2009, 07:30 PM
Post
#32
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 21,869 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
janie1635 please start atopic in the AM I Infected forum so we can help you with this,.
http://www.bleepingcomputer.com/forums/forum103.html -------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... Become a BleepingComputer fan: Facebook |
|
|
|
Jan 22 2009, 11:08 PM
Post
#33
|
|
|
New Member ![]() Group: Members Posts: 2 Joined: 21-January 09 Member No.: 285,643 |
I intend to make a topic, but I think honest feedback as to the results of this method of removal is pertinant. Negative and posative results are constructive I think.
|
|
|
|
Jan 22 2009, 11:25 PM
Post
#34
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 21,869 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
Also "install this program and then use it" seems like an odd guide to removing a specific malware. I at a loss of what you mean. Would you prefer we just threw any tool at you ,say CWshredder and say run that? The tool is directed at that malware and the scan log usually produces clues as to what needs to be done next, if needed. I have seen that tool remove it a 1000 times in this forum alone. Usually the times it doesn't work is because of the presence of other malwares. -------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... Become a BleepingComputer fan: Facebook |
|
|
|
Jan 30 2009, 09:30 AM
Post
#35
|
|
![]() Forum Regular ![]() ![]() ![]() Group: Members Posts: 194 Joined: 16-September 08 From: UK Member No.: 239,295 |
That's a bummer. Good thing for about 30 bucks I have AVG. Just renewed my license for it. No problems with that.
-------------------- ![]() |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 22nd November 2009 - 02:29 AM |