While researching some information, I came across a Google hit that looked like what I was looking for, but when I opened the page, none of the text in the preview paragraph was there. Somebody must have fed bogus contents to GoogleBot to attract searches.
Instead of the expected information I found myself on a scareware site called defend6-pc.com that was then trying to coerce me into downloading and installing their fake security software. A pop-up dialog asked me whether I wanted to scan my computer with their software. It didn’t matter if I clicked OK or Cancel, a download would always start. Only by closing the browser Window could I get rid of their nasty popup dialogs.
I’m using Mozilla FireFox, which does not offer to run downloaded EXEs directly. I did not click on the downloaded “Vir7remover_2009_b2.exe”, instead I ran it through the VirusTotal.com online malware scanner (highly recommended!) and products by four companies diagnosed it as malicious or suspicious:
- Microsoft (1.5605) says it’s a “Trojan:Win32/FakeXPA”
- Sophos (4.52.0) says it’s “Mal/FakeAV-CX”
- VBA32 (3.12.12.4) says it’s “BScope.Trojan.MTA.0157”
- Panda (10.0.2.2) calls it a “”Suspicious file”
“Mal/FakeAV-CX” indicates “scareware“, software that pretends to be an anti-virus / malware scanner that scares you with bogus alerts of malware on your harddisk into installing and or purchasing the software. Such software can include Trojans (as you would suspect from “Trojan:Win32/FakeXPA” and “BScope.Trojan.MTA.0157”) that take over your machine and can give someone else full control over your machine for malicious activities.
The following domains are all hosted on the same server as defend6-pc.com (IP address 93.174.95.154) and this list probably is not complete. I definitely would not recommend installing any software from any of these sites:
- 10scanantispyware.com
- 20scanantispyware.com
- 2scanantispyware.com
- 30scanantispyware.com
- 3scanantispyware.com
- 50virus-scanner.com
- 5scanantispyware.com
- 60scanantispyware.com
- 7scanantispyware.com
- 80scanantispyware.com
- 8scanantispyware.com
- 90virus-scanner.com
- antispy-scan200.com
- antispy-scan400.com
- antispy-scan600.com
- antispy-scan700.com
- antispy-scan800.com
- antispywarehelp002.com
- antispywarehelp004.com
- antispywarehelp008.com
- antispywarehelp010.com
- antispywarehelp022.com
- antispywarehelpk0.com
- antispywarehelpk2.com
- antispywarehelpk4.com
- antispywarehelpk6.com
- antispywarehelpk8.com
- antivirus-inet01.com
- antivirus-inet31.com
- antivirus-inet41.com
- antivirus-inet51.com
- antivirus-scan200.com
- antivirus-scan400.com
- antivirus-scan600.com
- antivirus-scan700.com
- antivirus-scan900.com
- antivirus-test88.com
- antivirus10scanner.com
- antivirus900scanner.com
- av-scanner200.com
- av-scanner300.com
- av-scanner400.com
- av-scanner500.com
- av-scanner700.com
- defend-computer10.com
- defend-computer30.com
- defend-computer50.com
- defend-computer70.com
- defend-computer82.com
- defend-computer83.com
- defend-computer84.com
- defend-computer85.com
- defend-computer86.com
- defend-computer88.com
- defend-computer90.com
- defend-pc100.com
- defend-pc130.com
- defend-pc150.com
- defend-pc170.com
- defend2-pc.com
- defend5-pc.com
- defend6-pc.com
- inetproscan001.com
- inetproscan031.com
- inetproscan061.com
- inetproscan081.com
- inetproscan091.com
- insight-scan20.com
- insight-scan40.com
- insight-scan60.com
- insight-scan80.com
- insight-scan90.com
- insight-scanner2.com
- insight-scanner5.com
- insight-scanner7.com
- insight-scanner8.com
- insight-scanner9.com
- internet-scan020.com
- internet-scan040.com
- internet-scan050.com
- internet-scan070.com
- internet-scan090.com
- internet-scanner020.com
- internet-scanner030.com
- internet-scanner050.com
- internet-scanner070.com
- internet-scanner090.com
- net-02antivirus.com
- net-04antivirus.com
- net-05antivirus.com
- net-07antivirus.com
- net001antivirus.com
- net011antivirus.com
- net021antivirus.com
- net111antivirus.com
- net222antivirus.com
- novirus-scan00.com
- novirus-scan01.com
- novirus-scan22.com
- novirus-scan31.com
- novirus-scan33.com
- novirus-scan41.com
- novirus-scan55.com
- novirus-scan61.com
- novirus-scan81.com
- novirus-scan88.com
- spyware-stop01.com
- spyware-stopb1.com
- spyware-stopm1.com
- spyware-stopn1.com
- spyware-stopz1.com
- spyware200scan.com
- spyware500scan.com
- spyware800scan.com
- spyware880scan.com
- spywarescan010.com
- spywarescan013.com
- spywarescan015.com
- spywarescan017.com
- spywarescan018.com
- stop-all-virus1.com
- stop-all-virus3.com
- stop-all-virus6.com
- stop-all-virus9.com
- stop-virus-01a.com
- stop-virus-01b.com
- stop-virus-01d.com
- stop-virus-01e.com
- stop-virus-01f.com
- stop-virus-03b.com
- stop-virus-03u.com
- stop-virus-03y.com
- stop-virus-03z.com
- stop-virus-040.com
- stop-virus-070.com
- stop-virus-090.com
- stop-virus-091.com
- stop-virus-099.com
- stopvirus-scan11.com
- stopvirus-scan13.com
- stopvirus-scan16.com
- stopvirus-scan18.com
- stopvirus-scan33.com
- stopvirus-scan66.com
- stopvirus-scan88.com
- stopvirus-scan99.com
- virus77scanner.com
- virus88scanner.com