Thursday, March 12, 2009

Enticing to download fake antivirus through popular celebrity video !

Recently, few of sites registered in blogspot detected as malicious link to trick users to view popular celebrity sex movies by downloading their decoder. Malicious website will prompt a message dialog mentioned that users computer were infected by viruses, and fake antivirus 'InstallAVg_881050.exe' will be downloaded and installed in user computer. Rouge antivirus rename by using AVG antivirus vendor name to foolish users and believe its from true website.

Below is the bad links that hosted in blogspot.

  • h xxp://lisa-bonet-angel-heart.blogspot.com
  • h xxp://milla-jovovich-gallery.blogspot.com
  • h xxp://pamela-anderson-hot-sex-tape.blogspot.com
  • h xxp://rihanna-nude-gallery.blogspot.com
  • h xxp://kate-hudson-nude-gallery.blogspot.com
  • h xxp://teacher-slept-with-boy.blogspot.com
  • h xxp://meg-white-new-sex-tape.blogspot.com
  • h xxp://anna-faris-hot-video.blogspot.com
  • h xxp://so-hard-movies.blogspot.com
  • h xxp://vanessa-hot.blogspot.com
  • h xxp://paris-hilton-sexass.blogspot.com
  • h xxp://sex-tape-lindsay-lohan.blogspot.com
  • h xxp://chloesevigny-privategallery.blogspot.com
  • h xxp://kate-winslet-nude-gallery.blogspot.com
  • h xxp://keeley-hazell-sex-hot-video.blogspot.com
  • h xxp://miley-cyrus-sex-tape.blogspot.com
  • h xxp://britney-spears-ho xxest-video.blogspot.com
  • h xxp://miley-cyrus-naked-video.blogspot.com
  • h xxp://alyssa-milano-naked-video.blogspot.com
  • h xxp://kardashian-hot-video.blogspot.com
  • h xxp://naked-jennifer-lopez.blogspot.com
  • h xxp://vanessa-hudgens-hot-video.blogspot.com
  • h xxp://ho xxest-lindsay-lohan-video.blogspot.com
  • h xxp://cameron-diaz-porn.blogspot.com
  • h xxp://underworld-rise-lycans.blogspot.com


Figure 1: Trick users to download the encoder to view the video



Figure 2: Trick users that computer were infected by viruses


Figure 3: Scanning in process using fake images



Figure 4: Viruses were detected and fake antivirus has been download automatically



Figure 5: md5 for the fake executable exe file

3 comments:

SyaFia said...

i take it to my blog...


with back link :P

webevil said...

Sure

montlytailor said...

This Antivirus rename by application AVG antivirus bell-ringer name to absurd users and accept its from accurate website.

Norton 360 for small business