Subscribe: Subscribe to Malware Help. Org Full Post Feed Subscribe to Malware Help. Org Summary Feed

Custom Search
Search more than 150 trusted Websites for related information.

Fake security software distributor mimics Google attack site warning

April 14, 2009 by Shanmuga  
Filed under Featured, Rogue Security Software

I usually don’t check my site statistics log everyday, every week or even every month, I usually have a occasional glance to get a general idea about the browsers being used to access this site and from where the visitors are coming if I sense a spike in website traffic. Last night I was bored enough to browse the stats, when I found number of visitors referred from a curious looking URL: h**p://securityhelpcenter.com/block.php?id=2003-2&url=http://malwarehelp.org/anti_spyware_download.html.

May be a script to log the outgoing links?

Loading the link in the web browser threw up a Google warning that you see in Firefox when visiting links that Google determined as attack sites….or is it? On closer inspection the differences between the original and the masquerader began to resolve clearly. The appearance is deceptively same as the original Google warning, similar in color, logo and placement of the buttons. Though the text is different, it’s similar in tone. The link is actually an attempt to de-fraud people into buying a fake security software.

Fake Google Warning

Fake Google Warning

Original Google Warning

Original Google Warning

Clicking on the “Continue Unprotected” button in the fake google warning page loads the anti-spyware software download page on this website, While clicking on the “Get security software” button loads the URL h**p://securityhelpcenter.com/1/?id=2003-2, a payment gateway page promoting a fake anti-virus software going by the name “Personal Antivirus“. The payment processor for this campaign is secure.securedpaymentsystem.com through internetsoftwarepayments.com

The block.php file is just a (open) redirect script which makes it possible to redirect to any valid webpage using a code similar to the following:

    h**p://securityhelpcenter.com/block.php?id=2003-2&url=ENTER YOUR URL HERE

The domain securityhelpcenter.com is registered to one Sunil A Mittal, No.13 1ST AVENUE, Adyar, India and hosted at IP 78.47.91.153 appears to be located in Berlin, Germany. The IP address seems to be a den full of questionable websites with many involved in the distribution of fake security and other unwanted software. Some of the domains associated with this IP are:

  • advancedproantivirusscanner.com
  • alaskatoursonline.cn
  • antimalwaresecurityscan.com
  • arangeyourdreams.cn
  • bestgossips.cn
  • bestworldmusic.cn
  • controlledsurfaces.cn
  • fastantimalwareproscanner.com
  • fastantimalwarescan.com

Domains directly associated with this scam

  • securityhelpcenter.com
  • internetsoftwarepayments.com
  • securedpaymentsystem.com

This is another case where the scammers use the visual recognition associated with brands like Google to channel victims from reputable sites to those that harbor fake security software for phishing.

Update (17 Apr 2009)

If you are infected with the “Personal Antivirus” rogue, the procedure below should help you to get rid of it.

The free versions of MalwareBytes’s Anti-Malware and SuperAntiSpyware should remove this rogue security software.

  1. If Internet Explorer is hijacked, use an alternate browser like Firefox or Chrome to download and Install either MalwareBytes’s Anti-Malware or SuperAntiSpyware from the links above.
  2. Also download CCleaner.
  3. Boot in to Windows Safe mode.
  4. Click to scan with your chosen software. Check mark all instances of the rogue security software and delete them.
  5. Turn System Restore off and on.
  6. Install, scan and clean the temporary files with CCleaner.

You should now be clean of this rogue.

If you still see symptoms associated with this rogue security software, please post your problem at one of the Recommended Online Forums for Malware Help.

  • StumbleUpon
  • Digg
  • del.icio.us
  • Facebook
  • MySpace
  • Google Bookmarks
  • Live
If you enjoyed this post, make sure you subscribe to my RSS feed!

Post to Twitter

Limited Period Offers

Save 10% on Kaspersky AntiVirus 2010 - Coupon Code: KAV10
10% off Spyware Doctor - Coupon Code: pctools10
Get McAfee Total Protection for only $49.99 after $30 off!
Save 25% on a 2 year subscription of avast! 5 Pro Antivirus
Save 50% on ZoneAlarm Internet Security Suite 2010 ...More Offers

You may also like to read

Comments

4 Responses to “Fake security software distributor mimics Google attack site warning”

  1. jeremy on April 16th, 2009 10:46 AM

    This thing is blocking everything – I have current norton protection but it doesnt help.
    any idea how to block this website ?
    tanks
    jeremy

  2. Ashok on April 16th, 2009 2:25 PM

    How to remove this.

  3. Wayne on April 17th, 2009 3:09 AM

    Need help removing this

  4. Shanmuga on April 17th, 2009 12:14 PM

    I have updated the post with generic removal procedure for the scareware. Hope this helps.

  5. Jon S. on April 19th, 2009 1:44 PM

    Yes. Thank the geniuses. These cleanup tips worked. The securityhelpcenter.com hack was the worst malware I ever encountered.

Everyone has an Opinion...why don't you share yours and oh, if you want a pic to show with your comment, go get a gravatar! or you can even subscribe to our comments feed.

    Note:
  • All fields except the comments field are optional.
  • Real names aren't required, but please give us something to call you. Conversations among several people called "Anonymous" get too confusing.
  • All comments are pre-moderated, and will not appear on this site until approved by the site owner.





Tags

More News, Articles from elsewhere