MacHouse video tutorials for Mac search engine optimization Spam database Web Hosting providers Web Hosting review web hosting providers MacHouse Help

June 20, 2008

Beware of GOOGLE-US.INFO - Leading Internet Users to a New Fake Anti-Virus Scan Website at VIRUS-SECURITYSCANNER.COM

Filed under: Internet security — Administrator @ 8:29 pm
Posted about 2 years and 2 months ago

anti spam






TOKYO (MacHouse) - A cyber scum organization has been circulating spam comments (See Screenshot 01.) for the past several hours to advertise a redirection website hosted in Malaysia. Accessing the redirection website hosted at the domain of google-us.info including its subdomain website at google-videos.google-us.info will lead Internet users to a brand-new fake anti-virus scan website at the domain of virus-securityscanner.com.





XPantivirus2008_v880421.exe google-us.info virus-securityscanner.com
Screenshot 01 - Source: MacHouse
  XPantivirus2008_v880421.exe google-us.info virus-securityscanner.com
Screenshot 02 - Source: google-us.info






If you access the domain of google-us.info (See Screenshot 02.), you will have 1/10 of a second or a little longer to prevent redirection. The final destination is a fake anti-virus scan website (XP Antivirus Protection) hosted at the domain of virus-securityscanner.com with an affiliate ID of 880421. (See Screenshot 03.) As usual, if you don’t close the web browser window until a fake scan animation ends, you will be forced to download a file titled ‘XPantivirus2008_v880421.exe,’ which presumably contains a Trojan virus derivative. (See Screenshot 04.)





XPantivirus2008_v880421.exe google-us.info virus-securityscanner.com
Screenshot 03 - Source: virus-securityscanner.com
  XPantivirus2008_v880421.exe google-us.info virus-securityscanner.com
Screenshot 04 - Source: virus-securityscanner.com
  XPantivirus2008_v880421.exe google-us.info virus-securityscanner.com
Screenshot 05 - Source: Whois.Net






As we noted earlier, this fake anti-virus scan website is brand-new. Screenshot 05 shows the domain registration of virus-securityscanner.com. The domain in question took effect just yesterday.

Furthermore, the IP location of the website at virus-securityscanner.com is 208.88.53.180. So the new fake anti-virus scan website appears to be hosted by a mysterious web hosting company called Said, Inc. They are based in Perkasie, Pennsylvania. Its website is supposed to be located at the domain of saidcom.com. But the website is currently not accessible.

By the way, The IP location of the redirection website hosted at google-us.info is possibly hosted by another mysterious web hosting company called Piradius.net. They seem to be based in Kuala Lumpur, Malaysia.






Click on the button to watch a documentation video. VTC
Click on the button to watch more documentation videos. VTC





********** ********** ********** ********** ********** ********** ********** **********

MacHouse is not funded by tax payers' money. We have limited resources. We also need time to sleep and eat just as others. So we will not act as the International police to contact all victims of website abuse. All you have to do is to subscribe to spam messages and spam posts. If we can, why don't you?







Leave a Reply


You are prohibited from posting comments merely to advertise your website. Please read Rules and About This Blog at the top menu bar for more information.

Because of spam-comment criminals, we are forced to manually moderate every comment that you may post. Your comment will appear only after we review and then approve it. It will take us several hours at most to review it.

Please note that all one-sentence comments will be automatically rejected as an anti-spam measure.

Subscribe without commenting