Send Anonymous Email | Stealth Internet Rotating Header Image

November 21st, 2008:

Antivirus 2009

A new computer threat has been circulating all over the Internet: the Antivirus 2009. Posed as a “legitimate” antivirus software, the Antivirus 2009 is a rogue anti-spyware program that installs a Trojan into the computer system.

Introducing Antivirus 2009

The Antivirus 2009 introduces itself by using Trojans that are disguised as video codecs. These Trojans, which are usually found in warez and porn sites, floods the computer with fake system notifications and pop-ups to inform the user that his or her computer system is infected with viruses. This disinformation is used as a strategy to trick the user into downloading the “licensed version” Antivirus 2009: the alleged “latest antivirus and spyware program” found on the Internet.

Downloading Antivirus 2009

There are two ways to install the Antivirus 2009 into your system. In the first one, the user will be tricked into clicking any of the pop-ups that appear on the screen. Upon clicking, he or she will be redirected to a website that sells the malware. This website, aside from being fraudulent, is also malicious. Besides uploading Antivirus 2009, it may also install other malwares into your computer system. The fraudulent and malicious website to which the user will be redirected can be any of the following:

* http://www.antivirus-premium-scan.com
* http://www.webscannertools.com
* http://www.googlescanners-360.com
* http://www.livesecurityinfo.com
* http://www.antivirusonlivescan.com
* http://www.bestantivirusscan.com
* http://www.antivirus-best.com
* http://www.internetquarantinesite.com
* http://www.premiumlivescan.com
* http://www.secureclick1.com

In the second method of downloading the Antivirus 2009, a fake WINDOWS notification appears on the screen to inform the user that his or her computer is infected. To “remedy” the infection, he or she needs to choose between two buttons: a YES button and a No button. Regardless of which button the user clicks, the free Antivirus 2009 download will start.

ILOVEYOU Virus: The One That Started It All

As far as email viruses go, the ILOVEYOU virus is probably the most popular. Dubbed as the “Love Bug,” the ILOVEYOU virus invaded the computer world by spreading “love virus” to a number of computer systems all over the world. Some people even thought that it was the aftershock of the Y2K bug that caused glitches in several computer systems at the beginning of the new millennium. Although it was proven to be independent from the Y2K bug, the ILOVEYOU virus caused a technological havoc that kept the entire virtual world on its toes.

Opening the ILOVEYOU attachment

The ILOVEYOU email contains an attachment that is labeled LOVE-LETTER-FOR-YOU.TXT.vbs. Upon the activation of the said attachment, the virus automatically forwards the ILOVEYOU email to everybody on your address list. What’s worse is that the forwarded emails will all bear your name as the sender.

Replacing the system files

The effects of the ILOVEYOU virus are not limited to the involuntary forwarding of virus emails to everybody on your address list. In fact, when you open the ILOVEYOU virus attachment, the virus will automatically search the hard drive of your computer and will replace all MP3, JPEG, JPG, and DOC files with copies of itself bearing the .VBS extension.

Downloading the Trojan Horse

Another harmful effect of opening the ILOVEYOU virus attachment is that the virus downloads a Trojan Horse called WIN-BUGSFIX.exe from a certain website hosted by Sky Internet, a Philippine Internet service provider. The downloaded Trojan Horse then invades your computer system by collecting all your usernames and passwords and sends them to mailme@super.net.ph, the email address of the notorious author of the ILOVEYOU virus.