Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » Security Watch » Worm spoofs Google on infected PCs.

Security Watch - Worm spoofs Google on infected PCs. posted in the Security & Safety forums; Worm spoofs Google on infected PCs. Virus writers have developed a worm that spoofs the behaviour of internet search engine Google, varying the results displayed to suit the requirements of ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 09-20-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default Worm spoofs Google on infected PCs.



Worm spoofs Google on infected PCs.


Virus writers have developed a worm that spoofs the behaviour of internet search engine Google, varying the results displayed to suit the requirements of hackers.


P2Load-A modifies the HOSTS file on infected PCs by replacing the original with a file downloaded from a remote website under the control of hackers. When users run a search, the results are normally shown correctly - but sponsored links are different. For some searches, other links appear which have been specified by the creator of this malware, resulting in increased traffic to these websites.

Even users who mistype the www.google.com address are redirected to the fake site, which also supports the same range of languages as Google.com. This redirection is achieved by modifying the hosts file in the infected computer's operating system, which is a kind of address book used to quickly connect the browser to websites.

The worm spreads across file trading networks, targeting users of the Shareaza and Imesh P2P programs. P2Load-A copies itself to the shared directory of these programs as an executable file called Knights of the Old Republic 2, a reference to a well-known computer game related to the Star Wars saga. If this file is run, it displays an error message informing the user that a file does not exist and offering to download it. Meanwhile, unknown to its user, their Windows PC will have become infected.

Users infected with the worm will notice one other side effect: their browser's start page will be modified to display what appears to be a shopping site. P2Load.A affects Windows computers running Firefox or Internet Explorer.

From:
http://www.securityfocus.com/news/11322
and:
http://www.xatrix.org/article.php?s=4106



To restore a host file:

Download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original Hosts file.






__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 03:15 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top