04
Sep
08

Antivirus 2009…brought to you by Motigo

A colleague called me today stating that his website was the victim of a hack and he did not know what to do. He was frantic and said that his website was distributing Antivirus 2009, so I decided to take a look at it and lo and behold, we found Antivirus 2009 being distributed from Motigo’s ad system.

For those who don’t know what Antivirus 2009 is, it’s a rogue (fake) security product. You can see a video of it in action here.

*Update* We have noticed our keyword search hit for “quickupdates” has increased 70% of our total keyword hit statistics over the past 24 hours. If you are viewing our site as a result of experiencing this pop-up, please leave us a comment and be sure to include what site you were on at the time.

We traced the AV09 pop-up down to the following JavaScript counter code.

The ID has been removed to protect the victims identity

< !– Begin Motigo Webstats counter code — > < a id=”*” href=”hxxp://webstats.motigo.com/”> < img src=”hxxp://m1.webstats.motigo.com/n.gif?id=*” border=”0″ alt=”Free counter and web stats” width=”18″ height=”18″ /> < script src=”hxxp://m1.webstats.motigo.com/c.js?id=*” type=”text/javascript”> < !– End Motigo Webstats counter code — >

Resulted in this pop-up being displayed on his site:

Antivirus 2009 via Motigo

Clicking the pop-up brought us to:

hxxp://quickupdates29.com <–don’t go here

Antivirus 2009 via Motigo

File distributed:

File: AV2009Install_*.exe (0570484B66E9A139D8FD0A71F5448957)
MDB: /lithium-malware/AV2009Install.zip

The motigo webstat counter code is responsible for several pop-up’s and one of them is Antivirus 2009. This is a scary thought. This means that everyone hosting this code on their website can potentially infected their viewers/customers. This is an extremely cost effective distribution method for the malware creators and I bet we will see more like it as time goes by.

Important note to website owners!

If you are going to use any service (free or paid), you’d better make sure you understand all of the terms and conditions. It’s not unusual for free services to be accompanied by ad’s or pop-ups but you must ask yourself the following questions before putting anything on your site.

1. What is the service providers privacy policy?

2. What are their terms of service?

3. How do they screen their affiliate links for malware/phishing attacks?

Finally, it’s important to see what their users think of the service. As we can see, Motigo has a laundry list of pop-up complaints:

Related News: PandaLabs reports on the sudden increase of rogue (fake) security products. -> Report

Removal:

Remove this threat with MalwareBytes!


9 Responses to “Antivirus 2009…brought to you by Motigo”


  1. 1 a Sep 4th, 2008 at 4:49 pm

    I just got this virus on my computer– it didin’t visit any ’sketchy websites,’ but I’ll bet someone accidently put it on. I am running norton ultities and had recently updated virus profiles. Any ideas/links on how to get rid of this?
    thanks so so much

  2. 2 Richard Sep 4th, 2008 at 8:45 pm

    I know exactly where I got this damn virus……it was from the New York Post website. I went to their site for maybe 1 minute and immediately was barraged by that damn “quickupdates29.com” trying to load Antivirus 2009. I’ve tried AdAware Plus and Spybot and nothing is getting rid of this pop-up. I too am in desperate need of help to get rid of this pop-up. Any assistance would be gratefully appreciated.

    Thanks,
    Richard

  3. 3 Johan Sep 5th, 2008 at 3:19 am

    I also have it. The site hxxp://quickupdates29.com/2009/1/_freescan.php?aid=77052104 cam up and started some fake virus scan. Avg did not seem to be able to get rid of it. Any ideas? Thanks

  4. 4 Berta Sep 5th, 2008 at 10:59 am

    I don’t exactly remember the site I visited but I saw Antivirus 2009 trying to install. Tried to close,abort, no way! My system was infected by a trojan. I tried a couple of anti virus, spyware malware gave up and reinstalled xp on another drive. It redirects my web search to an advertisement page and couldn’t do any surfing, kind of Zombie? The trojan and key logger was traced by an anti virus malware spyware but was unable to remove it. It is also password protected.

  5. 5 Mats Sep 6th, 2008 at 5:51 am

    I’m trying to install this on my VMware Workstation.. but can’t install it!! :D

    You can try using Malwarebytes Anti-Malware to remove it…
    http://remove.malwaredatabase.net

    Mats

  6. 6 rich Sep 10th, 2008 at 7:20 am

    got through google chrome downloaded 3 copies of course i did not open that would be stupid deleted end of story

  1. 1 AntiMalware 2009 - 1 domain added - 1 file added (24/36) | Malware Database Pingback on Oct 19th, 2008 at 6:13 am
  2. 2 LOLCats hacked Pingback on Nov 1st, 2008 at 9:13 am
  3. 3 Antispyware 2008 Rogue Served Through Download.com Ads | Malware Database Pingback on Nov 6th, 2008 at 4:17 am

Leave a Reply

You must login to post a comment.






 

September 2008
M T W T F S S
« Aug   Oct »
1234567
891011121314
15161718192021
22232425262728
2930