Philippines Floods batters Search Engine with Fake AV

The Fake AV Gang is now taking advantage of the recent disasters in the Philippines. The Philippines has been hit with Typhoon Ketsana (Ondoy) followed by the Typhoon Parma (Pepeng), which has brought serious flooding in the Philippines. Searching for the key words “philippines-flood-2009� on Google and Yahoo Search Engine gives the following results:

googleyahoo

Clicking the link will redirect the user to a fake alert message, just like one of the following:

google1

google11

yahoo1

Users will not be able to close these messages, clicking the OK, Cancel or “X� Button will still go to a fake malware scanning page that will eventually report fake infections, and downloads the binary files as shown below:

googleyahoo2

We detect the files downloaded from the aforementioned malicious links as W32/FakeAV.NJ and W32/FakeAV.NK.  The downloaded files will install Rouge Anti-Malware Products.

As a reminder, don’t run files downloaded from untrusted source.

One Response to “Philippines Floods batters Search Engine with Fake AV”

  1. Steve Fox says:

    Google should focus on these types of sites more to find them and de-index them. They are blatantly setup in false pretense.

Leave a Reply