The Call – Warning! Your system is in danger.

Once in awhile I like to show off some of the malware I find when visit my St. Louis clients. Tonight I thought I’d treat you to a creative little rogue antivirus! When Joyce (my new client) would try visit free.avg.com (or any website) she would be presented with this fake little message…”Warning! Your system is in danger“.

Joyce was infected with the ever present and ever changing ZLOB trojan. I don’t have too much to say about this rogue except that it hijacked every single website visit with the text seen below (which is sorta rare). When Joyce would click the message she would get (…see img B) an installer for Antivirus Pro 2009. Joyce didn’t install Antivirus 2009 because she had heard about such scams at work.

I cleaned Joyce’s machine with Malwarebytes and GMER in safemode. Later she opted to buy Norton Internet Security 2009. Joyce had an expired copy of Trend Micro 2008.

Img. A

Img B.



, , , , ,

  • Jon

    wooo, jeeze cant these malware writers take a break for like a week

  • f

    at least she doesnt have the rouge

    …yet

  • arsenalfooty4 (youtube)

    “Warning! Your system is in danger!”
    How original!

    P.S.
    There is a typo in the second to last sentence. You misspelled “buy”

  • arsenalfooty4 (youtube)

    “Warning! Your system is in danger!”
    How original! Never heard that one before… XD

    Also you misspelled “buy” in the second to last paragraph.
    Have fun killing malware!

  • Jimmy James

    I thought the whole point of website hijacking was to stop you downloading antimalware software… this is just mean

  • darkside1222

    Never heard of that! Intresting!

  • fsg

    It is clear that the malware attacks are getting more and more sophisticated today if it hijacks AVG’s site . At least she was aware about that rogue and do not install it and it’s a good thing that people are aware about this type of malware thanks to people like you and many others with good intentions.

  • http://youtube.com/AZLAN210396 AZLAN210396

    Is this Image taken at Joyce PC?

  • f

    suprised it even hijaks firefox


Remove-Malware Traffic Stats