Worm spoofs Google

by Steve Kerrison on 20 September 2005, 00:00

Quick Link: HEXUS.net/qabsx

Add to My Vault: x

Please log in to view Printer Friendly Layout

A new worm is on the loose that could confuse a lot of net users by spoofing the popular search engine, Google.

The P2Load.A worm redirects users to a fake Google website on an infected machine, delivering hacker-controlled search results to direct a user wherever the hacker pleases.

The worm works its 'magic' by modifying the 'hosts' file on a Windows PC. When a domain name is typed into a web browser, the hosts file is the first place the system will look in an attempt to resolve the domain name to an IP address. www.google.com and various other similar domain names have incorrect entries in the modified hosts file, directing the browser to a spoof of the Google site rather than the real thing.

There are fears that this spoof Google could be used as a new way to lure people into phishing scams.

P2Load.A has been spreading via P2P networks. There are reports that in addition to the Google spoof, the worm will change the default startup page of Firefox and Internet Explorer to that of a shopping site. Keep your virus scanner up to date, and take care if you're using any P2P software.



HEXUS Forums :: 6 Comments

Login with Forum Account

Don't have an account? Register today!
a good protection for this is to enable the read only config of HOSTS from spybot search & destroy.
Indeed. However, if you get to a machine that's already spywared up, you have to fix the hosts file before you can actually get to the spybot download page XD.
thats what USB keys with all the kit you need on it are for Steve :P
Nah I wonder around with a CD in my pocket aptly labelled “ZOMG Toolz!!11”… it's true.
lol “Steve's 1337 hax0r tooz!!” :)