experts Malwarebytes Labs discovered the Extenbro Trojan, which not only replaces DNS to serve ads but also prevents the user from using anti-virus and other security products.
The user cannot download and install any protection program and get rid of the malware. Researchers warn that in this way the malware exposes infected devices to risks posed by other attacks, without any salvation for them.
Similar malicious behavior has already been observed by the Vonteera malware, which used system certificates to disable security solutions on systems.

Extenbro is distributed primarily through advertisements.
After installing the software, the user will find that unwanted ads appear that come from sites they have never visited. A new start page may appear in the browser. Finally, experts have found that Extenbro is distributed as part of malware from the Trojan.IstartSurf package family.

To display the unwanted advertisement, Extenbro changes the DNS settings on the victim's system. Furthermore, the researchers note that
"If a user opens the settings and goes to the Advanced DNS, they will find that four new DNS servers have appeared in the system at once, and not two, as is usually the case. Unfortunately, not all users have the knowledge to go to the advanced settings and pay attention to the fact that there are not two, but four servers at once."
What's worse is that if the victim tries to get rid of the "fake" DNS by deleting them, the malware will re-add them to the settings after each system reboot.

Additionally, the malware completely disables the IPv6 system , so that the victim cannot bypass malicious DNS servers and protect their computer. It also adds a new root certificate to the Windows root certificates by making changes to the Firefox user.js file.
This forces Firefox to use the Windows certificate store, where the attacker's root certificate was added.
