Trojan found disguised as Microsoft anti-virus product

By on
Trojan found disguised as Microsoft anti-virus product

Distributed via drive-by-download attacks.

A trojan masquerading as the anti-virus product Microsoft Security Essentials attempts to trick users into installing a rogue security program, according to researchers at anti-virus firm F-Secure.

The fake Microsoft Security Essentials is being distributed via drive-by-download attacks as part of a file called “hotfix.exe” or “mstsc.exe,” Mikko Hypponen, chief research officer at F-Secure, wrote in a blog post.

The malware displays a “Microsoft Security Essentials Alert”, which claims the user's computer is infected with an “Unknown Win32/Trojan” in an attempt to frighten users into downloading rogue AV products.

“We are aware of the appearance of rogue AV programs that mimic Microsoft Security Essentials – including the new scareware called ‘Microsoft Security Essentials' – and strongly encourage consumers to only download and install software that is provided directly from Microsoft or other trustworthy sources,” a Microsoft spokesman told in an email.

The malicious program ultimately offers up fake AV products called “AntiSpySafeguard”, “Major Defense Kit”, “Peak Protection”, “Pest Detector” and “Red Cross” to clean the supposed infection, Hypponen said.

“[The malware] will try to scare you into purchasing a product you don't need,” he wrote. “Don't fall for it.”

The legitimate Microsoft Security Essentials is a consumer and small business product that defends against viruses, spyware, and other malicious software.

See original article on

Copyright © SC Magazine, US edition

Most Read Articles

Log In

|  Forgot your password?