Trojan found disguised as Microsoft anti-virus product

By
Follow google news

Distributed via drive-by-download attacks.

A trojan masquerading as the anti-virus product Microsoft Security Essentials attempts to trick users into installing a rogue security program, according to researchers at anti-virus firm F-Secure.

The fake Microsoft Security Essentials is being distributed via drive-by-download attacks as part of a file called “hotfix.exe” or “mstsc.exe,” Mikko Hypponen, chief research officer at F-Secure, wrote in a blog post.

Trojan found disguised as Microsoft anti-virus product

The malware displays a “Microsoft Security Essentials Alert”, which claims the user's computer is infected with an “Unknown Win32/Trojan” in an attempt to frighten users into downloading rogue AV products.

“We are aware of the appearance of rogue AV programs that mimic Microsoft Security Essentials – including the new scareware called ‘Microsoft Security Essentials' – and strongly encourage consumers to only download and install software that is provided directly from Microsoft or other trustworthy sources,” a Microsoft spokesman told SCMagazineUS.com in an email.

The malicious program ultimately offers up fake AV products called “AntiSpySafeguard”, “Major Defense Kit”, “Peak Protection”, “Pest Detector” and “Red Cross” to clean the supposed infection, Hypponen said.

“[The malware] will try to scare you into purchasing a product you don't need,” he wrote. “Don't fall for it.”

The legitimate Microsoft Security Essentials is a consumer and small business product that defends against viruses, spyware, and other malicious software.

See original article on scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

The BoM has finally tamed SSL

The BoM has finally tamed SSL

Commercial spyware targeted Samsung Galaxy users for months

Commercial spyware targeted Samsung Galaxy users for months

Westpac factors post-quantum cryptography prep into "secure router" rollout

Westpac factors post-quantum cryptography prep into "secure router" rollout

Australia and US impose sanctions on North Korean cyber ops

Australia and US impose sanctions on North Korean cyber ops

Log In

  |  Forgot your password?