Trojan found disguised as Microsoft anti-virus product

A trojan masquerading as the anti-virus product Microsoft Security Essentials attempts to trick users into installing a rogue security program, according to researchers at anti-virus firm F-Secure.

The fake Microsoft Security Essentials is being distributed via drive-by-download attacks as part of a file called “hotfix.exe” or “mstsc.exe,” Mikko Hypponen, chief research officer at F-Secure, wrote in a blog post Friday. The malware displays a “Microsoft Security Essentials Alert,” which claims the user's computer is infected with an “Unknown Win32/Trojan” in an attempt to frighten users into downloading rogue AV products.

“We are aware of the appearance of rogue AV programs that mimic Microsoft Security Essentials – including the new scareware called ‘Microsoft Security Essentials' – and strongly encourage consumers to only download and install software that is provided directly from Microsoft or other trustworthy sources,” a Microsoft spokesman told SCMagazineUS.com in an email Friday.

The malicious program ultimately offers up fake AV products called “AntiSpySafeguard,” “Major Defense Kit,” “Peak Protection,” “Pest Detector” and “Red Cross” to clean the supposed infection, Hypponen said.

“[The malware] will try to scare you into purchasing a product you don't need,” he wrote. “Don't fall for it.”

The legitimate Microsoft Security Essentials is a consumer and small business product that defends against viruses, spyware, and other malicious software.

Sign up to our newsletters

More in News

House Intelligence Committee OKs amended version of controversial CISPA

Despite the 18-to-2 vote in favor of the bill proposal, privacy advocates likely will not be satisfied, considering two key amendments reportedly were shot down.

Judge rules hospital can ask ISP for help in ID'ing alleged hackers

The case stems from two incidents where at least one individual is accused of accessing the hospital's network to spread "defamatory" messages to employees.

Three LulzSec members plead guilty in London

Ryan Ackroyd, 26; Jake Davis, 20; and Mustafa al-Bassam, 18, who was not named until now because of his age, all admitted their involvement in the hacktivist gang's attack spree.