Trojan found disguised as Microsoft anti-virus product

A trojan masquerading as the anti-virus product Microsoft Security Essentials attempts to trick users into installing a rogue security program, according to researchers at anti-virus firm F-Secure.

The fake Microsoft Security Essentials is being distributed via drive-by-download attacks as part of a file called “hotfix.exe” or “mstsc.exe,” Mikko Hypponen, chief research officer at F-Secure, wrote in a blog post Friday. The malware displays a “Microsoft Security Essentials Alert,” which claims the user's computer is infected with an “Unknown Win32/Trojan” in an attempt to frighten users into downloading rogue AV products.

“We are aware of the appearance of rogue AV programs that mimic Microsoft Security Essentials – including the new scareware called ‘Microsoft Security Essentials' – and strongly encourage consumers to only download and install software that is provided directly from Microsoft or other trustworthy sources,” a Microsoft spokesman told SCMagazineUS.com in an email Friday.

The malicious program ultimately offers up fake AV products called “AntiSpySafeguard,” “Major Defense Kit,” “Peak Protection,” “Pest Detector” and “Red Cross” to clean the supposed infection, Hypponen said.

“[The malware] will try to scare you into purchasing a product you don't need,” he wrote. “Don't fall for it.”

The legitimate Microsoft Security Essentials is a consumer and small business product that defends against viruses, spyware, and other malicious software.

More in News

Attackers use Skype, other IM apps to spread Liftoh trojan

Countries in Latin America have been the primary targets in this campaign, researchers say.

Scammers on the hunt for Memorial Day deal watchers

Like they do with major news events and other holidays, online fraudsters are seeking to cash in on the upcoming Memorial Day weekend.

Proxy research firm settles charges with SEC over client breach

Institutional Shareholder Services (ISS), a research firm the advises clients on voting in proxy fights, must pay $300,000 to the U.S. Securities and Exchange Commission.