Trojan found disguised as Microsoft anti-virus product

Share this article:
A trojan masquerading as the anti-virus product Microsoft Security Essentials attempts to trick users into installing a rogue security program, according to researchers at anti-virus firm F-Secure.

The fake Microsoft Security Essentials is being distributed via drive-by-download attacks as part of a file called “hotfix.exe” or “mstsc.exe,” Mikko Hypponen, chief research officer at F-Secure, wrote in a blog post Friday. The malware displays a “Microsoft Security Essentials Alert,” which claims the user's computer is infected with an “Unknown Win32/Trojan” in an attempt to frighten users into downloading rogue AV products.

“We are aware of the appearance of rogue AV programs that mimic Microsoft Security Essentials – including the new scareware called ‘Microsoft Security Essentials' – and strongly encourage consumers to only download and install software that is provided directly from Microsoft or other trustworthy sources,” a Microsoft spokesman told SCMagazineUS.com in an email Friday.

The malicious program ultimately offers up fake AV products called “AntiSpySafeguard,” “Major Defense Kit,” “Peak Protection,” “Pest Detector” and “Red Cross” to clean the supposed infection, Hypponen said.

“[The malware] will try to scare you into purchasing a product you don't need,” he wrote. “Don't fall for it.”

The legitimate Microsoft Security Essentials is a consumer and small business product that defends against viruses, spyware, and other malicious software.

Share this article:

Sign up to our newsletters

More in News

EFF intros wireless router software to boost industry standard

EFF intros wireless router software to boost industry ...

This weekend, the digital rights group released a "hacker alpha" version of its Open Wireless Router software.

Breaches driving organizational security strategy, survey indicates

Breaches driving organizational security strategy, survey indicates

CyberArk interviewed 373 IT security executives and other senior management in North America, Europe and the Asia-Pacific as part of its eighth annual Global Advanced Threat Landscape survey.

Siemens industrial products impacted by four OpenSSL vulnerabilities

The vulnerabilities can be exploited remotely, and fairly easily, by an attacker to hijack sessions and crash the web server of the product.