Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    February 2012
    S M T W T F S
    « Jan    
     1234
    567891011
    12131415161718
    19202122232425
    26272829  
  • About Us
    Malware Blog > Rogue Antivirus Terminates EXE Files

    This weekend, we at TrendLabs came across a FAKEAV variant similar to the one peddled in the solar eclipse 2009 in America attack in this recent blog post. This one, however, introduces another new scare tactic (so far the latest new ploy we’ve seen is the ransomware/FAKEAV that encrypts files in the infected computer and offers a bogus fixtool for a price).

    This FAKEAV variant terminates any executed file with an .EXE file extension and displays a pop-up message saying that the .EXE file is infected and cannot execute.


    Click for larger view Click for larger view

    This way, users are left with no choice but to activate the antivirus product since no other application works. This Trojan is detected by Trend Micro as TROJ_FAKEAV.B. It avoids terminating critical processes to prevent system crashes.

    Unfortunately, cybercriminals work hard in creating so many gimmicks, that we can only guess what comes next in FAKEAV. Fortunately though, the Trend Micro Smart Protection Network provides users protection from such threats.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    16 Responses to “Rogue Antivirus Terminates EXE Files”

    1. Jerel Peters Says:

      I have trend micro internet security, and right now that virus has my computer hostage. I don’t understand the audacious statement: “Fortunately though, the Trend Micro Smart Protection Network provides users protection from such threats.”???

    2. davesgraphics Says:

      My vote for the worst ever rogue program is “Windows Antivirus Pro”–It will eat your computer program by program by refusing to load them as they are “infected”, then it proceeds to block any recovery—control alt delete wont work, regedit wont work, add remove programs wont work, you cant delete any of their programs files, cant restart your installed authentic virusware or even go to a previous restore point. AND YOU CANT LOAD EVEN A NEW LEGITIMATE ANTIVIRUS PROGRAM. You have but one choice–buy their software online—while Explorer is still working that is–that begins to go bad too. There are several Windows anti virus removal tools on the net—-but BEWARE—one of these—is them too!

      It appears the only recourse for one of my friends is to reinstall windows–and lose all her files.

    Trackbacks

    1. TrendMicro (TrendMicro)
    2. spamloco (Alejandro Eguía)
    3. samanahavemail (PipE)
    4. balaji_a (BaaJi)
    5. tonys3kur3 (Tony Bradley)
    6. internetsecurity of virusscanner - Pagina 157 - Zita Forums
    7. opexxx (alex knorr)
    8. Gefälschte Antiviren-Software macht Dateien unbrauchbar - Security | News | ZDNet.de
    9. Gefälschte Antiviren-Software macht Dateien unbrauchbar - WinBoard - Die Windows Community
    10. iia_security (Terry Walls)
    11. EvilFingers (EvilFingers)
    12. Plaats hier software gerelateerd nieuws! - Page 10
    13. Arvutikaitse » Blog Archive » Libatõje, mis keelab exe failide avamise
    14. jrimer2008 (Jared Rimer)


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice