FakeAV Uses False “Microsoft Security Updates”
Today at SophosLabs we encountered another interesting rogue security software (Fake AV) variant, Troj/FakeAv-AUF. When run Troj/FakeAv-AUF poses as the Windows Automatic Update facility and purports to install an update named XP Internet Security.

This is, as you will have guessed by now, not a genuine Windows security update, this is malware which redirects you from the Windows Security Center to the Fake AV interface and then presents you with false scan results that claim to have located malware on your machine. Rather a lot of malware as you can see from the picture below.

FakeAV malware employs a variety of tricks [1,2,3] and uses social engineering websites in oder to lure the innocent into its trap.
With the large revenue to be earned by the authors of such malware Sophos expects that more and more FakeAV trickery will be discovered in the near future.
Source: http://www.sophos.com/blogs/sophoslabs/?p=8564
February 8th, 2010
Related posts
- Trojan.FakeAV!gen2
- Pop up – Security advisor: Important updates available
- Rogue customer service from rogue antivirus
- Critical Windows file labeled as malicious by AVG Anti-Virus
- Search for “Winter Olympics” and Take Your Pick—FAKEAV or Bogus Windows Media Player Updates
- NY Times FakeAv Banner Ads Certainly not New
- FAKEAV Cashes in on Austin, Texas Plane Crash
- Warning! The media system on your computer is corrupt.
- Alarm in show_ads.js
- FAKEAV Gets First Dibs in Profits from Apple iPad
