Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Editor Blogs > Security

November 29th, 2011, 09:32 GMT · By Eduard Kovacs

BLOG

AV Protection 2011 Leads to Blackhole Exploit Kit

SHARE:

Adjust text size:

AV Protection 2011 is a fake antivirus from the FakeScanti family Enlarge picture - AV Protection 2011 is a fake antivirus from the FakeScanti family
The FakeScanti fake antivirus family has a new addition called AV Protection 2011, which uses a number of techniques to make sure the infected device is left vulnerable to all sorts of malicious elements.

GFI experts observed the infection patterns of this fake antivirus that, once it lands on a system, it tries to modify its host file, much like worms and backdoor threats do.

Whenever the user tries to access popular websites such as Bing, Yahoo!, Google or Facebook, he is automatically redirected to a malevolent IP from Germany where another piece of scareware is hosted.

Identified as Trojan.Win32.FakeAV.IS (v), the malware can in some cases come packaged with the infamous Blackhole exploit kit.

Internet users are advised to avoid clicking on links contained in emails, especially those that advertise great offers for security solutions that replicate famous brands.
FILED UNDER:
Blackhole
fake AV
Trojan

TELL US WHAT YOU THINK:

2,250 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Security Sphere Returns to Exploit KickAssTorrents

Scareware Spreads Through Trusted Internet Connection Speed Test Site

'Federal Tax Report' Emails Spread IRS Malware

Fake AVG Download Sites Steal Bank Accounts

Skype Automated Calls Hide Fake AVs

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM