Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Security

June 10th, 2009, 09:54 GMT · By

Internet Antivirus Pro Tackled by Microsoft Malicious Software Removal Tool

SHARE:

Adjust text size:


Internet Antivirus Pro rogue antivirus
Enlarge picture
Concomitantly with the June 2009 Microsoft security bulletin releases, the Redmond company has also refreshed the Windows Malicious Software Removal Tool. This month's update to the Malicious Software Removal Tool involves the addition of yet another rogue antivirus. The software giant's free security solution is now capable of tackling Internet Antivirus Pro. The moniker is just one used by a facility of malicious software labeled Win32/InternetAntivirus by Microsoft. Additional labels used by the rogue antivirus are General Antivirus and Personal Antivirus.

Win32/InternetAntivirus follows the familiar path of fake online scanner leading to the rogue downloader, which in turn installs the rogue itself,” revealed Microsoft's Hamish O'Dea. “This rogue downloader that these pages want you to run also downloads a password stealer called TrojanSpy:Win32/Chadem. Win32/Chadem tries to grab FTP usernames and passwords that the rogue creators can then use to compromise servers in order to host more malware. They use new domain names every day, often registering multiple names at a time, like scanfan4.info, star4scan.info and scanstar4.info.”

Rogue antiviruses are pieces of malicious software that masquerade as security products. The fake security solutions are designed to detect inexistent threats and to scare end users into paying for licenses with the promise that their machines will be cleaned by a fully licensed product. This is why rogue antiviruses are also referred to as scareware, and of course that none of these products possess even the most basic antivirus capabilities.

“Win32/InternetAntivirus also installs a component to display messages in your browser, similar to the combination of Win32/FakeXPA and Win32/Yektel. And it displays a bogus Windows Security Center, which reports that Internet Antivirus Pro is "unable" (sic),” O'Dea added. “This is all pretty normal rogue behaviour these days. As always, only use security software that has been tested by a trusted third party.”

The Windows Malicious Software Removal Tool is available for download here.

TELL US WHAT YOU THINK:

4,898 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Microsoft Cleans Password Stealer Malware from 860,000 PCs

Malicious Software Removal Tool Tackles Rogue Antiviruses

Windows Trojan That Infected Over 3.6 Million PCs Evolves with Worm Behavior

Windows 7 Build 7201 Leaked and Available for Download

Windows Live OneCare Bests Kaspersky, Symantec, McAfee, Nod32, BitDefender

READER COMMENTS:


Comment #1 by: steve on 04 Aug 2010, 17:59 UTC reply to this comment

I just ran the Windows Malicious Software Removal Tool. It didn't remove the antivirus pro.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM