NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Security

Security


Malicious Software Removal Tool Tackles Rogue Antiviruses

Win32/Winwebsec and Win32/FakePowav.B

By Marius Oiaga, Technology News Editor

14th of May 2009, 10:48 GMT

Adjust text size:


Security
Enlarge picture
As per tradition, Microsoft's monthly patch package was accompanied in May 2009 by a new release of the Malicious Software Removal Tool. The security solution went live concomitantly with this month's security bulletin release, with Microsoft having added new rogue antiviruses to the list of malicious code that the tool would tackle. “The monthly installment of the technology to remove malicious software from users’ systems is available today as well. This month’s update removes Win32/Winwebsec and Win32/FakePowav.B,” revealed Christopher Budd, security response communications lead for Microsoft.

Both Win32/Winwebsec and Win32/FakePowav.B are rogue antiviruses, namely fake security solutions that deliver no actual functionality but convince users to pay for inexistent protection via various methods. The most popular strategies associated with rogue antivirus products are attempts to convince victims that their computers are infected with malware, and scaring them into paying for a license in order for the fake antivirus to remove the made-up threats. This is why rogue antiviruses are also referred to as scareware.

“Winwebsec goes by different names (“System Security” and “Winweb Security”), typical of a rogue. One less common feature is that it has been known to download additional malware. For a short time it downloaded Worm:Win32/Koobface (which we added to MSRT in March). This brings us full circle: one of the ways we have seen people directed to Win32/Winwebsec’s fake online scanner is via Win32/Koobface. Koobface can launch pop-ups which load fake online scanners. At one time it was FakeXPA, at another it was Win32/Winwebsec. Koobface doesn’t seem attached to a specific rogue,” revealed Microsoft's Hamish O’Dea.

In addition, Winwebsec is also capable of blocking certain Windows programs and components from launching, informing the user that the items are infected. Trojan:Win32/Winwebsec is generally spread via webpages masquerading as online scanners. Users are tricked into downloading the Trojan, which is packaged under a file such as “install.exe.” In their attempt to clean the machine from inexistent threats, victims actually manage to get infected with the Trojan.

“Trojan:Win32/FakePowav is a family of programs that claims to scan for malware and displays fake warnings of “malicious programs and viruses”. They then inform the user that they need to pay money in order to remove these non-existent threats,” Microsoft informed.
 
The Malicious Software Removal Tool is available for download here.

TAGS:

Win32/Winwebsec | Win32/FakePowav.B | Malicious Software Removal Tool
Read by 2,901 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.6/5) 3 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Microsoft Patches Critical PowerPoint Vulnerability Against Attacks

AVG Internet Security 8.5 for Windows 7

Windows 7 RTM: 5 Things You Need to Know

Geneva Beta 2 Available for Download

Access Free eLearning Clinics on Windows 7

Microsoft Patches Target PowerPoint in May 2009

Windows 7 Vbootkit 2.0 Attack Tool Goes Open Source

Internet Explorer 8 "New Session"

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM