Knowledge Base

Support

Unmasking Fake Antivirus (AV) - For Small and Medium Businesses (SMB)

Solution IDLast Updated
1055358Date : 2012/02/2 Time: 1:11 AM (PST)


Product/VersionPlatform
Client Server Messaging Security for SMB - 3.6; Email Reputation Services - Hosted, Standard/Advanced; InterScan Gateway Security Appliance - 1.0, 1.1, 1.5; InterScan Messaging Hosted Security - Advanced, Standard; InterScan VirusWall - 6.0 for Windows, 7.0; Worry-Free Business Security Hosted - 2.5; Worry-Free Business Security Services - 3.0, 3.5; Worry-Free Business Security Services for Dell - 3.5; Worry-Free Business Security Standard/Advanced - 5.1, 6.0, 7.0; Worry-Free Remote Manager - 2.6
Windows - 2000 Advanced Server, 2000 Professional, 2000 Server, 2000 Small Business Server, 2003 Home Server, 2003 Small Business Server, 2003 Standard Server Edition, 2008 Enterprise Server, 2008 Essential Business Server, 2008 Small Business Server, 2008 Standard Server Edition, 7 32-bit, Vista 32-bit, XP Home, XP Professional

Problem Description

This article shows how rogue antivirus or FAKEAV applications arrive on systems.

Solution

FakeAV or rogue antivirus software has been prevalent in the market today and has affected millions of computers.

To educate you on how Fake AV arrives on a computer's system and to know the available Trend Micro solutions to combat this threat, please refer to the following:

        Unmasking Fake AV  

In this document, you will find detailed information on the following topics: 

    • Infection Vectors
 
    • Proliferation via Malicious Routine
 
    • Malware Transformation   
 
    • Notable Malware Behavior
 
    • Online and Local
 
    • Protection against Fave AV
 
    • Recovering from Fake AV infection 
 

 

To help clean the FakeAV infection, you may use the FakeAV Removal Tool

 

Note: This tool is still in the beta stage.


Rate this Solution
Did this article help you?  
 
Please provide your comments to help us improve this solution.

 
  *This form is an automated system. General questions, technical, sales and product-related issues submitted through this form will not be answered.
 
 

Connect with us on