Check my recent post that starts out "YAHOO!!..............." (do a forum search, it should be in the past day or two so fairly close to the top)
I created a policy using SEP that blocks some of those rogue av apps and other things from installing.
In fact, I was fully successful yesterday in that SEP didn't stop the EXE installer from running, even though it flagged and attempted to delete it, but the policy DID prevent any DLL or EXE files from being installed in the user profile area!
So in effect, I used a part of SEP to block the infection that otherwise might have taken place.
I saw it in action as the logs rolled by on my screen and was pretty happy with it.
I've also got an article posted from months ago that tells what I did and how it worked.
So do read all the above, and know that SEP or any other can't be 100%, but at some risk here, I'll also state and AV is only as good as the security administrator makes it.......... and you with our help can make SEP even better by using custom policies and configurations.
Go for it, then post your sucess stories!
Too often forums are gripe areas where those with problems come to find others like them........... I'd like to see some more "YES, we killed it and here's how we did it" posts myself. We can ALL learn from those as well!