Most good AV developers do a good job at blocking it, but the malware/scareware developers have ways of dynamically changing their ‘deployments’ to avoid signature detection. Often times, even the best AV developers can be a day or so behind.
I just wish there was a way to fight back - not just be defensive.