SharePoint itself is not very smart and relies on file extensions, so renaming files will bypass it.
Forefront for SharePoint performs file validation, therefore it should be included in the list of mandatory for any appearance (and internal, if you allow staff to install / run unknown software).
You can manage the list of locked files in the central administrator in the "Types of operations / locked files" section. Note: this is for webapp!
Craig
source share