Skip to main content
Skip to main content
Microsoft Security Intelligence
18 entries found.
Updated on Apr 11, 2011
TrojanDropper:Win32/Renos.F is a trojan that drops unwanted software, known as Program:Win32/Antivirus2008.
Alert level: severe
Updated on Apr 11, 2011
Trojan:Win32/Zlob.G is a component of Win32/Zlob that downloads rogue security programs, adware, and additional Win32/Zlob components.
Alert level: severe
Updated on Apr 11, 2011
TrojanDownloader:Win32/Renos.EE a generic detection for a component of certain variants of TrojanDownloader:Win32/Renos, a family of trojan downloaders that automatically download unwanted software such as SpySheriff, SpyAxe, SpyFalcon, SpyDawn, SpywareStrike, and other similarly named programs. These programs typically present erroneous warnings claiming the system is infected with spyware and offer to remove the alleged spyware for a fee. In some cases, the programs may also cause system instability.
Alert level: severe
Updated on Apr 17, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/Defmid description for more information.

Alert level: severe
Updated on Apr 17, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/InternetAntivirus description for more information.

Alert level: severe
Updated on Apr 11, 2011
TrojanDropper:Win32/Insebro.A is a trojan that downloads and executes arbitrary files. In the wild it has been observed downloading and installing rogue security software, such as Win32/FakeRean, onto affected machines. 
 
Special Note:
Reports of Rogue Antivirus programs have been more prevalent as of late.  These are programs that generate misleading alerts and false detections in order to convince users to purchase illegitimate security software.  Some of these programs may display product names or logos in an apparently unlawful attempt to impersonate Microsoft products. 
Alert level: severe
Updated on Aug 24, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/Winwebsec description for more information.

Find out ways that malware can get on your PC.  

Alert level: severe
Updated on Apr 17, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/Winwebsec description for more information.

Alert level: severe
Updated on Mar 13, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/Fakeinit description for more information.

Alert level: severe
Updated on May 29, 2008
Trojan:Win32/Renos.D is a trojan that downloads unwanted software such as "Antivirus2008", a rogue security program that displays misleading alerts regarding computer problems or falsely reports detections of malicious files on the affected machine in order to convince users to purchase rogue security software.
Alert level: severe
Updated on Mar 13, 2014

Windows Defender detects and removes this threat.

A trojan within this family consists of a downloader component and a fake scanner component. The downloader stops certain processes, lowers security settings, changes the desktop background, and tries to download other malware like Trojan:Win32/Alureon.CT. It also blocks access to webpages from certain domains.

Alert level: severe
Updated on Aug 06, 2014

Microsoft security software detects and removes this family of threats.

This family of rogue security programs pretend to scan your PC for malware, and often report lots of infections. The program will say you have to pay for it before it can fully clean your PC.

However, the program hasn't really detected any malware at all and isn't really an antivirus or antimalware scanner. It just looks like one so you'll send money to the people who made the program. Some of these programs use product names or logos that unlawfully impersonate Microsoft products.

Even if you do pay to "unlock" the app, it won't do anything because your PC isn't actually infected with all that malware it "found".

Different brands of the rogues may modify various settings on your computer, end or close programs or system services, or block access to websites.

by other malware.

You can read more on our rogue page.

Find out ways that malware can get on your PC.

Alert level: severe
Updated on Apr 11, 2011
Trojan:Win32/Renos.C is a trojan that installs unwanted software such as "XP Antivirus2008", a rogue security program that displays misleading alerts regarding computer problems or falsely reports detections of malicious files on the affected machine in order to convince users to purchase rogue security software.
Alert level: severe
Updated on Apr 11, 2011
TrojanDownloader:Win32/FakeIA.A is a trojan downloader and component of the rogue program Trojan:Win32/InternetAntivirus.
Alert level: severe
Updated on Apr 11, 2011
Trojan:Win32/FakeAnts is a rogue security program that displays misleading alerts regarding computer problems or falsely reports detections of malicious files on the affected machine in order to convince users to purchase rogue security software. It may be installed by Trojan:Win32/Renos.D, or manually installed by a computer user.
Alert level: severe
Updated on Apr 11, 2011
Trojan:Win32/FakeCanine is a family of trojans that claims to scan for malware and displays fake warnings of “malicious programs and viruses”. They then inform the user that they need to pay money to register the software in order to remove these non-existent threats. They change the user’s default Start Page and may change other security-related registry settings. Trojan:Win32/FakeCanine variants have been observed to use names such as “Secure Antivirus Pro.”
 
Note:
Reports of Rogue Antivirus programs have been more prevalent as of late.  These are programs that generate misleading alerts and false detections in order to convince users to purchase illegitimate security software.  Some of these programs may display product names or logos in an apparently unlawful attempt to impersonate Microsoft products. 
Alert level: high
Updated on Apr 11, 2011
Trojan:Win32/Pernefed is a family of programs that claims to scan for malware and displays fake warnings of “malicious programs and viruses”. They then inform the user that they need to pay money in order to remove these non-existent threats.
Special Note:
Reports of Rogue Antivirus programs have been more prevalent as of late.  These are programs that generate misleading alerts and false detections in order to convince users to purchase illegitimate security software.  Some of these programs, such as Trojan:Win32/Antivirusxp and Program:Win32/FakeRednefed may display product names or logos in an apparently unlawful attempt to impersonate Microsoft products.  These products may represent themselves as “Antivirus XP”, “AntivirusXP 2008”, “WinDefender 2008”, “XP Antivirus”, or similar.
 
Use Microsoft Windows Defender, the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742), or another up-to-date scanning and removal tool to detect and remove these threats and other unwanted software from your computer. For more information on Microsoft security products, see http://www.microsoft.com/protect/products/computer/default.mspx.
Alert level: high
Updated on Jun 07, 2016

Windows Defender detects and removes this threat. 

This threat is a rogue security program that displays misleading alerts regarding computer problems or falsely reports detections of malicious files on the affected machine. It does so to attempt to convince users to purchase rogue security software.
 
These are programs that generate misleading alerts and false detections to convince users to purchase illegitimate security software.  Some of these programs, such as this threat and Program:Win32/FakeRednefed, might display product names or logos in an apparently unlawful attempt to impersonate Microsoft products.  These products may represent themselves as “Antivirus XP”, “AntivirusXP 2008”, “WinDefender 2008”, “XP Antivirus”, or similar.

Find out ways that malware can get on your PC.  

Alert level: high