Skip to main content
Skip to main content
Microsoft Security Intelligence
500 entries found. Displaying page 1 of 25.
Updated on Sep 06, 2011
Rogue:Win32/FakeYak is a family of fake antivirus products, using names such as Zentom System Guard or Antimalware Doctor, that claim to scan for malware and display fake warnings of malicious files. They then inform the user that they need to pay money to register the software in order to remove these non-existent threats.
Alert level: severe
Updated on Mar 13, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/FakeXPA description for more information.

Alert level: severe
Updated on Nov 19, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/FakeRean description for more information.

Find out ways that malware can get on your PC.  

Alert level: severe
Updated on Mar 13, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/Fakeinit description for more information.

Alert level: severe
Updated on Aug 24, 2014

Windows Defender detects and removes this threat.

This threat is detected in a webpage that shows a fake security scanner. It falsely tells you that your PC is infected with viruses and that you need to install other software to disinfect it. The software it offers for install is usually a rogue security software, which doesn't clean your PC and instead tells you that you need to pay for more, nonexistent, cleaning.

See the Rogue security software page for more information.

Alert level: severe
Updated on Mar 25, 2015

Windows Defender detects and removes this threat.

This threat is a webpage that claims your PC is infected with malware. It asks you to phone a number to receive technical support to help remove the malware.

The website is a hoax and cannot find malware on your PC.

You can read more about this type of threat on our rogue security software page.

Find out ways that malware can get on your PC.

Alert level: severe
Updated on Mar 24, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/FakePowav description for more information.

Alert level: severe
Updated on Apr 15, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/Sirefef description for more information.

Alert level: severe
Updated on Apr 11, 2011
Rogue:Win32/Cedel is a rogue rogue antivirus program that imitates the Microsoft Malicious Software Removal Tool (MSRT). It displays fake alerts that the computer is infected and then redirects the user to a website to purchase the fake program.
 
Special Note:
Reports of Rogue Antivirus programs have been more prevalent as of late.  These are programs that generate misleading alerts and false detections in order to convince users to purchase illegitimate security software.  Some of these programs may display product names or logos in an apparently unlawful attempt to impersonate Microsoft products. 
 
To detect and remove this threat and other malicious software that may be installed in your computer, run a full-system scan with an up-to-date antivirus product such as the following:
 
 
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.
Alert level: severe
Updated on Mar 24, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/FakePowav description for more information.

Alert level: severe
Updated on Apr 11, 2011
Rogue:MSIL/Zeven is a family of programs that claims to scan for malware and displays fake warnings of "malicious programs and viruses". They then inform the user that they need to pay money to register the software in order to remove these non-existent threats. MSIL/Zeven also has the ability to mimic browser pages that indicate a particular website is blocked; the fake warning pages offer a "solution" for download; the "solution" is actually a copy of Rogue:MSIL/Zeven.
Alert level: severe
Updated on Apr 17, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/Winwebsec description for more information.

Alert level: severe
Updated on Aug 24, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/Onescan description for more information.

Find out ways that malware can get on your PC

Alert level: severe
Updated on Apr 11, 2011
Win32/FakePlus is a rogue security program that falsely claims the user's system is infected and encourages the user to buy a promoted product in order 'remove' the bogus infections.
 
Special Note:
Reports of Rogue Antivirus programs have been more prevalent as of late.  These are programs that generate misleading alerts and false detections in order to convince users to purchase illegitimate security software.  Some of these programs, such as Win32/Antivirusxp and Win32/FakeRednefed may display product names or logos in an apparently unlawful attempt to impersonate Microsoft products. 
 
To detect and remove this threat and other malicious software that may be installed in your computer, run a full-system scan with an up-to-date antivirus product such as the following:
 
 
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.
Alert level: severe
Updated on Apr 11, 2011
Rogue:Win32/Rudoct is a rogue scanner that imitates an antivirus program and displays misleading alerts in an attempt to coax the affected user to purchase it.
 
Special Note:
Reports of Rogue Antivirus programs have been more prevalent as of late.  These are programs that generate misleading alerts and false detections in order to convince users to purchase illegitimate security software.  Some of these programs may display product names or logos in an apparently unlawful attempt to impersonate Microsoft products. 
 
To detect and remove this threat and other malicious software that may be installed in your computer, run a full-system scan with an up-to-date antivirus product such as the following:
 
 
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.
Alert level: severe
Updated on May 22, 2016

Microsoft Defender Antivirus detects and removes this threat.

This threat claims to scan for malware and then shows you fake warnings about “malicious programs and viruses”. It then asks you to pay money to remove the fake threats.

Our rogue security software page has more information about this type of threat.

Find out ways that malware can get on your PC.

Alert level: severe
Updated on Nov 16, 2014

Windows Defender detects and removes this threat.

The threat is a rogue, which means it pretends to be security software. It looks and acts like Windows Defender, but is completely fake.

It uses names such as "Spyware Defender" or "System Defender".

It says it finds malware, viruses, and threats on your PC, and that you need to pay money to fully remove them. The threats do not exist - the rogue is just trying to scare you into paying money for a piece of software that does not work. 

The threat might also block access to some websites, change your PC's security settings, and open Internet Explorer windows that load adult content.

It might have been downloaded onto your PC by another malware, or you might have been tricked into downloading it, thinking it was legitimate. 

Find out ways that malware can get on your PC.  

Alert level: severe
Updated on Dec 08, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/FakePAV description for more information.

Alert level: severe
Updated on Oct 27, 2015

Windows Defender Antivirus detects and removes this threat. See the Win32/FakePAV description for more information.

Alert level: severe
Updated on Oct 27, 2015

Microsoft security software detects and removes this threat.

The threat is a VBScript component of Win32/Trapwot, used to install this rogue. Rogues pretend to be security software and might look and act like Windows Defender, but it's completely fake.

It uses names such as "Spyware Defender" or "System Defender".

It might have been downloaded onto your PC by another malware, or you might have been tricked into downloading it, thinking it was legitimate. 

You can read more about this family in the Win32/Trapwot description.

Find out ways that malware can get on your PC

Alert level: severe