Skip to main content
Skip to main content
Microsoft Security Intelligence
500 entries found. Displaying page 1 of 25.
Updated on Apr 11, 2011
TrojanDownloader:Win32/Chepvil.I is a trojan that attempts to download other malware from a remote server. In the wild, this trojan was observed to download files detected as Rogue:Win32/Winwebsec, Backdoor:Win32/Cycbot.B and VirTool:Win32/Injector.gen!BG.
Alert level: severe
Updated on Apr 11, 2011
TrojanDownloader:Win32/Chepvil.J is a trojan that attempts to download other malware from a remote server. In the wild, we observed this trojan downloading files detected as Rogue:Win32/Winwebsec, Backdoor:Win32/Cycbot.B and VirTool:Win32/Injector.gen!BG.
Alert level: severe
Updated on May 03, 2011

Spammer:Win32/Fifesock.C is a component of Win32/Fifesock - a multiple component trojan family that injects code into Internet Explorer and Firefox in order to steal the user’s social networking credentials for sites such as Facebook, and then uses these credentials to send spam to their contacts. It may also download and execute arbitrary files. Some variants have also been observed to install rogue security software such as Rogue:Win32/Winwebsec.

Alert level: severe
Updated on Apr 17, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/Defmid description for more information.

Alert level: severe
Updated on Mar 13, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/Fakeinit description for more information.

Alert level: severe
Updated on Mar 13, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/FakeXPA description for more information.

Alert level: severe
Updated on Aug 06, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/FakeXPA description for more information.

Alert level: severe
Updated on Aug 20, 2013

SpySheriff may be installed without user consent, and may then display a dialog box suggesting malware has been found, and prompting the user to buy software to remove the malware that doesn't exist. SpySheriff may download and install program updates without notifying the user.

Alert level: severe
Updated on Aug 20, 2013
Rogue:Win32/SpyAxeis a program that displays misleading warning messages to convince users to purchase a product that removes spyware. It might have a desktop icon that looks like the following:

Alert level: severe
Updated on Apr 11, 2011
Win32/FakeRemoc is a family of trojans that claim to scan for malware and display fake warnings of “malicious programs and viruses”. They inform the user that they need to pay money to register the software in order to remove these non-existent threats. These trojans may subvert an affected user's web activity, or attempt to download other malware, such as Trojan:Win32/Hiloti. They may also display dialogs that mimic the Windows Security Center.
 
Special Note:
Reports of Rogue Antivirus programs have been more prevalent as of late.  These are programs that generate misleading alerts and false detections in order to convince users to purchase illegitimate security software.  Some of these programs may display product names or logos in an apparently unlawful attempt to impersonate Microsoft products. 
 
To detect and remove this threat and other malicious software that may be installed in your computer, run a full-system scan with an up-to-date antivirus product such as the following:
 
 
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.
Alert level: severe
Updated on Oct 27, 2015

Windows Defender detects and removes this threat.

This threat is a file that is used to download rogue security software programs that we detect as Win32/FakePav.

See the Win32/FakePAV description for more information.

Find out ways that malware can get on your PC.

Alert level: severe
Updated on Mar 20, 2016

Windows Defender detects and removes this threat.

This threat is a webpage that claims that your PC is infected with malware. It asks you to call a technical support number to help remove the malware.

The website is a hoax and cannot find malware on your PC.

You can read more about this type of threat on our rogue security software page.

Find out ways that malware can get on your PC.

Alert level: severe
Updated on Apr 11, 2011
Win32/FakeFast is a family of programs that claims to scan for malware and displays fake warnings of "malicious programs and viruses". They then inform the user that they need to pay money in order to remove these non-existent threats.
Alert level: severe
Updated on Sep 05, 2014

Windows Defender detects and removes this threat.

This rogue security program falsely claims that your PC is infected with malware. It then encourages you to pay for a product to remove the "threats" from your PC.

See the Win32/FakeSpypro family description for more information.

Alert level: severe
Updated on Jan 28, 2014

Windows Defender detects and removes this threat.

This threat tries to download rogue security software onto your PC, including Win32/FakeRean.

It runs when you visit a malicious web page and move your mouse cursor over certain graphics or images.

Alert level: severe
Updated on Apr 17, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/InternetAntivirus description for more information.

Alert level: severe
Updated on Aug 17, 2014

Windows Defender detects and removes this threat.

This rogue security website pretends to scan your PC for malware, and often report lots of infections. It will say you have to pay for it before it can fully clean your PC.

However, it hasn't really detected any malware at all and isn't really an antivirus or antimalware scanner. It just looks like one so you'll send money to the people who made the rogue. The websites use product names or logos that unlawfully impersonate Microsoft products.

Even if you do pay, it won't do anything because your PC isn't actually infected with all that malware it "found".

Find out ways that malware can get on your PC.

Alert level: severe
Updated on Aug 24, 2014

Windows Defender Antivirus detects and removes this threat. See the Win32/Winwebsec description for more information.

Find out ways that malware can get on your PC.  

Alert level: severe
Updated on Oct 07, 2013

Rogue:MacOS_X/FakeMacdef is a family of rogue programs that affect Mac OSX. They claim to scan for malware and display fake warning messages regarding “malicious programs and viruses”. They attempt to scare you into paying for the fake product by displaying fake scan results, infection messages and warnings.

You can read more on our rogue page.

Alert level: severe
Updated on Nov 17, 2015

Windows Defender Antivirus detects and removes this threat. 

This threat claims to scan for malware and then shows you fake warnings about “malicious programs and viruses”. It then asks you to pay money to remove the fake threats.

Our rogue security software page has more information about this type of threat.

Find out ways that malware can get on your PC.

Alert level: severe