We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Rogue:MSIL/Zeven
Detected by Microsoft Defender Antivirus
Aliases: No associated aliases
Summary
Rogue:MSIL/Zeven is a family of programs that claims to scan for malware and displays fake warnings of "malicious programs and viruses". They then inform the user that they need to pay money to register the software in order to remove these non-existent threats. MSIL/Zeven also has the ability to mimic browser pages that indicate a particular website is blocked; the fake warning pages offer a "solution" for download; the "solution" is actually a copy of Rogue:MSIL/Zeven.
To detect and remove this threat and other malicious software that may be installed in your computer, run a full-system scan with an up-to-date antivirus product such as the following:
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.