We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Rogue:VBS/Trapwot
Aliases: No associated aliases
Summary
Microsoft security software detects and removes this threat.
The threat is a VBScript component of Win32/Trapwot, used to install this rogue. Rogues pretend to be security software and might look and act like Windows Defender, but it's completely fake.
It uses names such as "Spyware Defender" or "System Defender".
It might have been downloaded onto your PC by another malware, or you might have been tricked into downloading it, thinking it was legitimate.
You can read more about this family in the Win32/Trapwot description.
Use the following free Microsoft software to detect and remove this threat:
- Microsoft Defender Antivirus for Windows 10 and Windows 8.1, or Microsoft Security Essentials for Windows 7 and Windows Vista
- Microsoft Safety Scanner
You should also run a full scan. A full scan might find hidden malware.
Get more help
You can also visit our advanced troubleshooting page or search the Microsoft virus and malware community for more help.
If you’re using Windows XP, see our Windows XP end of support page.