Skip to main content
Skip to main content
Microsoft Security Intelligence
14 entries found.
Updated on Jun 05, 2012

Worm:Win32/Flame is a multi-component worm that uses a variety of actions to perform its malicious payload, which also includes gathering information from your infected computer.

Worm:Win32/Flame.gen!B is a component of this malware that may be used to contact remote hosts, as part of its payload.

Worm:Win32/Flame components have been observed using stolen certificates to facilitate the malware's attack. On June 3, 2012, Microsoft reported on the revocation of this certificate; you can read more about this in the following article: http://technet.microsoft.com/en-us/security/advisory/2718704

Alert level: severe
Updated on Jun 05, 2012

Worm:Win32/Flame is a multi-component worm that uses a variety of actions to perform its malicious payload, which also includes gathering information from your infected computer.

Worm:Win32/Flame components have been observed using stolen certificates to facilitate the malware's attack. On June 3, 2012, Microsoft reported on the revocation of this certificate; you can read more about this in the following article: http://technet.microsoft.com/en-us/security/advisory/2718704

Alert level: severe
Updated on Jun 05, 2012

Trojan:Win32/Flame.A!cert is a detection for files signed by a fraudulent certificate that appears as if it was produced by Microsoft.

On June 3, 2012, Microsoft reported on the revocation of this certificate; you can read more about this in the following article: http://technet.microsoft.com/en-us/security/advisory/2718704

Alert level: severe
Updated on Jun 05, 2012

Trojan:Win32/Flame.B!cert is a detection for files signed by a fraudulent certificate that appears as if it was produced by Microsoft.

On June 3, 2012, Microsoft reported on the revocation of this certificate; you can read more about this in the following article: http://technet.microsoft.com/en-us/security/advisory/2718704

Alert level: severe
Updated on Jun 20, 2012

Worm:Win32/Flame is a multi-component worm that uses a variety of actions to perform its malicious payload, which also includes gathering information from your infected computer.

Worm:Win32/Flame components have been observed using stolen certificates to facilitate the malware's attack. On June 3, 2012, Microsoft reported on the revocation of this certificate; you can read more about this in the following article: http://technet.microsoft.com/en-us/security/advisory/2718704

Alert level: severe
Updated on Jun 05, 2012

Worm:Win32/Flame is a multi-component worm that uses a variety of actions to perform its malicious payload, which also includes gathering information from your infected computer.

Worm:Win32/Flame.gen!C is a component of this malware that may be used to steal information about the infected computer, as part of its payload.

Worm:Win32/Flame components have been observed using stolen certificates to facilitate the malware's attack. On June 3, 2012, Microsoft reported on the revocation of this certificate; you can read more about this in the following article: http://technet.microsoft.com/en-us/security/advisory/2718704

Alert level: severe
Updated on Jun 05, 2012

Worm:Win32/Flame is a multi-component worm that uses a variety of actions to perform its malicious payload, which also includes gathering information from your infected computer.

Worm:Win32/Flame!cfg is a component of this malware that may be used to capture screenshots of the affected computer.

Worm:Win32/Flame components have been observed using stolen certificates to facilitate the malware's attack. On June 3, 2012, Microsoft reported on the revocation of this certificate; you can read more about this in the following article: http://technet.microsoft.com/en-us/security/advisory/2718704

Alert level: severe
Updated on Jun 05, 2012

Worm:Win32/Flame is a multi-component worm that uses a variety of actions to perform its malicious payload, which also includes gathering information from your infected computer.

Worm:Win32/Flame!dat is an encrypted configuration component of this malware.

Worm:Win32/Flame components have been observed using stolen certificates to facilitate the malware's attack. On June 3, 2012, Microsoft reported on the revocation of this certificate; you can read more about this in the following article: http://technet.microsoft.com/en-us/security/advisory/2718704

Alert level: severe
Updated on Oct 07, 2008
Alert level: severe
Updated on Oct 07, 2008
Alert level: severe
Updated on Oct 07, 2008
Alert level: severe
Updated on May 31, 2012
Alert level: severe
Updated on Jan 02, 2022
Alert level: severe
Updated on Jan 10, 2018

Windows Defender AV detects and removes this threat.

This ransomware can stop you from using your PC or accessing your data. It might ask you to pay money to a malicious hacker.

We've seen this ransomware being downloaded by a trojan detected as TrojanDownloader:JS/Crimace.A, which is being distributed via email messages that pretend to be fax.

Read more in this blog: Fake fax ushers in revival of a ransomware family.

Our ransomware FAQ page has more information on this type of threat.

The trend towards increasingly sophisticated malware behavior, highlighted by the use of exploits and other attack vectors, makes older platforms so much more susceptible to ransomware attacks. From June to November 2017, Windows 7 devices were 3.4 times more likely to encounter ransomware compared to Windows 10 devices.

Read our latest report: A worthy upgrade: Next-gen security on Windows 10 proves resilient against ransomware outbreaks in 2017.

Alert level: severe