Skip to main content
Skip to main content
Microsoft Security Intelligence
17 entries found.
Updated on Aug 19, 2020
Alert level: severe
Updated on Oct 11, 2021
Alert level: severe
Updated on Aug 22, 2023
Alert level: severe
Updated on Sep 20, 2017

Microsoft Defender Antivirus detects and removes this threat.

The threat is a backdoor trojan that is related to the "trojanized" version of a third-party utility known as "CCleaner". If you have installed the infected or trojanized version of CCleaner, it's likely you'll have this threat detected on your machine.

Find out ways that malware can get on your PC.

Also detected as: Win32/CCleaner.A(ESET),W32/CCleaner.A!tr(Fortinet),Backdoor.CCleaner!1.A3B5 (CLOUD)(Rising AV)
Alert level: severe
Updated on Sep 20, 2017

Microsoft Defender Antivirus detects and removes this threat.

The threat is a backdoor trojan that is related to the "trojanized" version of a third-party utility known as "CCleaner". If you have installed the infected or trojanized version of CCleaner, it's likely you'll have this threat detected on your machine.

Find out ways that malware can get on your PC.

Also detected as: Win32/CCleaner.A(ESET),W32/CCleaner.A!tr(Fortinet),Trojan.CCleaner.2(Dr.Web)
Alert level: severe
Updated on Apr 11, 2011
Trojan:Win32/Emuni.A is a detection for a trojan component of the rogue Win32/Rudoct. The trojan terminates certain security-related processes.
Alert level: severe
Updated on Apr 11, 2011
Worm:BAT/Autorun.L is a destructive worm that spreads via logical drives and peer to peer networks. It terminates processes, mostly related to security programs. It also modifies a number of system settings. It also deletes certain files, such as MP3 files.
Alert level: severe
Updated on Aug 03, 2020
Alert level: severe
Updated on Apr 11, 2011
Win32/Mevon is a worm that spreads via mapped drives using the Autorun feature and via peer to peer file sharing networks.
Alert level: severe
Updated on Apr 11, 2011
Trojan:Win64/Emuni.A is a detection for a 64-bit trojan component of the rogue Win32/Rudoct. The trojan terminates certain security-related processes.
Alert level: severe
Updated on Sep 20, 2017

Microsoft Defender Antivirus detects and removes this threat.

The threat is a backdoor trojan that is related to the "trojanized" version of a third-party utility known as "CCleaner".

Find out ways that malware can get on your PC.

Alert level: severe
Updated on Jul 06, 2016

This application was stopped from running on your network because it has a poor reputation. This application can affect the quality of your computing experience. We have seen this leading to the following potentially unwanted behaviors on PCs:

  • Installs browser extensions

These applications are most commonly software bundlers or installers for applications such as toolbars, adware, or system optimizers. We have observed this application installing software that you might not have intended on your PC.

If you were trying to install an application, you might have downloaded it from a source other than the official product's website.

We usually see this application installed on PCs in the following countries. This list is sorted according to prevalence:

  • Germany
  • United States
  • Austria
  • Hungary
  • Switzerland

This detection is part of our extended Potentially Unwanted Application protection feature.

Alert level: severe
Updated on Jun 29, 2016

This application was stopped from running on your network because it has a poor reputation. This application can affect the quality of your computing experience. We have seen this leading to the following potentially unwanted behaviors on PCs:

  • Adds files that run at startup
  • Installs a driver
  • Injects into other processes on your system
  • Injects into browsers
  • Changes browser settings
  • Changes browser shortcuts
  • Installs browser extensions
  • Modifies your system DNS settings

These applications are most commonly software bundlers or installers for applications such as toolbars, adware, or system optimizers. We have observed this application installing software that you might not have intended on your PC.

If you were trying to install an application, you might have downloaded it from a source other than the official product's website.

We usually see this application installed on PCs in the following countries. This list is sorted according to prevalence:

  • Brazil
  • United States
  • Russia
  • Poland
  • France

This detection is part of our extended Potentially Unwanted Application protection feature.

Alert level: severe
Updated on Nov 23, 2023
Alert level: severe
Updated on Jul 03, 2023
Alert level: severe
Updated on Oct 09, 2013

Windows Defender detects and removes this threat.

Win32/Wecykler is a family of worms that spread via removable drives, such as USBs, that can stop security and other processes on your PC, and log keystrokes which can then be sent to a hacker.

Alert level: severe
Updated on Oct 09, 2013

Windows Defender detects and removes this threat.

Win32/Wecykler.A is a worm that spread via removable drives, such as USBs, that can stop security and other processes on your PC, and log keystrokes which can then be sent to a hacker.

Alert level: severe