Rogue security software, also known as scareware or fake antivirus, is malicious software that masquerades as legitimate security software. It uses fear, intimidation, and deception to trick users into believing their system is infected, then demands payment for fake "removal" of non-existent threats.
Financial Impact: Rogue security software scams have defrauded victims of an estimated $400 million annually, with elderly and less tech-savvy users being primary targets.
Key characteristics of rogue security software:
Displays persistent pop-up warnings claiming the system is infected. Alerts often mimic legitimate Windows security messages.
Runs simulated system scans that always detect multiple threats, regardless of actual system health.
Redirects browsers to fake security pages and prevents access to legitimate security sites.
Creates urgency through fear, time pressure, and authority claims to manipulate victims into paying.
Packaged with free software downloads, often installed without clear disclosure during installation.
Blocks legitimate programs, prevents task manager access, and disables real security software.
One of the earliest and most widespread rogue antivirus programs. Displayed fake XP security alerts and demanded payment for removal.
Aggressive rogue that locked browsers and displayed persistent pop-ups. Used names to appear legitimate.
Fake system optimizer that claimed to fix registry errors. Distributed through deceptive advertisements and bundled software.
Rogue that displayed fake registry errors and system crashes. Required payment to "repair" non-existent problems.
Family of rogues that mimicked legitimate security software interfaces. Spread through malicious ads and fake download sites.
Rogue that displayed continuous security warnings and prevented access to legitimate security websites.
Fake system optimization tool that claimed to find hundreds of errors requiring paid cleanup.
Aggressive rogue that hijacked browsers, displayed fake BSOD warnings, and demanded payment.
| Characteristic | Legitimate Security Software | Rogue Security Software |
|---|---|---|
| Characteristic | Legitimate Security Software | Rogue Security Software |
| Pricing | Transparent, upfront pricing | Hidden fees, escalating demands |
| Scanning | Thorough, accurate detection | Fake scan results, inflated threat counts |
| Reviews | Verified by independent labs (AV-TEST, etc.) | No independent verification, fake reviews |
| Uninstall | Standard uninstall process | Resists uninstallation, may require special tools |
| Pop-ups | Occasional, non-intrusive notifications | Aggressive, constant pop-ups and fake warnings |
| Support | Professional customer support channels | Limited or non-existent support |
| Updates | Regular signature and engine updates | No real updates, may download more malware |
Only download security software from the official vendor website or trusted app stores. Avoid third-party download sites.
Search for reviews from reputable tech sites and independent testing labs like AV-TEST, AV-Comparatives, or SE Labs.
Never trust browser pop-ups claiming your system is infected. Close them and run a scan with your actual security software.
Windows Defender and built-in macOS security are sufficient for most users. Keep your OS and browser updated.
Install a reputable ad blocker like uBlock Origin to prevent malicious ads that promote rogue security software.
If infected, use legitimate tools like Malwarebytes, AdwCleaner, or Microsoft Safety Scanner to remove rogue software.
Excellent for detecting and removing rogue security software and PUPs.
Independent testing lab — verify any security product before installing.
Free, on-demand scanner from Microsoft for removing malware.
Free tool specifically for removing adware and potentially unwanted programs.