We have had 4 laptops come in with the same virus. It is the Win32/FakeRean. Forefront Security Client picks it up and shows it in History as being found. Meanwhile, the virus is still running. Forefront is not automatically removing it. Is there a setting
we are missing to remove the virus automatically?
Win32/FakeRean is a active malware and more difficult to remove. If you could obtain the malware sample, please
submit it to MMPC.
Meanwhile, I recommend you use
Microsoft Safety Scanner and
MSRT(Malicious software removal tool) to full scan your system. Check the Prevention and Recovery(KB2656106) according to the
Win32/FakeRean Encyclopedia page.
If there are more inquiries on this issue, please feel free to let us know.
Microsoft is conducting an online survey to understand your opinion of the Technet Web site. If you choose to participate, the online survey will be presented to you when you leave the Technet Web site.