Sideloaded repair prompts are back in desktop installer lures

In February 2026 the Removal Bits desk logged a fresh cluster of desktop installer lures that open a fake repair prompt. The window copies the layout of a Windows troubleshooter, then asks the user to sideload a helper package so the scan can finish. Nothing in that prompt is signed by the operating system. The package is a packed dropper that writes a scheduled task and a lookalike service name.

Abstract console and lock graphic for a fake repair prompt

The lure usually arrives as a zip next to a PDF invoice or a browser download named like a cumulative update. Once the helper runs, it plants a second executable under a user AppData folder and names it close to a real maintenance tool. Task Manager then shows a process that looks routine. That is the point. People close the window and keep working.

If you already clicked through, disconnect the session that downloaded the zip, then inspect Startup and Task Scheduler before you delete files at random. Note the full path of the helper, not only the process title. Our malware-removal walkthroughs still apply: quarantine the dropper, drop the scheduled task, then scan leftover DLLs that share the same timestamp.

We are not seeing a new ransomware family in this wave. The operators want a quiet foothold and a later browser-helper install. Treat any repair prompt that asks you to sideload a package as hostile, even when the wording mentions a familiar vendor. Keep the original zip if you need to compare hashes later. Write to the contact desk with the filename if the sample is not already in the Files section.

Information added: February 2026;