{"id":25607,"date":"2026-09-05T02:46:27","date_gmt":"2026-09-04T23:46:27","guid":{"rendered":"https:\/\/alienroad.com\/google-bilgi-bankasi\/malware-and-unwanted-software\/"},"modified":"2026-09-05T02:46:27","modified_gmt":"2026-09-04T23:46:27","slug":"malware-and-unwanted-software","status":"publish","type":"ar_kb","link":"https:\/\/alienroad.com\/google-bilgi-bankasi\/malware-and-unwanted-software\/","title":{"rendered":"Malware and unwanted software"},"content":{"rendered":"<p>Google checks websites to see whether they host software or downloadable executables that<br \/>\n  negatively affect the user experience. Malware and unwanted software are either downloadable<br \/>\n  binaries or applications that run on a website and affect site visitors. You can see a list of<br \/>\n  any suspected files hosted on your site in the<br \/>\n  <a href=\"https:\/\/support.google.com\/webmasters\/answer\/9044101\" class=\"external-link\">Security Issues<br \/>\n    report<\/a>.<\/p>\n<h2 id=\"what_is_malware\" tabindex=\"-1\">What is malware?<\/h2>\n<p>Malware is any software or mobile application specifically designed to harm a computer, a<br \/>\n  mobile device, the software it&#8217;s running, or its users. Malware exhibits malicious behavior<br \/>\n  that can include installing software without user consent and installing harmful software<br \/>\n  such as viruses. Website owners sometimes don&#8217;t realize that their downloadable files are<br \/>\n  considered malware, so these binaries might be hosted inadvertently.<\/p>\n<ul>\n<li>For more on how Google helps protect users from malicious downloads, see<br \/>\n    <a href=\"https:\/\/googleonlinesecurity.blogspot.com\/2011\/04\/protecting-users-from-malicious.html\" class=\"external-link\">Protecting<br \/>\n      users from malicious downloads<\/a> in our Google Online Security Blog.<\/li>\n<li>For our criteria for safe software on the web, see our <a href=\"https:\/\/www.google.com\/about\/unwanted-software-policy.html\" class=\"external-link\">Unwanted<br \/>\n    Software Policy<\/a>.<\/li>\n<\/ul>\n<h2 id=\"what-is-unwanted-software\" tabindex=\"-1\">What is unwanted software?<\/h2>\n<p>Unwanted software is an executable file or mobile application that engages in behavior that<br \/>\n  is deceptive, unexpected, or that negatively affects the user&#8217;s browsing or computing<br \/>\n  experience. Examples include software that switches your home page or other browser settings to<br \/>\n  ones you don&#8217;t want, or apps that leak private and personal information without proper<br \/>\n  disclosure.<\/p>\n<p>\n  For more on how Google helps protect users from unwanted software, see<br \/>\n  <a href=\"https:\/\/googleonlinesecurity.blogspot.com\/2014\/08\/thats-not-download-youre-looking-for.html\" class=\"external-link\">That&#8217;s not<br \/>\n    the download you&#8217;re looking for&#8230;<\/a> in our Google Online Security Blog.\n<\/p>\n<aside class=\"note\">\n  In the <a href=\"https:\/\/support.google.com\/webmasters\/answer\/9044101\" class=\"external-link\">Security Issues report<\/a>, &#8220;Malware&#8221; refers to web-based malware that operates without explicit user action.<br \/>\n  &#8220;Harmful downloads&#8221; refers to malware or unwanted software downloads that must be explicitly<br \/>\n  downloaded by the user.<br \/>\n<\/aside>\n<h2 id=\"fixing-the-problem\" tabindex=\"-1\">Fixing the problem<\/h2>\n<p>\n  Ensure that your site or application follows the <a href=\"#guidelines\">guidelines<\/a>, then<br \/>\n  you can request a review in the<br \/>\n  <a href=\"https:\/\/support.google.com\/webmasters\/answer\/9044101\" class=\"external-link\">Security Issues report<\/a>.\n<\/p>\n<p>\n  If your mobile application is showing warnings, you can<br \/>\n  <a href=\"https:\/\/support.google.com\/googleplay\/android-developer\/answer\/2992033\" class=\"external-link\">file an appeal<\/a>.\n<\/p>\n<h2 id=\"guidelines\" tabindex=\"-1\">Guidelines<\/h2>\n<p>Be sure that you don&#8217;t violate the <a href=\"https:\/\/www.google.com\/about\/company\/unwanted-software-policy.html\" class=\"external-link\">Unwanted<br \/>\n  Software Policy<\/a>, and follow the guidelines given here. Though this list isn&#8217;t comprehensive,<br \/>\n  these behaviors can cause apps and websites to display warnings to users upon downloading and<br \/>\n  visiting. You can see a list of any suspected files hosted on your site in the<br \/>\n  <a href=\"https:\/\/support.google.com\/webmasters\/answer\/9044101\" class=\"external-link\">Security Issues report<\/a>.<\/p>\n<h3 id=\"mobile-app-guidelines\" tabindex=\"-1\">Don&#8217;t misrepresent yourself<\/h3>\n<ul>\n<li><b>Accurately inform users of a software&#8217;s purpose and intent.<\/b> Users must be able to<br \/>\n    download the software intentionally, with accurate knowledge of what will be downloaded, by<br \/>\n    clicking on an accurate advertisement that clearly informs the user of what will be<br \/>\n    downloaded. Advertisements leading the user to the download must not be deceptive or<br \/>\n    inaccurate, such as:<\/p>\n<ul>\n<li>An ad that only contains the words &#8220;Download&#8221; or &#8220;Play&#8221; without identifying the software<br \/>\n        it advertises for.<\/li>\n<li>A &#8220;Play&#8221; button that leads to a download.<\/li>\n<li>An ad that mimics the look and feel of the publisher&#8217;s website and pretends to offer<br \/>\n        content (for example, a movie) but instead leads to unrelated software.<\/li>\n<li>Read about <a href=\"https:\/\/googleonlinesecurity.blogspot.com\/2015\/11\/safe-browsing-protection-from-even-more.html\" class=\"external-link\">Social<br \/>\n        Engineering<\/a> in our Online Security Blog.<\/li>\n<\/ul>\n<\/li>\n<li><b>Behave as advertised.<\/b> Make sure your program is clear about its<br \/>\n    functionality and intentions. If your program collects user data or injects ads into a<br \/>\n    user&#8217;s browser, package these behaviors in clear language and don&#8217;t frame them as insignificant<br \/>\n    features.<\/li>\n<li><b>Explicitly and clearly explain to the user what browser and system changes will<br \/>\n    be made by your software.<\/b> Allow users to review and approve all significant<br \/>\n    installation options and changes. Your program&#8217;s main UI must clearly disclose the binary&#8217;s<br \/>\n    components and their primary functionality. The binary must offer an easy way for the user<br \/>\n    to skip the installation of bundled components. For example, hiding these options or<br \/>\n    using barely visible text is not good disclosure.<\/li>\n<li><b>Use endorsements only when authorized.<\/b> Don&#8217;t use other companies&#8217; logos<br \/>\n    in an unauthorized way to legitimize or endorse a product. Don&#8217;t use government logos<br \/>\n    without authorization. <\/li>\n<li><b>Don&#8217;t scare the user.<\/b> Software must not misrepresent the state of the<br \/>\n    user&#8217;s machine to the user, for example by claiming the system is in a critical security<br \/>\n    state or infected with viruses. Software must not claim to provide a service (for example,<br \/>\n    &#8220;speed up your PC&#8221;) that it does not or cannot provide. For example, &#8220;free&#8221; computer<br \/>\n    cleaners and optimizers must not be advertised as such unless advertised services and<br \/>\n    components require no payment.<\/li>\n<\/ul>\n<h3 id=\"mobile-app-guidelines\" tabindex=\"-1\">Software guidelines<\/h3>\n<ul>\n<li><b>Use the Google Settings API if your program changes Chrome settings.<\/b><br \/>\n      Any changes to the user&#8217;s default search settings, startup page, or new tab page must be<br \/>\n      made using the <a href=\"https:\/\/developer.chrome.com\/docs\/extensions\/reference\/manifest\/chrome-settings-override\" class=\"external-link\">Chrome Settings Override API<\/a>,<br \/>\n      which requires the use of a Chrome extension, as well as compliant extension installation flow.<\/li>\n<li><b>Allow browser and operating system dialogues to alert the user as intended.<\/b><br \/>\n      Don&#8217;t suppress alerts to the user from the browser or from the operating system, notably<br \/>\n      those which inform the user of changes to their browser or OS. <\/li>\n<li><b>We recommend that you sign your code.<\/b> While an unsigned binary isn&#8217;t<br \/>\n      a reason for flagging your binary as unwanted software, we recommend programs have a valid<br \/>\n      and verified code signature issued by a code-signing authority that presents verifiable<br \/>\n      publisher information.<\/li>\n<li><b>Don&#8217;t degrade the security and protection measures provided by TLS\/SSL<br \/>\n      connections.<\/b> An application may not install a root certificate-authority<br \/>\n      certificate. It may not intercept SSL\/TLS connections unless designed for experts to debug<br \/>\n      or investigate software. For more details, see the related <a href=\"https:\/\/googleonlinesecurity.blogspot.com\/2015\/04\/beyond-annoyance-security-risks-of.html\" class=\"external-link\">Google<br \/>\n      Security Blog post.<\/a><\/li>\n<li><b>Protect user data.<\/b> Software, including mobile apps, must only transmit<br \/>\n      private user data to servers as it is related to the functionality of the app, and these<br \/>\n      transmissions must be both disclosed to the user and encrypted.<\/li>\n<li><b>Do no harm<\/b>. Your binary must respect and not harm the user&#8217;s browsing<br \/>\n      experience. Make sure that your downloadable binaries adhere to the following common policies:<\/p>\n<ul>\n<li><b>Don&#8217;t break the browser&#8217;s reset functionality<\/b>. Read about the<br \/>\n          <a href=\"https:\/\/chrome.blogspot.com\/2013\/10\/dont-mess-with-my-browser.html\" class=\"external-link\">reset<br \/>\n            browser settings<\/a> button in Chrome.<\/li>\n<li><b>Don&#8217;t bypass or suppress the browser&#8217;s or operating system&#8217;s UI control for<br \/>\n          setting changes<\/b>. Your program must provide users proper notice and control<br \/>\n          over settings changes that occur in the browser. Use the <a href=\"https:\/\/developer.chrome.com\/docs\/extensions\/reference\/manifest\/chrome-settings-override\" class=\"external-link\">Settings API<\/a><br \/>\n          to change Chrome settings (see this Chromium blog post about<br \/>\n          <a href=\"https:\/\/blog.chromium.org\/2014\/03\/protecting-user-settings-on-windows.html\" class=\"external-link\">protecting user settings on Windows with the new Settings API<\/a>).<\/li>\n<li><b>Use an extension to change Google Chrome functionality<\/b>, rather than<br \/>\n          causing browser behavior change through other programmatic means. For example, your<br \/>\n          program must not use DLLs (dynamically linked libraries) to inject ads in the browser,<br \/>\n          must not deploy proxies that intercept traffic, must not use a Layered Service<br \/>\n          Provider to intercept user actions, or insert new UI into every web page by patching<br \/>\n          the Chrome binary.<\/li>\n<li><b>Your product and component descriptions must not scare the user and\/or<br \/>\n          make false, misleading, claims.<\/b> For example, your product must not make<br \/>\n          false claims about how the system is in a critical security state or infected with<br \/>\n          viruses. Programs like registry cleaners must not show alarming messages about the<br \/>\n          state of a user&#8217;s computer or device, and claim they can optimize the user&#8217;s PC.<\/li>\n<li><b>Make the uninstallation process findable, simple, and non-threatening<\/b>.<br \/>\n          You program must have clearly-labeled instructions for returning the browser and\/or<br \/>\n          system to its previous settings. The uninstaller must remove <b>all<\/b><br \/>\n          components and not deter the user from continuing the uninstall process, for example<br \/>\n          by claiming potential negative effects on the user&#8217;s system or privacy if the software<br \/>\n          is uninstalled.<\/li>\n<\/ul>\n<\/li>\n<li><b>Keep good company.<\/b> If your software bundles other software components,<br \/>\n      you are responsible for making sure that none of these components violate any of the<br \/>\n      <a href=\"#guidelines\">recommendations<\/a>.<\/li>\n<\/ul>\n<h3 id=\"chrome-extension-guidelines\" tabindex=\"-1\">Chrome extension guidelines<\/h3>\n<ul>\n<li>\n    <b>All extensions need to be disclosed and installed in Chrome to be policy-compliant.<\/b><br \/>\n    Extensions must be hosted in the Chrome Web Store, disabled by default, and compliant with Chrome<br \/>\n    Web Store <a href=\"https:\/\/developer.chrome.com\/webstore\/program_policies\" class=\"external-link\">policies<\/a> (including<br \/>\n    the <a href=\"https:\/\/developer.chrome.com\/docs\/webstore\/program-policies\/quality-guidelines-faq\" class=\"external-link\">single-purpose policy<\/a>).<br \/>\n    Extensions installed from a program must use the<br \/>\n    <a href=\"https:\/\/developer.chrome.com\/docs\/extensions\/how-to\/distribute\/install-extensions\" class=\"external-link\">authorized Chrome Extensions installation flow<\/a>,<br \/>\n    which will prompt the user to enable them within Chrome. Extensions may not suppress Chrome<br \/>\n    dialogues alerting the user to settings changes.<br \/>\n    <img decoding=\"async\" alt=\"Chrome popup requesting approval to install an extension.\"\n          src=\"https:\/\/lh3.googleusercontent.com\/nJZpiAAdD4RV1H2Tr9Rg7u1N2stxKdGyfYvJBkdn-WvC0_MOVD_1MmEHof46GOEU3Qba=w361\" \/><\/li>\n<li>\n    <b>Instruct users on how to remove a Chrome Extension.<\/b> A good user experience is<br \/>\n    when a user uninstalls a program, everything that was installed along with it gets removed too.<br \/>\n    The uninstallation flow includes instructions for the user to disable and delete the<br \/>\n    extension themselves.<\/li>\n<li>\n    <b>If your binary installs a browser add-on or changes default browser settings, it must<br \/>\n      follow the browser-supported installation flow and API.<\/b> For example, if the binary<br \/>\n    installs a Chrome extension, it must be hosted in the Chrome Web Store and adhere to the Chrome<br \/>\n    <a href=\"https:\/\/developer.google.com\/chrome\/web-store\/program_policies\" class=\"external-link\">Developer Program Policies<\/a>.<br \/>\n    Your binary will be identified as malware if it installs a Chrome extension in violation of the<br \/>\n    <a href=\"https:\/\/developer.chrome.com\/extensions\/external_extensions\" class=\"external-link\">Chrome Alternative Extension Distribution Options policy<\/a>.<\/p>\n<ul>\n<li>\n        Read about <a href=\"https:\/\/blog.chromium.org\/2012\/12\/no-more-silent-extension-installs.html\" class=\"external-link\">silent installs<\/a><br \/>\n        in the Chromium Blog and in our<br \/>\n        <a href=\"https:\/\/googleonlinesecurity.blogspot.ru\/2013\/04\/new-warnings-about-potentially.html\" class=\"external-link\">Online Security Blog<\/a>.<\/li>\n<li>\n        Read <a href=\"https:\/\/blog.chromium.org\/2014\/02\/make-sure-to-get-your-extension-in.html\" class=\"external-link\">how to<br \/>\n        publish extensions in the Chrome Web Store<\/a>.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3 id=\"mobile-app-guidelines\" tabindex=\"-1\">Mobile application guidelines<\/h3>\n<ul>\n<li>\n<p><b>Inform users of your intent to collect their data.<\/b> Provide users an<br \/>\n      opportunity to agree to the collection of their data before you start collecting and sending<br \/>\n      it from the device, including data about third-party accounts, email, phone number,<br \/>\n      installed apps, and files on the mobile device. Make sure you securely handle any personal<br \/>\n      or sensitive user data that you collect, including being transmitted using modern cryptography (for<br \/>\n      example, over HTTPS). For non-Play apps, you must disclose your data collection to the<br \/>\n      user in the app. For Google Play apps, disclosure must adhere to Play <a href=\"https:\/\/play.google.com\/policy\" class=\"external-link\">policy<\/a>.<br \/>\n      Don&#8217;t collect data that goes beyond the published use of your application.<\/p>\n<\/li>\n<li>\n    <b>Don&#8217;t impersonate another brand or app.<\/b> Don&#8217;t use improper or unauthorized<br \/>\n      imagery or design similar to another brand or app in a way that is likely to confuse the<br \/>\n      user.\n    <\/li>\n<li>\n      <b>Keep all content within the context of the app.<\/b> Apps must not interfere<br \/>\n      with other apps and the usability of the device. Apps must not display ads or additional<br \/>\n      content to the user outside of the context or function of the app itself without getting<br \/>\n      informed consent from the user and including clear attribution of the ads&#8217; source wherever<br \/>\n      those ads appear.\n    <\/li>\n<li>\n      <b>The app must deliver on promises made to the user.<\/b> All advertised<br \/>\n      functionality must be available to the user in the app. Apps may update app content but<br \/>\n      must not download additional apps without getting informed consent from the user.\n    <\/li>\n<li>\n      <b>Keep behavior transparent.<\/b> Apps must not uninstall or replace other<br \/>\n      apps or their shortcuts, unless that is the app&#8217;s stated purpose. Uninstall must be<br \/>\n      clear and complete. Apps must not mimic prompts from the device OS or other apps.\n    <\/li>\n<\/ul>\n<p>Apps distributed through Google Play must comply with the <a href=\"https:\/\/play.google.com\/about\/developer-content-policy\/#!?modal_active=none\" class=\"external-link\">Developer<br \/>\n    Program Policies<\/a> and <a href=\"https:\/\/play.google.com\/intl\/ALL_us\/about\/developer-distribution-agreement.html\" class=\"external-link\">Developer<br \/>\n    Distribution Agreement<\/a>, which have additional requirements.<\/p>\n<section background=\"grey\" header-position=\"top\">\n<p>\n    If you&#8217;re a Search Console user and are having trouble with persistent or unfixable security issues on your site, you can let us know.\n      <\/p>\n<p align=\"center\"><a class=\"button button-primary\" href=\"https:\/\/support.google.com\/webmasters\/contact\/report_security_issues\" class=\"external-link\">Report a security issue<\/a><\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Google checks websites to see if they host unwanted software that negatively affects visitors. Explore this overview to learn more about malware.<\/p>\n","protected":false},"menu_order":134,"template":"","meta":{"footnotes":""},"ar_kb_kategori":[699],"ar_kb_etiket":[],"class_list":["post-25607","ar_kb","type-ar_kb","status-publish","has-post-thumbnail","hentry","ar_kb_kategori-preventing-and-monitoring-abuse"],"_links":{"self":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb\/25607","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb"}],"about":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/types\/ar_kb"}],"version-history":[{"count":0,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb\/25607\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/media\/27605"}],"wp:attachment":[{"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/media?parent=25607"}],"wp:term":[{"taxonomy":"ar_kb_kategori","embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb_kategori?post=25607"},{"taxonomy":"ar_kb_etiket","embeddable":true,"href":"https:\/\/alienroad.com\/wp-json\/wp\/v2\/ar_kb_etiket?post=25607"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}