Yandex flags a site for unwanted software when it finds dangerous or unwanted programs — or links to them — on its pages. The category covers outright malware and a second, larger group: software that is technically functional but installs or does things the user did not agree to.
What qualifies
- A page that launches a malicious script on open, or downloads a program to the device unexpectedly.
- A download that delivers an executable of a different format than advertised.
- Viruses and spyware hosted on the site.
- Programs that, once run, silently install additional software, use intrusive attention-grabbing techniques, or run hidden miners that consume the visitor’s device for cryptocurrency.
The part that applies to legitimate sites
Most of Yandex’s remediation guidance is not about removing malware — it is about how downloads are presented, which is where honest sites fail:
- Text describing a downloadable file must be prominent, large, readable and contrasting.
- The site must say what the file actually does.
- Where a file has several download options — the plain program, or a version bundled with extras — the user must be warned.
- If the download is an installer or downloader rather than the program itself, that must be stated clearly.
- Direct download buttons and links must be visibly distinguishable — which, read from the other direction, is a ruling on the decoy download button that is really an advert.
If you are flagged
- Remove the malicious fragments and the links to unwanted software.
- Scan the site with third-party antivirus and file-scanning services rather than trusting a visual inspection — injected code is normally obfuscated and placed in files nobody opens.
- Find the entry point before submitting for review. A cleaned site with an unpatched plugin is reinfected within days, and a failed re-review costs 30 days.
Third-party risk
A link to unwanted software is enough, which extends the exposure to user-generated content, comment spam, outdated advertising networks and any download mirror the site does not control. On sites accepting submissions, this is an ongoing moderation obligation rather than a one-off cleanup.
How we apply this
When a client is flagged here, we treat it as a security incident rather than an SEO ticket: find the entry point, patch it, rotate credentials, then clean. Cleaning first and investigating later is how sites get flagged twice, and the second flag costs a month of waiting before Yandex will even look again. On sites that host downloads legitimately, the fix is usually presentational — saying plainly that the file is an installer, and making the real download button the most obvious one on the page.
Related services