DRIDEX..Malware detected – Error Code: DXRW2:#19X80XD e-mail scam: how to spot it and what to do
DRIDEX..Malware detected - Error Code: DXRW2:#19X80XD is a fake alert that can be hosted on numerous malicious websites. In most cases, users end up on these sites by accident, which adds to visitors' confusion and it is more likely to work.
Facts checked October 7, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation. Sections marked as our earlier report are the original text: they describe the threat as it was then and have not been reviewed since. The 2026 status, the removal steps and the questions are current.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Do it yourself · free Remove DRIDEX..Malware detected – Error Code: DXRW2:#19X80XD e-mail scam yourself 4 steps, about 12 minutes, no software needed.
Start the steps
DRIDEX..Malware detected – Error Code: DXRW2:#19X80XD e-mail scam: summary
| Damage | Fake messages usually aim for users to download potentially unwanted or malicious programs, steal their personal information or trick them into subscribing to useless services |
|---|---|
| Name | DRIDEX..Malware detected – Error Code: DXRW2:#19X80XD |
| Type | Scam, phishing, fraud, fake alert |
| Operation | Claims that Dridex Trojan has been detected on the system and provides a fake tech support number to allegedly fix the situation |
| Symptoms | A phishing e-mail asking you to sign in |
| Evidence | One write-up by a security site; details still limited |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 6 more facts
| Arrives as | |
|---|---|
| Pretends to be | Microsoft |
| Claim | Your account needs urgent attention |
| Asks for | Your password |
| First seen | 17 June 2022 |
| Facts checked | 7 October 2026 |
What the DRIDEX..Malware detected – Error Code: DXRW2:#19X80XD e-mail scam e-mail looks like
Windows Firewall Alert !!!
DRIDEX..Malware detected - Error Code: DXRW2:#19X80XD
Access to this PC has been disabled for security reasons.
Call Microsoft Helpline: +1 1300 720 905 (AU Tollfree)
Microsoft
Threat_Detected - DRIDEX Malware
App: keylogger.financetracer.exe
How to tell the DRIDEX..Malware detected – Error Code: DXRW2:#19X80XD e-mail scam e-mail is fake
From our report of Jun 2022 · not reviewed since
- If you can't close down the tab, open the task manager and shut down your browser's process.
- Pressing F11 can take you out of the full-screen mode if needed.
- Also, perform a full system scan with security software
- Cleaning web browsers is one of the secondary tasks you should do after PUP/malware removal to secure your privacy.
- can be a great help with this process
Is DRIDEX..Malware detected – Error Code: DXRW2:#19X80XD e-mail scam dangerous? What the senders want
From our report of Jun 2022 · not reviewed since
DRIDEX..Malware detected - Error Code: DXRW2:#19X80XD: a scam message you should ignore
DRIDEX..Malware detected - Error Code: DXRW2:#19X80XD is a fake alert that can be hosted on numerous malicious websites.
In most cases, users end up on these sites by accident, which adds to visitors' confusion and it is more likely to work. Besides, people are frightened of fake claims about virus infections, PC access being blocked, personal information being stolen, and similar misleading statements. Allegedly, the only way to prevent further damage, secure personal information, and fix the computer is by calling the tech support number.
Warning: If you have come across the DRIDEX..Malware detected - Error Code: DXRW2:#19X80XD scam, you should not interact with any of its components and, most importantly, do not call the fake support line, or you may lose money or have your system infected with malware.
Instead, follow the steps below to remediate the situation in the best possible way.
Dridex is a banking Trojan that has been infecting numerous organizations worldwide. Probably because of its notoriety, scammers decided to use this name. It is not the first time this has happened - they commonly use terms of widespread malware in scam schemes to frighten users (for example, Zeus or Emotet).
It is important to note that some scammers choose to simply fake the names of the allegedly found malware - for example, Tor.jack or Win Erx03. Regardless of which case is being used, you should never trust these messages as they are all fake.

From our report of Jun 2022 · not reviewed since
The scam message
There could be numerous websites that host DRIDEX..Malware detected - Error Code: DXRW2:#19X80XD scam message, for example operatingsystemkeyregistrationfailure.live.
Regardless of the website URL, the scam would always look the same for every user that accesses it.
Soon after entering the malicious page, users are presented with what looks like a security scan by Microsoft Defender - users are soon shown the detection pop-ups and other alarms. Several pop-ups show up during this time, and the very top message shows the following information:
It is important to note that Microsoft has nothing to do with this scam, and the page was fabricated - created by scammers who seek to trick users by using fake technical support messages.
Microsoft (or any other reputable company) would never provide contact information in their alerts. Also, no website can determine whether or not malware is installed on your system - only a dedicated anti-malware installed on your device is capable of that.
Never call the fake tech support numbers, as you may be fooled into allowing remote access to your machine. From there, crooks would show you even more "proof" that the system is infected and then misleadingly claim that they have taken care of the virus for you, demanding hundreds of dollars in return.

From our report of Jun 2022 · not reviewed since
Check your system thoroughly
Regardless of whether or not you called the fake tech support numbers or interacted with the DRIDEX..Malware detected - Error Code: DXRW2:#19X80XD scam in any way, we still recommend checking your device properly. If you have allowed remote access to your system or installed something from a malicious website, this step is especially important, as there is likely malware running on your system.
1. Exit the scam message page
First of all, if you are put into the full-screen after accessing the malicious page, you should simply press F11 to exit it easily. In some cases, scams may prevent you from exiting the page by clicking the X button - you can call up the Task Manager (Ctrl + Shift + Esc) and shut down the browser task there. Then, proceed with the steps below.
2. Scan with security software
The first step of ensuring that all the malicious programs are found and removed is scanning the system with reputable anti-malware, such as or . Unlike the fake scan generated via the website, security software can immediately determine whether or not your device is infected by Trojans, backdoors, adware, or other malware.
3. Remove unwanted extensions, apps, and clean browser caches
After the full system scan with the security application is performed, you can be sure that there is no malware running on your device. However, you could also check your device manually, just in case. If you are not sure, you can skip this process, although we strongly recommend you clean your browser caches regardless of which removal method you chose - can be used as an automatic option instead.
To find suspicious apps on your system, you should access the Control Panel and reach Apps & Features section:
Once the unwanted programs are gone, you should also remove unwanted browser extensions and clean caches.
Clean web data on Chrome:
Clean web data on Firefox:
MS Edge (Chromium)
Clean web data on MS Edge:
- Enter Control Panel into the Windows search box and hit Enter or click on the search result.
- Under Programs, select Uninstall a program.
- Here, you will find a list of installed apps on your system. Look for anything suspicious - media players, file converters, system optimizers, driver updaters, and similar. If you are not sure about what should and shouldn't be installed, you should simply skip this step.
- Right-click on the unwanted application and select Uninstall.
- When User Account Control shows up, click Yes.
- Wait till the uninstallation process is complete and click OK.
- Open Google Chrome, click on the Menu (three vertical dots at the top-right corner) and select More tools > Extensions.
- In the newly opened window, you will see all the installed extensions. Uninstall all the suspicious plugins that might be related to the unwanted program by clicking Remove.
- Click on Menu and pick Settings.
- Under Privacy and security, select Clear browsing data.
- Select Browsing history, Cookies and other site data, as well as Cached images and files.
- Click Clear data.
- Open Mozilla Firefox browser and click on the Menu (three horizontal lines at the top-right of the window).
- Select Add-ons.
- In here, select the unwanted plugin and click Remove.
- Click Menu and pick Options.
- Go to Privacy & Security section.
- Click on Clear Data...
- Select Cookies and Site Data, as well as Cached Web Content and press Clear.
- Open Edge and click select Settings > Extensions.
- Delete unwanted extensions by clicking Remove.
- Click on Menu and go to Settings.
- Select Privacy and services.
- Under Clear browsing data, pick Choose what to clear.
- Under Time range, pick All time.
- Select Clear now.
What to do after the DRIDEX..Malware detected – Error Code: DXRW2:#19X80XD e-mail
If you only received the message and clicked nothing, step 3 is all you need.
If you clicked the link or typed anything on the page it opened, do every step, starting with the password.
Step 1: Change the password you typed on the fake page
If you entered a password after clicking the link in the DRIDEX..Malware detected – Error Code: DXRW2:#19X80XD message, treat that account as known to the sender.
Open the provider's real site by typing its address yourself, not through any link in the e-mail, and change the password there. Choose a new one you have never used before, and change it on every other account that shared the old one.
Then use the option to sign out of all other sessions or devices, if the provider has one. This works the same in any browser on Windows 11 and Windows 10.

Microsoft account, Security page (account.microsoft.com/security): Change password. Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 2: Turn on two-step verification
Two-step verification asks for a code from your phone or an authenticator app whenever someone signs in from a new device. A stolen password alone is then not enough to open the mailbox.
Turn it on in the security settings of the e-mail account first, then for the bank, shop and social accounts that send their reset links to that address.
While you are there, check the recovery e-mail and phone number and the forwarding rules, which attackers sometimes change to keep access. The settings pages look the same on Windows 11 and Windows 10.

Microsoft account: Manage how I sign in, where two-step verification and the sign-in methods are. Full procedure with screenshots: Turn on two-step verification / secure a hacked account
Step 3: Report the e-mail and delete it
Report the message instead of only deleting it. In Outlook choose Report > Report phishing, in Gmail the three-dot menu > Report phishing; the provider then blocks the same message for other people.
Do not reply and do not click anything else in it. On a work account, forward it to your IT team as an attachment first. Web mail and the mail apps on Windows 11 and Windows 10 offer the same options.

New Outlook for Windows and Outlook on the web: Report > Report phishing. Full procedure with screenshots: Report a phishing e-mail
Step 4: Scan the PC if you opened a file from the message
A page that only asked for a password installs nothing, so most readers can skip this step.
If the DRIDEX..Malware detected – Error Code: DXRW2:#19X80XD e-mail or the page it opened made you download or open a file, delete it and run a full scan, then a Microsoft Defender Offline scan.
In Windows 11 and Windows 10 open Windows Security > Virus & threat protection > Scan options, select Microsoft Defender Antivirus (offline scan) and click Scan now. The PC restarts and the scan takes about 15 minutes, so save your work first.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Stream videos without limitations, no matter where you are
There are multiple parties that could find out almost anything about you by checking your online activity.
While this is highly unlikely, advertisers and tech companies are constantly tracking you online. The first step to privacy should be a secure browser that focuses on tracker reduction to a minimum.
Even if you employ a secure browser, you will not be able to access websites that are restricted due to local government laws or other reasons. In other words, you may not be able to stream Disney+ or US-based Netflix in some countries. To bypass these restrictions, you can employ a powerful VPN, which provides dedicated servers for torrenting and streaming, not slowing you down in the process.
Data backups are important - recover your lost files
Ransomware is one of the biggest threats to personal data.
Once it is executed on a machine, it launches a sophisticated encryption algorithm that locks all your files, although it does not destroy them. The most common misconception is that anti-malware software can return files to their previous states. This is not true, however, and data remains locked after the malicious payload is deleted.
While regular data backups are the only secure method to recover your files after a ransomware attack, tools such as can also be effective and restore at least some of your lost data.
Questions about DRIDEX..Malware detected – Error Code: DXRW2:#19X80XD e-mail scam
Does getting "Windows Firewall Alert !!!" mean my account was compromised?
Not by itself. Phishing waves are sent to long lists of addresses collected from old breaches, websites and guessing, and the sender does not know whether you even have the account the message mentions. Getting "Windows Firewall Alert !!!" only means your address is on such a list.
It becomes a problem if you sign in through the link. To be sure, open the real service from a bookmark and check recent activity and security alerts. If you see nothing unusual and you did not type your password into the fake page, your account is fine.
The "Windows Firewall Alert !!!" page asked for my code too. Is two-step verification enough?
Not when you typed the code yourself. Some phishing pages pass your password and the one-time code to the real site in real time, which lets the attacker sign in once. Change the password immediately, then sign out of all sessions so the stolen session ends.
Check the account's security page for new devices, app passwords and recovery details, and remove anything you did not add. A passkey or a hardware key is the strongest protection against this trick, because it cannot be typed into a fake page. Keep the e-mail "Windows Firewall Alert !!!" for your report, then delete it.
Is DRIDEX..Malware detected – Error Code: DXRW2:#19X80XD really from Microsoft?
No. It is sent by scammers who copy the name and look of Microsoft. The sender address and the links do not belong to it, and the message asks for your password, which a real company does not request through an unexpected message.
If you want to be sure about your account, open the website or app of Microsoft the way you normally do, not through the message, and look for notices there. Then delete the message and report it as phishing. If you already followed its instructions, use the steps in this guide for your case.
Is it true that your account needs urgent attention?
No. The claim that your account needs urgent attention is the hook of DRIDEX..Malware detected – Error Code: DXRW2:#19X80XD, invented to give you a reason to act quickly. Scammers pick a story that could plausibly apply to many people, so it may feel relevant to you, but nothing in the message is based on your real accounts or devices.
If the claim concerns a service you use, check it there directly, by opening the website or app yourself. You will find no such problem. Then delete the message and report it as phishing.
What happens if I do what DRIDEX..Malware detected – Error Code: DXRW2:#19X80XD asks?
The scammers get your password, and they use it quickly. Passwords are tried on the real service within minutes, cards are charged or added to phone wallets, remote access is used to open your bank, and crypto is moved on at once.
Documents surface later as accounts in your name. If you already did what the message asked, do not wait to see what happens; follow the steps in this guide for your case today. Speed matters more than anything else here.
Will Microsoft refund me if I fell for DRIDEX..Malware detected – Error Code: DXRW2:#19X80XD?
Microsoft did not send the message and is not responsible for it, so a refund usually comes from your bank or card issuer, not from the brand. Call the bank first if you paid.
It still helps to tell the real company: they can secure your account, add notes for their fraud team and take down pages that use their name. Contact them through their official website or app only, never through the message or a search ad. Keep the message as evidence.
Can just reading DRIDEX..Malware detected – Error Code: DXRW2:#19X80XD harm my PC?
No. Reading the e-mail does nothing to the PC. The risk lies in what the message wants you to do: your password. Every one of those needs an action from you, such as a click, a typed password, a payment or a call.
If you stopped at reading, you are fine. Delete it and report it. If you are unsure whether you clicked something, check your browser history for the time you read the message, and act on what you find there.
Should I reply or unsubscribe?
No. A reply confirms that your address is active and read, which leads to more scams. The unsubscribe link in a scam message is part of the scam and may lead to a phishing page. Mark the message as spam or phishing and delete it.
Block the sender if your mail app allows it, though scammers change addresses often. If the scam came by text message, do not reply STOP either. If it came through social media, use the platform's report function and block the account.
How quickly do scammers use a phished password?
Often within minutes. Phishing kits send each password to the operators as soon as it is typed, and many test it automatically on the real service. Some kits also pass the two-step code through in real time.
That is why the first hour matters: change the password, end all sessions and check that the recovery details are still yours. If nothing has changed by then, you were probably fast enough, but keep watching for login alerts and password-reset e-mails for a few weeks.
Will Fortect remove DRIDEX..Malware detected – Error Code: DXRW2:#19X80XD?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For DRIDEX..Malware detected – Error Code: DXRW2:#19X80XD, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- FTC: How to recognize and avoid phishing scams (read October 7, 2026)
- CISA: Recognize and report phishing (read October 7, 2026)
- Microsoft Support: Protect yourself from phishing (read October 7, 2026)
- NCSC: Phishing attacks, dealing with suspicious e-mails and messages (read October 7, 2026)
- FTC: How to recognize, remove and avoid malware (read October 7, 2026)