Suspicious AntiVirus Alert Popped Up on Web Page

Anonymous
2013-05-11T03:08:31+00:00

I am suspicious about messages that popped up when I went to a web page I'd never been to before. First a message popped up stating "Microsoft Antivirus has found critical process activity on your PC. You need to clean your computer to prevent system breakage."  And then right afterwards another message appeared -- I might have pressed okay --  in a rectangular box with a thick red stripe across the top that read "Potential Threat Details," and then below "Microsoft Security Essentials detected potential threats that might compromise your privacy or damage your computer. You need to clean your computer immediately to prevent the system crash."  But I noticed that "might" was spelled "mihgt." Then below that it listed the threats as:

Trojan PSW.Win32Launch

HackTool:Win32/Welevate.A

Adward.Win32Fraud

It said each of the three was "critical" and "active" and recommended I "remove" them.

Then below all this was a box I could check that said "clean computer."

Now aside from the misspelling of "might," I do not have Microsoft Security Essentials; I have Windows Defender, so I'm pretty sure this is a fake alert.

And I didn't press "clean computer." But I'm wondering what would have happened if I had; would I have gotten a virus, or a sales pitch to buy more antivirus software? But mostly I want to know what really will happen when my antivirus program -- which, again, is Windows Defender for Windows 8 -- does detect a real virus. It hasn't happened yet so I don't know, and I also would like to be able to distinguish the real alerts from the fake ones, especially if the fake ones do not have misspelled words as a telling sign.

Thanks

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2013-05-11T09:37:27+00:00

It is a fake alert and creater of that alert can enter as many virus names as he/she can, don't worry about that alert. Just practice safe browsing, do not click on Ads (specially of unknown source), always use original software and download them from their genuine sites only. Run scans from the tools you downloaded, and use free version only (neither Pro nor Trial).

About Trojan in quarantine-

Items in quarantine are neutral and cannot harm your PC, just like criminals in jail. There is no need to delete items in quarantine. You can also run a full scan of your PC to ensure no virus is lurking in your PC.

Was this answer helpful?

60+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2013-05-13T15:28:33+00:00

As per your description above, except for the part... "it said it couldn't do much with that"... (Don't know what you mean by this?)

When someone tries to close AdwCleaner after clicking on 'Search' button then AdwCleaner alerts that it has only scanned for Adwares, not removed them and asks to click on 'Delete' button to complete removal. This is what he is trying to say.

Was this answer helpful?

20+ people found this answer helpful.
0 comments No comments

71 additional answers

Sort by: Newest
  1. Anonymous
    2013-05-11T11:47:35+00:00

    Thanks for all that information and the several links. I'll know for the future not to close a web page with a virus alert, but to shut down the whole computer instead. I will read the link on how Windows Defender should work, but, in general, shouldn't any antivirus program running on real time alert someone if they have a Trojan instead of waiting to have them scan the computer and only then show that a threat has been quarantined? And I had to click on "History" myself in the Windows Defender box to see that possible threat; that is, even after I ran Windows Defender and it had quarantined a threat nothing popped up -- I had to look for it.

    And do you know if I find a Trojan quarantined AFTER I run Windows Defender if it could have done damage before, even if just allowing the Trojan creator to view files on my computer?

    Finally, I ran all three antivirus program for which PrashantKumar96kindly provided links and all of them gave my computer a clean bill of health virus-wise, but Adwcleaner, which seems to be more than an antivirus program, did find 12 stability issues and 134 registry issues on my computer and asked if I wanted to repair them by using files from its own database. It also stated my Windows Damage Severity was "Medium."  I actually clicked "yes" because I trust the program, but at that point it asked for $69 for a year's use. I haven't gone further. I'm assuming it's not necessary since I do not have any viruses on my computer according to all three programs plus my Windows Defender.  And I'm also assuming, it may be I set up the registry to be a certain way and want it that way so that "correcting" it may not be good at all. But, again, I don't know.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2013-05-11T10:53:39+00:00

    Adding to the good advice provided by PrashantKumar96:...

    +++++++++++++++++++++++++++++++++++

    Recommend you thoroughly review Windows Defender on Windows 8 - Introduction and Frequently Asked Questions

    You can verify that Windows Defender is working by checking it with Eicar if you wish to do so: http://www.rexswain.com/eicar.html

    The fake warnings you are (justifiably) concerned about usually appear in the middle of the screen and may take you to a different screen.  The fake alerts warn you of an an infection of multiple items and advise you to download some other software (which would be the actual malware) to "clean" or scan the PC or provide a link for you to pay something to protect the PC.

    See http://www.microsoft.com/security/pc-security/antivirus-rogue.aspx

    Here's a comprehensive list of suggestions on handling such "attacks" by Stephen Boots, MSE Forum Moderator:

    Unfortunately, these type of malware attacks are difficult to keep up with because they trick you into letting them install. They usually come from an infected web site, and usually through an advertisement. You get a pop-up from the infection and you click it to close the pop-up - which allows the infection to install.  They can also be delivered in a "drive-by" fashion with no action needed by the user due to the system being unpatched, no matter what security software is running.

    When you encounter one of these fake virus pop-ups while browsing, immediately do the following:

    -Do not touch any browser window to close it or browse further.

    -Immediately press Ctrl-Shift-Esc and bring up Task Manager and forcibly end all instances of iexplore.exe, if using Internet Explorer, or the executable for the browser you are using.

    --or--

    -Go to Start/Shut Down and restart the PC without touching any browser windows.

    -If you used task manager to close browser instances, reboot the machine.

    -Then go to Control Panel/Internet Options and delete all temporary Internet Files and cookies. If you are using an alternate web browser, open the browser settings to do the same - delete the local cached files and cookies.

    -Perform a full scan with your antimalware program.

    And see the following compliments of PA Bear:

    Fake => http://blogs.technet.com/b/mmpc/archive/2010/11/09/msrt-tackles-fake-microsoft-security-essentials.aspx

    Remember no antimalware program provides 100% protection.

    http://voices.washingtonpost.com/securityfix/2009/09/what\_to\_do\_when\_rogue\_anti-vir.html#more

    http://ask-leo.com/why\_dont\_antimalware\_tools\_work\_better.html

    Regards...

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2013-05-11T10:01:35+00:00

    Thanks. I am running all the scans for which you provided links -- right now the Malwarebytes. But I am wondering if whoever put this here was able to look at information on my computer.  Maybe I'm not understanding your answer: I know the Trojan was quarantined but was that after or before I ran Windows Defender and could it have had access to my computer before it was quarantined and/or I deleted it?

    I did join, well half-join, a site yesterday -- a well respected site -- that helps people find nannies and caretakers, and I gave them my email. After only a few minutes, a slew of replies arrived to my ad and I opened each one, which had a picture of the nanny and her information. I'm wondering if that's what harmed my computer. Maybe a "prospective" nanny also wants to hack into people's computers and that's why they joined the site.

    And when you write "Do not click on Ads, especially of an unknown source," do you also mean any links at all, including links I might find on someone's Facebook page that aren't even ads, just stories or videos?

    Malwarebytes found nothing, and I see you said I should only run a free version, not a trial, but I think SuperantiSpyware may be both a "free" and "trial" version. I'm running it now.

    Was this answer helpful?

    0 comments No comments