Suspicious AntiVirus Alert Popped Up on Web Page

Anonymous
2013-05-11T03:08:31+00:00

I am suspicious about messages that popped up when I went to a web page I'd never been to before. First a message popped up stating "Microsoft Antivirus has found critical process activity on your PC. You need to clean your computer to prevent system breakage."  And then right afterwards another message appeared -- I might have pressed okay --  in a rectangular box with a thick red stripe across the top that read "Potential Threat Details," and then below "Microsoft Security Essentials detected potential threats that might compromise your privacy or damage your computer. You need to clean your computer immediately to prevent the system crash."  But I noticed that "might" was spelled "mihgt." Then below that it listed the threats as:

Trojan PSW.Win32Launch

HackTool:Win32/Welevate.A

Adward.Win32Fraud

It said each of the three was "critical" and "active" and recommended I "remove" them.

Then below all this was a box I could check that said "clean computer."

Now aside from the misspelling of "might," I do not have Microsoft Security Essentials; I have Windows Defender, so I'm pretty sure this is a fake alert.

And I didn't press "clean computer." But I'm wondering what would have happened if I had; would I have gotten a virus, or a sales pitch to buy more antivirus software? But mostly I want to know what really will happen when my antivirus program -- which, again, is Windows Defender for Windows 8 -- does detect a real virus. It hasn't happened yet so I don't know, and I also would like to be able to distinguish the real alerts from the fake ones, especially if the fake ones do not have misspelled words as a telling sign.

Thanks

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2013-05-11T09:37:27+00:00

It is a fake alert and creater of that alert can enter as many virus names as he/she can, don't worry about that alert. Just practice safe browsing, do not click on Ads (specially of unknown source), always use original software and download them from their genuine sites only. Run scans from the tools you downloaded, and use free version only (neither Pro nor Trial).

About Trojan in quarantine-

Items in quarantine are neutral and cannot harm your PC, just like criminals in jail. There is no need to delete items in quarantine. You can also run a full scan of your PC to ensure no virus is lurking in your PC.

Was this answer helpful?

60+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2013-05-13T15:28:33+00:00

As per your description above, except for the part... "it said it couldn't do much with that"... (Don't know what you mean by this?)

When someone tries to close AdwCleaner after clicking on 'Search' button then AdwCleaner alerts that it has only scanned for Adwares, not removed them and asks to click on 'Delete' button to complete removal. This is what he is trying to say.

Was this answer helpful?

20+ people found this answer helpful.
0 comments No comments

71 additional answers

Sort by: Newest
  1. Anonymous
    2013-05-11T08:56:08+00:00

    Thanks for your response.

    Actually, I ran Windows Defender and there was a quarantined item -- unfortunately, I deleted it so I can't give you its exact name, but it was a Trojan -- and the message said "severe." I also think it might have said the Trojan could allow others to take over my computer. But, again, while the alert from the web page gave three possible threats, Windows Defender quarantined only one. I deleted it. But now I'm wondering if the alert itself was a precursor to a virus, or a virus itself that needed me to press on more buttons for it to do damage.  I know almost nothing about viruses but am assuming, with the  little knowledge I have, that this is how they work.  

    I find it a bit frustrating, though, that after I deleted the Trojan there was no history left that recorded what was there -- something to refer back to. 

    I also don't understand why Windows Defender didn't alert me if it's running on real time. Why did I have to run it first to see something was quarantined? Does this mean the Trojan was doing damage before I ran Windows Defender? It looks like everything on my computer is okay, but I'm wondering if the person who put the virus on here could see what I had on my computer before I deleted the Trojan itself, and I'm also wondering if they could have already done damage to my computer that isn't obvious.  Actually, I did notice something I thought might be amiss on here but that was hours and hours before I received any alert: the desktop icon of a PDF food diary looked different from how it usually looks, but once I opened and closed it again, it looked the same so I forgot about it until now.

    But what's most confusing is why would a web page give this warning and then, right away, I happen to find a dangerous Trojan in my Windows Defender. I have never had a virus program quarantine or detect anything more dangerous that cookies.  Can it just be a strange coincidence, or was the fake alert -- again, if it was a fake alert -- the Trojan and it was waiting for me to activate it (I'm assuming this is how they work).  Could it be I was mistaken and the pop up message was not from a web page, but from Microsoft Security Essentials, as it claimed?

    Because at the risk of appearing totally ignorant, how can I tell if the alert was from a web page in the first place? I had assumed it was because when I pressed the X in the upper right hand corner of my computer another message popped up and asked if I wanted to "leave this page." 

    I'm sorry this is such a long post, but it was pretty scary to get a "severe" alert on my actual Windows Defender. Thanks again.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2013-05-11T06:24:05+00:00

    When Windows Defender will detect anything then a seperate windows will come, web browser will not contain any alert. You can open Windows Defender --> History and see all detected items there.

    If you see a virus alert in Web browser then ignore it, in fact, I think some Adware or toolbar you recently installed is causing this scam alert. Run scans with these softwares:

    1. Malwarebytes(Free)
    2. AdwCleaner
    3. SUPERAntiSpyware(Free)

    Was this answer helpful?

    0 comments No comments