Suspicious AntiVirus Alert Popped Up on Web Page

Anonymous
2013-05-11T03:08:31+00:00

I am suspicious about messages that popped up when I went to a web page I'd never been to before. First a message popped up stating "Microsoft Antivirus has found critical process activity on your PC. You need to clean your computer to prevent system breakage."  And then right afterwards another message appeared -- I might have pressed okay --  in a rectangular box with a thick red stripe across the top that read "Potential Threat Details," and then below "Microsoft Security Essentials detected potential threats that might compromise your privacy or damage your computer. You need to clean your computer immediately to prevent the system crash."  But I noticed that "might" was spelled "mihgt." Then below that it listed the threats as:

Trojan PSW.Win32Launch

HackTool:Win32/Welevate.A

Adward.Win32Fraud

It said each of the three was "critical" and "active" and recommended I "remove" them.

Then below all this was a box I could check that said "clean computer."

Now aside from the misspelling of "might," I do not have Microsoft Security Essentials; I have Windows Defender, so I'm pretty sure this is a fake alert.

And I didn't press "clean computer." But I'm wondering what would have happened if I had; would I have gotten a virus, or a sales pitch to buy more antivirus software? But mostly I want to know what really will happen when my antivirus program -- which, again, is Windows Defender for Windows 8 -- does detect a real virus. It hasn't happened yet so I don't know, and I also would like to be able to distinguish the real alerts from the fake ones, especially if the fake ones do not have misspelled words as a telling sign.

Thanks

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2013-05-11T09:37:27+00:00

It is a fake alert and creater of that alert can enter as many virus names as he/she can, don't worry about that alert. Just practice safe browsing, do not click on Ads (specially of unknown source), always use original software and download them from their genuine sites only. Run scans from the tools you downloaded, and use free version only (neither Pro nor Trial).

About Trojan in quarantine-

Items in quarantine are neutral and cannot harm your PC, just like criminals in jail. There is no need to delete items in quarantine. You can also run a full scan of your PC to ensure no virus is lurking in your PC.

Was this answer helpful?

60+ people found this answer helpful.
0 comments No comments
Answer accepted by question author
Anonymous
2013-05-13T15:28:33+00:00

As per your description above, except for the part... "it said it couldn't do much with that"... (Don't know what you mean by this?)

When someone tries to close AdwCleaner after clicking on 'Search' button then AdwCleaner alerts that it has only scanned for Adwares, not removed them and asks to click on 'Delete' button to complete removal. This is what he is trying to say.

Was this answer helpful?

20+ people found this answer helpful.
0 comments No comments

71 additional answers

Sort by: Most helpful
  1. Anonymous
    2013-05-11T12:16:38+00:00

    WD quarantined the malware without notifying you.  It did what it was supposed to do...it took the appropriate actions to protect your computer.

    http://www.thethinkingblog.com/2008/06/malware-difference-between-quarantine.html

    The trojans that are not identified as malware are the ones that may cause problems...not the ones identified and quarantined/removed by antimalware programs.

    http://www.microsoft.com/security/portal/default.aspx  and be sure you review http://www.microsoft.com/security/portal/shared/help.aspx

    We don't recommend the use of registry cleaners (No, not even the registry cleaner pushed by ADWCleaner) on this forum.  Their adware removal program is good however.

    http://support.microsoft.com/kb/2563254

    http://www.edbott.com/weblog/2005/04/why-i-dont-use-registry-cleaners/

    http://en.wikipedia.org/wiki/Registry\_cleaner

    Regards...

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2013-05-11T11:47:35+00:00

    Thanks for all that information and the several links. I'll know for the future not to close a web page with a virus alert, but to shut down the whole computer instead. I will read the link on how Windows Defender should work, but, in general, shouldn't any antivirus program running on real time alert someone if they have a Trojan instead of waiting to have them scan the computer and only then show that a threat has been quarantined? And I had to click on "History" myself in the Windows Defender box to see that possible threat; that is, even after I ran Windows Defender and it had quarantined a threat nothing popped up -- I had to look for it.

    And do you know if I find a Trojan quarantined AFTER I run Windows Defender if it could have done damage before, even if just allowing the Trojan creator to view files on my computer?

    Finally, I ran all three antivirus program for which PrashantKumar96kindly provided links and all of them gave my computer a clean bill of health virus-wise, but Adwcleaner, which seems to be more than an antivirus program, did find 12 stability issues and 134 registry issues on my computer and asked if I wanted to repair them by using files from its own database. It also stated my Windows Damage Severity was "Medium."  I actually clicked "yes" because I trust the program, but at that point it asked for $69 for a year's use. I haven't gone further. I'm assuming it's not necessary since I do not have any viruses on my computer according to all three programs plus my Windows Defender.  And I'm also assuming, it may be I set up the registry to be a certain way and want it that way so that "correcting" it may not be good at all. But, again, I don't know.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2013-05-11T10:53:39+00:00

    Adding to the good advice provided by PrashantKumar96:...

    +++++++++++++++++++++++++++++++++++

    Recommend you thoroughly review Windows Defender on Windows 8 - Introduction and Frequently Asked Questions

    You can verify that Windows Defender is working by checking it with Eicar if you wish to do so: http://www.rexswain.com/eicar.html

    The fake warnings you are (justifiably) concerned about usually appear in the middle of the screen and may take you to a different screen.  The fake alerts warn you of an an infection of multiple items and advise you to download some other software (which would be the actual malware) to "clean" or scan the PC or provide a link for you to pay something to protect the PC.

    See http://www.microsoft.com/security/pc-security/antivirus-rogue.aspx

    Here's a comprehensive list of suggestions on handling such "attacks" by Stephen Boots, MSE Forum Moderator:

    Unfortunately, these type of malware attacks are difficult to keep up with because they trick you into letting them install. They usually come from an infected web site, and usually through an advertisement. You get a pop-up from the infection and you click it to close the pop-up - which allows the infection to install.  They can also be delivered in a "drive-by" fashion with no action needed by the user due to the system being unpatched, no matter what security software is running.

    When you encounter one of these fake virus pop-ups while browsing, immediately do the following:

    -Do not touch any browser window to close it or browse further.

    -Immediately press Ctrl-Shift-Esc and bring up Task Manager and forcibly end all instances of iexplore.exe, if using Internet Explorer, or the executable for the browser you are using.

    --or--

    -Go to Start/Shut Down and restart the PC without touching any browser windows.

    -If you used task manager to close browser instances, reboot the machine.

    -Then go to Control Panel/Internet Options and delete all temporary Internet Files and cookies. If you are using an alternate web browser, open the browser settings to do the same - delete the local cached files and cookies.

    -Perform a full scan with your antimalware program.

    And see the following compliments of PA Bear:

    Fake => http://blogs.technet.com/b/mmpc/archive/2010/11/09/msrt-tackles-fake-microsoft-security-essentials.aspx

    Remember no antimalware program provides 100% protection.

    http://voices.washingtonpost.com/securityfix/2009/09/what\_to\_do\_when\_rogue\_anti-vir.html#more

    http://ask-leo.com/why\_dont\_antimalware\_tools\_work\_better.html

    Regards...

    Was this answer helpful?

    0 comments No comments