Windows Defender alert--real or phony?

The machines we love to hate

Moderator: Wiz Feinberg

Post Reply
Brint Hannay
Posts: 3942
Joined: 23 Dec 2005 1:01 am
Location: Maryland, USA

Windows Defender alert--real or phony?

Post by Brint Hannay »

I just encountered a very real-looking "Windows Defender Security Center" alert claiming my computer is infected with 5 viruses. It alleges that my "anti-virus software subscription has expired." I have Trend Micro Maximum Security and, checking with the main TM console, it has NOT expired.

My understanding is that activating TM automatically disables Windows Defender, and I have checked and WD says it is disabled.

What am I to make of this? I am very skeptical, to put it mildly.

I attach a screenshot of the alert screen. I have not clicked on the "Renew Now" button!
Image
Mitch Drumm
Posts: 2664
Joined: 4 Aug 1998 11:00 pm
Location: Frostbite Falls, hard by Veronica Lake

Post by Mitch Drumm »

I say it's bogus.

Grammatical errors are a common indicator of a fake.

Windows is NOT capitalized where it should be if it were legitimately from Microsoft/Windows Defender.

Likewise, exclamation points to heighten your anxiety is another reason to question it!!!!!!!!

You'd think they'd have these "warnings" proofread by a native English speaker with some sense of proper usage, but they never seem to get to that point.

I'm willing to be proven wrong here, but I've got major doubts.
Brint Hannay
Posts: 3942
Joined: 23 Dec 2005 1:01 am
Location: Maryland, USA

Post by Brint Hannay »

Me too.
note url below. "securitys-shieldso"? and all that other stuff
http://windowsappcenter.securitys-shiel ... tron.space
Mitch Drumm
Posts: 2664
Joined: 4 Aug 1998 11:00 pm
Location: Frostbite Falls, hard by Veronica Lake

Post by Mitch Drumm »

Run some other stuff to see if you can find any malware.

Malwarebytes maybe.

Malwarebytes.org

https://www.eset.com/int/home/online-scanner/
Mitch Drumm
Posts: 2664
Joined: 4 Aug 1998 11:00 pm
Location: Frostbite Falls, hard by Veronica Lake

Post by Mitch Drumm »

Brint Hannay wrote:Me too.
note url below. "securitys-shieldso"? and all that other stuff
http://windowsappcenter.securitys-shiel ... tron.space
Yeah, even more bogus looking.
Brint Hannay
Posts: 3942
Joined: 23 Dec 2005 1:01 am
Location: Maryland, USA

Post by Brint Hannay »

I'm running TM full scan right now. I have MBAM paid version also, and will run that next.
User avatar
Wiz Feinberg
Posts: 6091
Joined: 8 Jan 1999 1:01 am
Location: Mid-Michigan, USA
Contact:

Post by Wiz Feinberg »

That pop-up is for what's known as a Fake Anti-Virus Alert. It is an ad to goad the unsuspecting user into paying to remove the listed viruses. The only virus is that program that launches the pop-up alert. Malwarebytes will find and terminate it. You will need to reboot and scan again to get all of it out.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Mitch Drumm
Posts: 2664
Joined: 4 Aug 1998 11:00 pm
Location: Frostbite Falls, hard by Veronica Lake

Post by Mitch Drumm »

I wouldn't be amused that the paid version of Malwarebytes apparently did not prevent it.
User avatar
Wiz Feinberg
Posts: 6091
Joined: 8 Jan 1999 1:01 am
Location: Mid-Michigan, USA
Contact:

Post by Wiz Feinberg »

Mitch Drumm wrote:I wouldn't be amused that the paid version of Malwarebytes apparently did not prevent it.
Some variants of these fake AV alerts are well disguised. In fact, there is a new trick being employed by scammers using Desktop Notifications over the System Tray to peddle crapware and fake security programs. This may even be one of those.

Desktop notifications can be disabled in your browser. It is an advanced option. You normally see a pop-up requesting permission to show these notifications. You can disallow them on a one to one basis, or all at once.

If it is just a browser pop-over alert, it is driven by JavaScript. Disabling JavaScript with the NoScript Add-on puts the kibosh on that crap. Blocking JavaScript is also an option with the uBlock Origin Add-on.
"Wiz" Feinberg, Moderator SGF Computers Forum
Security Consultant
Twitter: @Wizcrafts
Main web pages: Wiztunes Steel Guitar website | Wiz's Security Blog | My Webmaster Services | Wiz's Security Blog
Brint Hannay
Posts: 3942
Joined: 23 Dec 2005 1:01 am
Location: Maryland, USA

Post by Brint Hannay »

Thanks, Wiz. I have rebooted and run both MBAM and Trend Micro scans, and both came up with 0 threats detected.

I looked into the settings in Firefox (my browser), and found options relating to what they call "Web Push" notifications. Is that what you're referring to as desktop notifications?
Post Reply