Tue Sep 30, 2008 5:08PM EDT
See Comments (91)
WARNING: YOUR COMPUTER IS VULNERABLE! CLICK HERE TO PROTECT YOURSELF!
Ever seen a message like that? It probably looked just like any other pop-up your PC gives you when something isn't working right. But, as many have found out the hard way, such pop-ups are nothing but scams, designed to scare you into clicking on them and then tricking you into paying for the software to "fix" the "problems" it discovers.
In reality, when you click on these pop-ups, you're downloading malware that will be installed on your PC. The program then proceeds to pretend to scan your computer, subsequently alerting you to dozens or hundreds of problems it's found on your machine. The catch: If you want to fix those problems, you'll have to pay for the full version of the software. And if you do pay, all those problems will miraculously disappear! Gotcha!
The specific lawsuit in this case has been filed by Microsoft and Washington state against a number of companies (some of whom are still not even identified), but which include a Texas firm that sells a $40 application called Registry Cleaner XP. Microsoft continues to hammer out lawsuits against copycat companies, as allowed by the 2005 Computer Spyware Act, but tracking down defendants is difficult.
What should you do if you encounter a pop-up telling you about a security problem? Contrary to conventional wisdom, don't click on any close window buttons you see in the window. There's a good possibility that clicking that red X will actually start the software download. The way to reliably get rid of these pop-ups without risking clicking on them is to right-click on the appropriate item in the taskbar, then click Close. If that doesn't work, exit your web browser entirely through the File menu.
Another form of this pop-up ad attack uses Microsoft's Windows Messenger service to send ad messages, but this service was disabled beginning with Windows XP Service Pack 2. If for some reason you haven't upgraded, do so immediately. If you can't, disable the service manually by following these instructions.
Our team is on it and we should have everything back to normal shortly. Please come back soon.