BitShop, Inc.
Ashburn, VA
(703) 940-6703
Fax:
(703) 563-3826

EMail Us
 

 
Our Blogs
 
Loading BitShop News...
   
 
Morals
 

BitShop abides by: the Rotary International Four Way Test - Find out what that means..

   
 
NEXT STEP
 

To navigate our site click the menu at the top.

   
 
Non-BitShop Ads (Hold Control when you click)
 
Feb28

Written by:Steve Radich - Founder BitShop, Inc.
2/28/2010 1:44 PM 

So today I log into my computer and see the following message come in via Skype:

[9:59:17 AM] Update Registry: WINDOWS REQUIRES IMMEDIATE ATTENTION
URGENT SYSTEM SCAN NOTIFICATION ! PLEASE READ CAREFULLY !!

Is this a scam? Does Microsoft post via Skype to the world? No, they don't..

The full message is at the end of this post for reference.

So how do I know this is a scam? Well the most immediate sign is knowledge of updatingmy computer - That's why I wanted to share this - All too often users are convinced to just click something and install it, and that something turns out to be a virus they install.

Next year ago, after numerous people (myself included) pointed out to Microsoft that malware was using exact copies of their security bulletins with links changed they started signing their security notices. You'll notice their emails start like:

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA256

 

and have and a bunch of random looking junk (a signature) on them

-----BEGIN PGP SIGNATURE-----

 

If you take the time you can compare that signature using PGP, personally I just read the message and can figure out if it's real or not from doing this stuff since the stone ages..

 

Microsoft is *NEVER* going to release an update via Skype or some non-Microsoft web site to avoid users being confused and clicking something that is a virus.

 

So what do you do about this message? Block the sender in Skype may be a good idea..  Ignore it is an option. 

Unfortunately we live in a world where there are scam artists trying to attack us on every front, agressive marketers calling us on the phone, people out on street corners raising funds for organizations that aren't legitimate, and many more attempts to cause us headaches. It's hard to know who to trust, but the legitimate Microsoft bullets are almost exclusively on the second Tuesday of each month (there are sometimes out fo band updates, but those are rare).

 

Good luck, and MAKE SURE you do not click the URL (I have removed it from being a link).

 

Full Message:

[9:59:17 AM] Update Registry: WINDOWS REQUIRES IMMEDIATE ATTENTION
URGENT SYSTEM SCAN NOTIFICATION ! PLEASE READ CAREFULLY !!

WARNING: DO NOT GO TO THIS URL! http://www.updatepo.org/ WARNING: DO NOT GO TO THIS URL!

For the link to become active, please click on 'Add to contacts' skype button or type it in manually into your web browser !

FULL DETAILS OF SCAN RESULT BELOW
****************************************

WINDOWS REQUIRES IMMEDIATE ATTENTION

ATTENTION ! Security Center has detected
malware on your computer !

Affected Software:

Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair utility immediately

Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.

WARNING: DO NOT GO TO THIS URL! http://www.updatepo.org/ WARNING: DO NOT GO TO THIS URL!

For the link to become active, please click on 'Add to contacts' skype button or type it in manually into your web browser!

Tags:

2 comment(s) so far...

Re: WARNING: Scam / Virus via Skype?

Thank you so much for posting this warning.
It looked suspicious to me so I googled the url.
PA

By Pat Adler on  3/4/2010 11:16 AM

Re: WARNING: Scam / Virus via Skype?

Hadn't been on skype in ages, so when this popped up I thought "What is this thing? So I googled and found that it is a scam. I blocked the sender on skype. Anyone know if there is a way to tell skype they are being used for a scam and get them to ban the user? I know it would only be until they got some other profile to send it from, but it might be worth a shot. Thanks for the post :)

By KaliDava on  4/22/2010 8:21 PM

Your name:
Your email:
(Optional) Email used only to show Gravatar.
Your website:
Title:
Comment:
Security Code
CAPTCHA image
Enter the code shown above in the box below
Add Comment  Cancel 
 
Please Share Your Comments With Us
 



Submit Comment
Excellent Info0.00%0
Great Info0.00%0
Useful Info0.00%0
Not so useful0.00%0
Confusing / Useless0.00%0

Number of Comments0,Average of Ratings
No comment.
 
Network Status
 

All servers Operational

   
 
Learn More!
 

Find more about our founder

Steve Radich:

LinkedIn Profile

Contact Us