So today I log into my computer and see the following message come in via Skype:
[9:59:17 AM] Update Registry: WINDOWS REQUIRES IMMEDIATE ATTENTION
URGENT SYSTEM SCAN NOTIFICATION ! PLEASE READ CAREFULLY !!
Is this a scam? Does Microsoft post via Skype to the world? No, they don't..
The full message is at the end of this post for reference.
So how do I know this is a scam? Well the most immediate sign is knowledge of updatingmy computer - That's why I wanted to share this - All too often users are convinced to just click something and install it, and that something turns out to be a virus they install.
Next year ago, after numerous people (myself included) pointed out to Microsoft that malware was using exact copies of their security bulletins with links changed they started signing their security notices. You'll notice their emails start like:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
and have and a bunch of random looking junk (a signature) on them
-----BEGIN PGP SIGNATURE-----
If you take the time you can compare that signature using PGP, personally I just read the message and can figure out if it's real or not from doing this stuff since the stone ages..
Microsoft is *NEVER* going to release an update via Skype or some non-Microsoft web site to avoid users being confused and clicking something that is a virus.
So what do you do about this message? Block the sender in Skype may be a good idea.. Ignore it is an option.
Unfortunately we live in a world where there are scam artists trying to attack us on every front, agressive marketers calling us on the phone, people out on street corners raising funds for organizations that aren't legitimate, and many more attempts to cause us headaches. It's hard to know who to trust, but the legitimate Microsoft bullets are almost exclusively on the second Tuesday of each month (there are sometimes out fo band updates, but those are rare).
Good luck, and MAKE SURE you do not click the URL (I have removed it from being a link).
Full Message:
[9:59:17 AM] Update Registry: WINDOWS REQUIRES IMMEDIATE ATTENTION
URGENT SYSTEM SCAN NOTIFICATION ! PLEASE READ CAREFULLY !!
WARNING: DO NOT GO TO THIS URL! http://www.updatepo.org/ WARNING: DO NOT GO TO THIS URL!
For the link to become active, please click on 'Add to contacts' skype button or type it in manually into your web browser !
FULL DETAILS OF SCAN RESULT BELOW
****************************************
WINDOWS REQUIRES IMMEDIATE ATTENTION
ATTENTION ! Security Center has detected
malware on your computer !
Affected Software:
Microsoft Windows Vista
Microsoft Windows XP
Microsoft Windows 2000
Microsoft Windows Server 2003
Impact of Vulnerability: Remote Code Execution / Virus Infection /
Unexpected shutdowns
Recommendation: Users running vulnerable version should install a repair utility immediately
Your system IS affected, download the patch from the address below !
Failure to do so may result in severe computer malfunction.
WARNING: DO NOT GO TO THIS URL! http://www.updatepo.org/ WARNING: DO NOT GO TO THIS URL!
For the link to become active, please click on 'Add to contacts' skype button or type it in manually into your web browser!