Threat Database Adware 'Your Windows is Infected with (2) Viruses!' Pop-Ups

'Your Windows is Infected with (2) Viruses!' Pop-Ups

By GoldSparrow in Adware

The 'Your Windows is Infected with (2) Viruses!' pop-up windows that may be displayed on a new tab titled 'Windows Security Scan' should not be trusted. The 'Your Windows is Infected with (2) Viruses!' pop-ups are generated on pages like Winshield6[.]club, which offers misleading information with the aim to lure users into installing a questionable security solution. The 'Your Windows is Infected with (2) Viruses!' warnings are produced by Web designers who employ unfair tactics into generating more pay-per-install revenue. Web surfers who stumble upon the 'Your Windows is Infected with (2) Viruses!' warnings are suggested that their systems have been infected with spyware and phishing viruses that require immediate removal. Security researchers note that the 'Your Windows is Infected with (2) Viruses!' alerts may be displayed thanks to a 'pop-up loop,' which is a term that describes a code, which is supposed to keep your Internet browser focused on a single message box. That way the visitors at Winshield6[.]club are unable to switch between tabs, access their bookmarks and use the close button to restart their Internet sessions. Hence, some users may believe that the 'Your Windows is Infected with (2) Viruses!' notifications are delivered by the Microsoft Corp, and they need to follow the instruction on their screens. We have seen that the 'Your Windows is Infected with (2) Viruses!' pop-ups include a screenshot of Support.microsoft.com and offer the following text:

'Windows Security Scan
Your Windows Windows 10 is infected with (2) Viruses!
[CURRENT DATE]
Your Windows Windows 10 is infected with i21 Viruses. The pre-scan found daces 0112) malware and (1)
Phishing/spyware System damage 28,1% - Immediate removal required!
The removal of (2) Viruses is required immediately to prevent further system damage, loss of Apps, Photos
or other tiles.
Traces of (1) Phishing/Spyware were found on your computer. Personal and banking information are at
risk.
1 minutes and 5 seconds
[Download Now|button]'

The same message can be found on subpages of Techreview[.]site, Winsecure[.]online, Winsecure[.]life and Kcmcc.com[.]kw. You should note that these messages are used by technical support crooks, and you might be directed to install a customized remote desktop client that connects you to them directly. It is a bad idea to trust the 'Your Windows is Infected with (2) Viruses!' alerts on your screen because you are likely to be exposed to remote desktop attacks. The operators of pages such as Techreview[.]site, Winsecure[.]online, Winsecure[.]life and Kcmcc.com[.]kw register clones almost daily and it is hard for AV companies to keep up with them since domain registrars are not known for their good security mechanisms. Web surfers who load resources related to the 'Your Windows is Infected with (2) Viruses!' may notice that AV engines bring up security warnings, which include the following detection names:

  • HEUR:Trojan.Script.Generic
  • HEUR:Trojan.Script.Iframer
  • Trojan.Script.743219
  • Win32.Trojan.Raasj.Auto

Trending

Most Viewed

Loading...