# online-systemscan.net ==\> legitimate or evil spyware-installer site or what?

**URL:** <https://boards.straightdope.com/t/online-systemscan-net-legitimate-or-evil-spyware-installer-site-or-what/509751>\
**Category:** Factual Questions\
**Created:** [September 11, 2009, 11:05pm UTC](https://boards.straightdope.com/t/online-systemscan-net-legitimate-or-evil-spyware-installer-site-or-what/509751 "2009-09-11T23:05:37Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![AHunter3](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ahunter3/32/368_2.png) [@AHunter3](https://boards.straightdope.com/u/AHunter3)\
**Post date:** [September 11, 2009, 11:05pm UTC](https://boards.straightdope.com/t/online-systemscan-net-legitimate-or-evil-spyware-installer-site-or-what/509751/1 "2009-09-11T23:05:37Z")

</div>

My gf was browsing away doing other things and for some reason switched windows and [THIS](http://www.sendspace.com/file/158gb6) (sendspace link; it’s a JPEG file) was what was going on in another window. It wanted to install something to her computer whilst informing her that she was up to her eyeballs in viruses and trojans.

She didn’t do anything to intentionally invoke that site or start it up to scan her computer.

I had her cancel and close the windows after I took the screen shot.

Is this one of those sites that gets you to install their crapware/spyware/hijacking stuff while screaming “YOUR COMPUTER IS AT RISK AND FULL OF VIRUSES” ? Or is it legitimate? (If it’s legitimate how’d we end up on their site without deliberately going there?)

She has BitDefender and just ran it and it said it found nothing.

Me, I’m Mac-centric and know nothing about PC viruses and virus-scanning and whatnot aside from stuff I overhear.

---

<div class="post-metadata">

**Author:** ![Mogle](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mogle/32/12021_2.png) [@Mogle](https://boards.straightdope.com/u/Mogle)\
**Post date:** [September 11, 2009, 11:29pm UTC](https://boards.straightdope.com/t/online-systemscan-net-legitimate-or-evil-spyware-installer-site-or-what/509751/2 "2009-09-11T23:29:47Z")

</div>

I’d say that this is one of those cases where if you feel the need to ask ‘Is this legitimate?’ then the answer is ‘No’.

[This site](http://www.tech-linkblog.com/) list it as a scareware site, ie it’s just trying to trick you into installing the actual malware.

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [September 12, 2009, 2:18am UTC](https://boards.straightdope.com/t/online-systemscan-net-legitimate-or-evil-spyware-installer-site-or-what/509751/3 "2009-09-12T02:18:25Z")

</div>

Rule number one: Anything that pops up in a web browser window claiming your have multiple viruses is an out-and-out fake.

Antivirus software usually only finds one virus at a time. It also doesn’t ask that you download software to clean it.

Your girlfriend should download the [EICAR Test file](http://www.eicar.org/anti_virus_test_file.htm). This is a harmless file that all antivirus vendors have agreed to treat like it’s a real virus. When you download it, she will get a virus warning (if she doesn’t, her antivirus is not working). She can then familiarize herself with what a legitimate virus warning looks like. Anything else is fake.

---

<div class="post-metadata">

**Author:** ![IAmNotSpartacus](https://avatars.discourse-cdn.com/v4/letter/i/cc9497/32.png) [@IAmNotSpartacus](https://boards.straightdope.com/u/IAmNotSpartacus)\
**Post date:** [September 12, 2009, 4:50pm UTC](https://boards.straightdope.com/t/online-systemscan-net-legitimate-or-evil-spyware-installer-site-or-what/509751/4 "2009-09-12T16:50:36Z")

</div>

Nothing to add to your question, but OP you really might consider using an image host to host your images. There’s no good reason I should download that picture to my harddrive and then open it with picture viewer or paint or whatever when all I should really have to do is click a link and see the picture in my browser.

---

<div class="post-metadata">

**Author:** ![JKilez](https://avatars.discourse-cdn.com/v4/letter/j/e5b9ba/32.png) [@JKilez](https://boards.straightdope.com/u/JKilez)\
**Post date:** [September 13, 2009, 1:26pm UTC](https://boards.straightdope.com/t/online-systemscan-net-legitimate-or-evil-spyware-installer-site-or-what/509751/5 "2009-09-13T13:26:27Z")

</div>

> [@IAmNotSpartacus](#):
>
> Nothing to add to your question, but OP you really might consider using an image host to host your images. There’s no good reason I should download that picture to my harddrive and then open it with picture viewer or paint or whatever when all I should really have to do is click a link and see the picture in my browser.

Yes. I found myself asking, “is [sendspace.com](http://sendspace.com) legitimate site or an evil spyware installer?” After all, why would I have to \*download \*an image when I should just be able to view it in the browser.

---

<div class="post-metadata">

**Author:** ![Ximenean](https://avatars.discourse-cdn.com/v4/letter/x/aca169/32.png) [@Ximenean](https://boards.straightdope.com/u/Ximenean)\
**Post date:** [September 13, 2009, 3:01pm UTC](https://boards.straightdope.com/t/online-systemscan-net-legitimate-or-evil-spyware-installer-site-or-what/509751/6 "2009-09-13T15:01:47Z")

</div>

That looks like a classic “malware disguised as antivirus” page. You can usually tell because, for all they try to make it look like a standard Windows window, none of the controls are clickable. And if you have a non-standard colour scheme, it doesn’t match. They always use the default Windows XP Luna theme.

---

<div class="post-metadata">

**Author:** ![Ximenean](https://avatars.discourse-cdn.com/v4/letter/x/aca169/32.png) [@Ximenean](https://boards.straightdope.com/u/Ximenean)\
**Post date:** [September 13, 2009, 3:09pm UTC](https://boards.straightdope.com/t/online-systemscan-net-legitimate-or-evil-spyware-installer-site-or-what/509751/7 "2009-09-13T15:09:47Z")

</div>

[too late for edit]  
And I see that in this case they’ve capitalised “My Computer” incorrectly in the fake window title.

---

<div class="post-metadata">

**Author:** ![Kolak\_of\_Twilo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/kolak_of_twilo/32/73_2.png) [@Kolak\_of\_Twilo](https://boards.straightdope.com/u/Kolak_of_Twilo)\
**Post date:** [September 13, 2009, 4:48pm UTC](https://boards.straightdope.com/t/online-systemscan-net-legitimate-or-evil-spyware-installer-site-or-what/509751/8 "2009-09-13T16:48:54Z")

</div>

I got an email at work just the other day from our IT guys telling us that if any of us had a screen like that pop up to call them immediately and to not click on any links, etc. It most definitely is some type of malware trying to install a virus.

---

<div class="post-metadata">

**Author:** ![AHunter3](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ahunter3/32/368_2.png) [@AHunter3](https://boards.straightdope.com/u/AHunter3)\
**Post date:** [September 13, 2009, 4:55pm UTC](https://boards.straightdope.com/t/online-systemscan-net-legitimate-or-evil-spyware-installer-site-or-what/509751/9 "2009-09-13T16:55:25Z")

</div>

That was my Mac-centric but Windows-virus-paranoid reaction when she showed me the screen: I smell a rat, let’s close this window and cancel this install operation.

She uses Windows Classic appearance so the [del]Romper Room[/del] Luna appearance was a bit of a tip-off, yes.

But what the heck prompted this in the first place? Is her computer compromised insofar as nowhere she was browsing should have directed her to such a site? Any info on how this exploit gets THAT far, minus already-existent malware hijacking a browser window off to that site?

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [September 16, 2009, 12:45pm UTC](https://boards.straightdope.com/t/online-systemscan-net-legitimate-or-evil-spyware-installer-site-or-what/509751/10 "2009-09-16T12:45:25Z")

</div>

> [@AHunter3](#):
>
> That was my Mac-centric but Windows-virus-paranoid reaction when she showed me the screen: I smell a rat, let’s close this window and cancel this install operation.
> 
> She uses Windows Classic appearance so the [del]Romper Room[/del] Luna appearance was a bit of a tip-off, yes.
> 
> But what the heck prompted this in the first place? Is her computer compromised insofar as nowhere she was browsing should have directed her to such a site? Any info on how this exploit gets THAT far, minus already-existent malware hijacking a browser window off to that site?

Meh. It was probably just a popunder. Those don’t really require any sort of infection to happen. But you might want to run a spyware scan just to be sure. If you find a particular type of spyware, it would be easier to tell you how that particular one works.

The above is why I use an adblocker. Not to try and take away money from websites, but to avoid illegitimate ads that contain malware.

---

<div class="post-metadata">

**Author:** ![Claire\_Beauchamp](https://avatars.discourse-cdn.com/v4/letter/c/ec9cab/32.png) [@Claire\_Beauchamp](https://boards.straightdope.com/u/Claire_Beauchamp)\
**Post date:** [September 16, 2009, 3:47pm UTC](https://boards.straightdope.com/t/online-systemscan-net-legitimate-or-evil-spyware-installer-site-or-what/509751/11 "2009-09-16T15:47:34Z")

</div>

Was she by chance visiting the NYTimes or other newspaper site?

[http://bits.blogs.nytimes.com/2009/09/14/times-site-was-victim-of-a-malicious-ad-swap/](http://bits.blogs.nytimes.com/2009/09/14/times-site-was-victim-of-a-malicious-ad-swap/)

---

<div class="post-metadata">

**Author:** ![AHunter3](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ahunter3/32/368_2.png) [@AHunter3](https://boards.straightdope.com/u/AHunter3)\
**Post date:** [September 16, 2009, 5:53pm UTC](https://boards.straightdope.com/t/online-systemscan-net-legitimate-or-evil-spyware-installer-site-or-what/509751/12 "2009-09-16T17:53:51Z")

</div>

_I saw that news article_!

It’s possible; it’s also possible that insofar as the rogue advertiser’s ad was carried on the NY Times web page, the same ad was _also_ carried elsewhere.

Sure looks like the same setup screen etc.
