# WARNING: Insidious virus on Internet

**URL:** <https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305>\
**Category:** Factual Questions\
**Created:** [March 27, 2016, 3:24am UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305 "2016-03-27T03:24:17Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![dougie\_monty](https://avatars.discourse-cdn.com/v4/letter/d/439d5e/32.png) [@dougie\_monty](https://boards.straightdope.com/u/dougie_monty)\
**Post date:** [March 27, 2016, 3:24am UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/1 "2016-03-27T03:24:17Z")

</div>

I had just gone on the Internet this afternoon when a large dialog box, supposedly warning of some serious problem with my Internet security, appeared, and I could not remove it. It had a toll-free number; to sum it up, the “technician” wanted to correct it but I would have to pay a fee. I did not identify my ISP to this person, and hung up. Later I was able to go back online–for awhile. The box appeared again, and I shut off the surge protector and haven’t switched the computer on since. I’m taking it to Office Depot tomorrow to have it checked out.  
This is really a bad one.

---

<div class="post-metadata">

**Author:** ![running\_coach](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/running_coach/32/15836_2.png) [@running\_coach](https://boards.straightdope.com/u/running_coach)\
**Post date:** [March 27, 2016, 3:27am UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/2 "2016-03-27T03:27:50Z")

</div>

So what’s the question?  
Reported for forum change.

---

<div class="post-metadata">

**Author:** ![dougie\_monty](https://avatars.discourse-cdn.com/v4/letter/d/439d5e/32.png) [@dougie\_monty](https://boards.straightdope.com/u/dougie_monty)\
**Post date:** [March 27, 2016, 3:29am UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/3 "2016-03-27T03:29:48Z")

</div>

What would YOU do if you went online and saw this appear on your screen?

---

<div class="post-metadata">

**Author:** ![running\_coach](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/running_coach/32/15836_2.png) [@running\_coach](https://boards.straightdope.com/u/running_coach)\
**Post date:** [March 27, 2016, 3:30am UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/4 "2016-03-27T03:30:02Z")

</div>

Any clues you could give up as to where you might have gotten it or _anything_ useful?

---

<div class="post-metadata">

**Author:** ![Left\_Hand\_of\_Dorkness](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/left_hand_of_dorkness/32/7156_2.png) [@Left\_Hand\_of\_Dorkness](https://boards.straightdope.com/u/Left_Hand_of_Dorkness)\
**Post date:** [March 27, 2016, 3:41am UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/5 "2016-03-27T03:41:38Z")

</div>

This sounds like ransomware. [Read this article](https://www.microsoft.com/security/portal/mmpc/shared/ransomware.aspx). It looks like sometimes just closing your browser and not clicking “restore previous session” may work, but not always. [This episode of Radiolab](http://www.radiolab.org/story/darkode/) has a terrifying story about a woman hit hard by ransomware in a way that encrypted all her files and threatened to erase them if she didn’t pay hundreds of dollars.

After hearing that story, I installed [Malwarebytes Ransomware Beta](https://blog.malwarebytes.org/news/2016/01/introducing-the-malwarebytes-anti-ransomware-beta/) on my computer, just in case :).

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [March 27, 2016, 7:15am UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/6 "2016-03-27T07:15:28Z")

</div>

> [@dougie\_monty](#):
>
> What would YOU do if you went online and saw this appear on your screen?

Run a full scan using whatever security software is already in place. Download and run full scans with one or two other popular tools from Malwarebytes, Kaspersky, Sophos etc.

I wouldn’t call the number. I wouldn’t click on anything in the message box reporting the supposed problem.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [March 27, 2016, 7:18am UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/7 "2016-03-27T07:18:19Z")

</div>

Also, do you have your browser set to block popup? do you use any ad blocking utility?

---

<div class="post-metadata">

**Author:** ![Atamasama](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/atamasama/32/12961_2.png) [@Atamasama](https://boards.straightdope.com/u/Atamasama)\
**Post date:** [March 27, 2016, 8:46am UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/8 "2016-03-27T08:46:21Z")

</div>

Often the goal isn’t to get the $50 or whatever it is that they are asking you to “clean your system”, it’s to get your financial info and then clean you out/commit identity theft. Don’t contact them again.

There’s a great thread stickied in this forum with advice on cleaning malware from your system, read it [here](http://boards.straightdope.com/sdmb/showthread.php?t=538187).

I’ll personally second the advice for Malwarebytes, that software is fantastic.

---

<div class="post-metadata">

**Author:** ![Richard\_Pearse](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/richard_pearse/32/13144_2.png) [@Richard\_Pearse](https://boards.straightdope.com/u/Richard_Pearse)\
**Post date:** [March 27, 2016, 8:50am UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/9 "2016-03-27T08:50:04Z")

</div>

> [@dougie\_monty](#):
>
> What would YOU do if you went online and saw this appear on your screen?

Sure as hell wouldn’t _ring them up!_

---

<div class="post-metadata">

**Author:** ![Derleth](https://avatars.discourse-cdn.com/v4/letter/d/b9e5f3/32.png) [@Derleth](https://boards.straightdope.com/u/Derleth)\
**Post date:** [March 27, 2016, 8:58am UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/10 "2016-03-27T08:58:26Z")

</div>

> [@dougie\_monty](#):
>
> What would YOU do if you went online and saw this appear on your screen?

Update my adblock software.

Laugh about how stupid you’d have to be to fall for such a transparent ploy.

Calling the number isn’t “falling for it”. _Paying the fee_ is “falling for it”.

Calling a toll-free number is actually smart, if you don’t mind getting junk calls, because it costs _them_ money. I might well _keep_ calling the number, just to work on my “stupid old man” impersonation.

---

<div class="post-metadata">

**Author:** ![watchwolf49](https://avatars.discourse-cdn.com/v4/letter/w/e9c0ed/32.png) [@watchwolf49](https://boards.straightdope.com/u/watchwolf49)\
**Post date:** [March 27, 2016, 11:01am UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/11 "2016-03-27T11:01:18Z")

</div>

… buy a Macintosh …

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [March 27, 2016, 11:14am UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/12 "2016-03-27T11:14:40Z")

</div>

> [@watchwolf49](#):
>
> … buy a Macintosh …

Let the hijack begin :smack:

---

<div class="post-metadata">

**Author:** ![Mr\_Shine](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mr_shine/32/464_2.png) [@Mr\_Shine](https://boards.straightdope.com/u/Mr_Shine)\
**Post date:** [March 27, 2016, 11:24am UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/13 "2016-03-27T11:24:47Z")

</div>

> [@watchwolf49](#):
>
> … buy a Macintosh …

Do you happen to know it’s raining where the OP lives and that he has no protective gament? Because that’s the only way this is a reasonable resonse.

---

<div class="post-metadata">

**Author:** ![madsircool](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/madsircool/32/3432_2.png) [@madsircool](https://boards.straightdope.com/u/madsircool)\
**Post date:** [March 27, 2016, 12:29pm UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/14 "2016-03-27T12:29:51Z")

</div>

Never click anything on the pop up. Close it with end process con+alt+del.

---

<div class="post-metadata">

**Author:** ![running\_coach](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/running_coach/32/15836_2.png) [@running\_coach](https://boards.straightdope.com/u/running_coach)\
**Post date:** [March 27, 2016, 12:40pm UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/15 "2016-03-27T12:40:29Z")

</div>

> [@watchwolf49](#):
>
> … buy a Macintosh …

[Can Macs get viruses and malware? We ask an expert](http://www.digitaltrends.com/computing/can-macs-get-viruses/)  
[Two Mac viruses strike at the heart of the platform’s secure image](http://www.theguardian.com/technology/2015/aug/04/mac-viruses-strike-secure-thunderstrike-2)

[Checking your Mac for viruses](http://www.macworld.com/article/2923022/checking-your-mac-for-viruses-wait-what.html)

---

<div class="post-metadata">

**Author:** ![simster](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/simster/32/1047_2.png) [@simster](https://boards.straightdope.com/u/simster)\
**Post date:** [March 27, 2016, 12:43pm UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/16 "2016-03-27T12:43:17Z")

</div>

dougie\_monty -

If this is the add/scam I think it is - it’s not a ‘virus’ in the traditional sense of the word. Its the internet equivalent of a ‘snake oil salesman’, and the worst part about it is being out the dollars to pay for their software (and if you did, and used paypal, they set up payment agreements so they can charge you again, and again and again).

As others have stated - if you run across popups/adds claiming you have a problem - close them immediately - never believe them - never click or call them - close and clear your browser history,and run malwarebytes and whatever current anti-virus software you have - and you will (most likely) be fine.

If you did end up installing the software -do the above plus uninstalling the software - dispute the charges with paypal/bank and change online passwords.

I know of several people that have, unfortunately, fallen for this scam - there did not seem to be any long term affects - their primary goals seem to be

a) sell you the snakeoil  
b) try and get you to let them remote into your pc and get even more money from you thru offering to clean up your terribly infected pc.  
c) potentially get info to reuse later

---

<div class="post-metadata">

**Author:** ![Bullitt](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bullitt/32/5725_2.png) [@Bullitt](https://boards.straightdope.com/u/Bullitt)\
**Post date:** [March 27, 2016, 12:48pm UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/17 "2016-03-27T12:48:32Z")

</div>

Another +1 for Malwarebytes.

---

<div class="post-metadata">

**Author:** ![core](https://avatars.discourse-cdn.com/v4/letter/c/d26b3c/32.png) [@core](https://boards.straightdope.com/u/core)\
**Post date:** [March 27, 2016, 12:54pm UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/18 "2016-03-27T12:54:02Z")

</div>

This is not a virus. Just sayin’. If you wouldn’t install random crap on your machine there would be considerably less risk. Now in Chrome, it was possible until just recently to display the ransom message in the browser and “sorta” lock up the machine. That no longer works.

The scammers that want this stuff written tell me that the $conversion rate is good enough that they don’t care to totally screw up the machine nor even trap Ctrl+Alt+Del. They say people fork over the dough without even attempting to resolve it themselves. I guess there really is one born every minute.

One last comment about installing random crap- You needn’t have done it recently. What happens is one group of perps gets you to run something, or uses a legitimate exploit. This simply installs a sleeper exe. Now, possibly even months later, these people sell installs to the scummy “entrepreneurs” with considerably less skills. Scammer XYZ just pays $x and gets his .exe effortlessly delivered to tens of thousands of machines per day. By the time you see stuff appearing on your machine, you’ve long forgotten what you might have done to cause it.

---

<div class="post-metadata">

**Author:** ![coremelt](https://avatars.discourse-cdn.com/v4/letter/c/4491bb/32.png) [@coremelt](https://boards.straightdope.com/u/coremelt)\
**Post date:** [March 27, 2016, 1:37pm UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/19 "2016-03-27T13:37:03Z")

</div>

Another new trend I’ve seen recently is ransomware on linux webservers. I had a script hack that encrypted some of the files on my webserver and wanted $50 in bitcoins to decrypt. Luckily I had a backup I could restore. This was using Joomla CMS and I believe it got in through a plugin that hadn’t been updated.

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [March 27, 2016, 2:18pm UTC](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305/20 "2016-03-27T14:18:32Z")

</div>

It’s basically harmless if you don’t call the phone number. I’ve seen many infections of it, and never found a problem. No virus is put onto the computer by it.

If you call the number, you won’t get infected unless you pay them to do it or grant them access to “check out” your computer. Anything they tell you will be a lie, BTW.

To get rid of this, kill the process: Press Ctrl-Shift-Esc to bring up the task manager. Look for your web browser on the list of apps, click on it, then on “End Task.” It will ask if you’re sure, but close the task. Then, when you bring up you browser, make sure it doesn’t go to the same pages on startup.

[Next page](https://boards.straightdope.com/t/warning-insidious-virus-on-internet/750305.md?page=2)
