real or fake?

RudeDawg

New member
Member
VIP
Local time
7:28 AM
Messages
51
Location
Wrangell, Alaska
I have Microsoft Security Essentials on my computer. Lately I'm getting a warning popup. Is this actually MSSE or is it malware?
 

Attachments

  • Fake Warning.jpg
    Fake Warning.jpg
    15.9 KB · Views: 102

My Computer

Computer Manufacturer/Model Number
self built
OS
Windows 7 Ultimate/ Windows XP Professional
CPU
AMD Phenom 2 965 Deneb 3.4Ghz Black Edition
Motherboard
Gigabyte GA-MA790XT-UD4P
Memory
2X Mushkin 2GB DDR3 1333
Graphics Card(s)
Sapphire Radeon HD 5750 1 GB GDDR5
Sound Card
Onboard
Monitor(s) Displays
Dell E770
Hard Drives
2X Western Digital Caviar Blue 320Gb
PSU
Thermaltake Toughpower XT 750 Cable Management
Case
Thermaltake Element G
Cooling
Cooler Master Hyper 212 Plus
I have Microsoft Security Essentials on my computer. Lately I'm getting a warning popup. Is this actually MSSE or is it malware?


Can we get the details of that pop up?
 

My Computer

Computer Manufacturer/Model Number
HP Pavillion dv-7 1005 Tx
OS
Win 8 Release candidate 8400
CPU
[email protected]
Memory
4 gigs
Graphics Card(s)
Nvidia 9600M
Sound Card
HD built-in
Monitor(s) Displays
17" Wxga
Screen Resolution
1440x900
Cooling
none
Internet Speed
45Mb down 5Mb up

My Computer

Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
Thanx A Guy.
 

My Computer

Computer Manufacturer/Model Number
self built
OS
Windows 7 Ultimate/ Windows XP Professional
CPU
AMD Phenom 2 965 Deneb 3.4Ghz Black Edition
Motherboard
Gigabyte GA-MA790XT-UD4P
Memory
2X Mushkin 2GB DDR3 1333
Graphics Card(s)
Sapphire Radeon HD 5750 1 GB GDDR5
Sound Card
Onboard
Monitor(s) Displays
Dell E770
Hard Drives
2X Western Digital Caviar Blue 320Gb
PSU
Thermaltake Toughpower XT 750 Cable Management
Case
Thermaltake Element G
Cooling
Cooler Master Hyper 212 Plus
That looks like the real thing. Click "Show details" and post a snip.
 

My Computer

Computer Manufacturer/Model Number
tw33k
OS
Windows 7 Ultimate (x64) SP1
CPU
Intel 3770k 4.6GHz
Motherboard
ASUS Maximus V Formula
Memory
8GB (2x 4GB) Crucial Ballistix
Graphics Card(s)
Sapphire 7950 (1060/1600)
Sound Card
On Board Realtek HD Audio
Monitor(s) Displays
27" Acer B273HU (via HDMI)
Screen Resolution
2048 x 1152
Hard Drives
Crucial M4 128GB
2TB WD Black
1TB Samsung F3 SATA
1TB WD Elite External
2TB WD USB 3.0
PSU
Corsair AX750 Gold
Case
Corsair Obsidian 800DW
Cooling
Corsair H100 (2x AP-121/2x UK-3000 push/pull)
Keyboard
Microsoft Wireless 5000
Mouse
Microsoft Wireless 5000
Internet Speed
5mb/s
Other Info
Logitech z-2300 2.1 speakers
Lamptron FC-5 v2
Agreed, I don't use MSE, so have not seen their alerts, the details would help as well. A Guy
 

My Computer

Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
I'm pretty sure it's a real alert (like 99.999% sure)
 

My Computer

Computer Manufacturer/Model Number
tw33k
OS
Windows 7 Ultimate (x64) SP1
CPU
Intel 3770k 4.6GHz
Motherboard
ASUS Maximus V Formula
Memory
8GB (2x 4GB) Crucial Ballistix
Graphics Card(s)
Sapphire 7950 (1060/1600)
Sound Card
On Board Realtek HD Audio
Monitor(s) Displays
27" Acer B273HU (via HDMI)
Screen Resolution
2048 x 1152
Hard Drives
Crucial M4 128GB
2TB WD Black
1TB Samsung F3 SATA
1TB WD Elite External
2TB WD USB 3.0
PSU
Corsair AX750 Gold
Case
Corsair Obsidian 800DW
Cooling
Corsair H100 (2x AP-121/2x UK-3000 push/pull)
Keyboard
Microsoft Wireless 5000
Mouse
Microsoft Wireless 5000
Internet Speed
5mb/s
Other Info
Logitech z-2300 2.1 speakers
Lamptron FC-5 v2
Thanks tw33k, I could find no alert images with that color and the exclamation point. Of course, a MBAM scan is always a good thing :) Hoping we get the details still. A Guy
 
Last edited:

My Computer

Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
Absolutely he scan with MBAM. This article might help him. Fake MSE Alert
 

My Computer

Computer Manufacturer/Model Number
tw33k
OS
Windows 7 Ultimate (x64) SP1
CPU
Intel 3770k 4.6GHz
Motherboard
ASUS Maximus V Formula
Memory
8GB (2x 4GB) Crucial Ballistix
Graphics Card(s)
Sapphire 7950 (1060/1600)
Sound Card
On Board Realtek HD Audio
Monitor(s) Displays
27" Acer B273HU (via HDMI)
Screen Resolution
2048 x 1152
Hard Drives
Crucial M4 128GB
2TB WD Black
1TB Samsung F3 SATA
1TB WD Elite External
2TB WD USB 3.0
PSU
Corsair AX750 Gold
Case
Corsair Obsidian 800DW
Cooling
Corsair H100 (2x AP-121/2x UK-3000 push/pull)
Keyboard
Microsoft Wireless 5000
Mouse
Microsoft Wireless 5000
Internet Speed
5mb/s
Other Info
Logitech z-2300 2.1 speakers
Lamptron FC-5 v2
Looks like a fake to me. I've had a warning from MSE and I don't recall it looking like that.

Don't click on those windows--Not even the X.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Built 2/11/2011
OS
Windows 7 Pro-x64
CPU
i7-2600 3.4GHz - 3.8GHz Turbo
Motherboard
Intel DH67BL-B3
Memory
8Gb - 2x4GB, Muskin 991770 PC3-1333
Graphics Card(s)
Integrated Intel HD 2000
Sound Card
Integrated Intel 10.1 HD, RealTek ALC892
Monitor(s) Displays
Asus LCD VH222H, Haier HL24XSL2a
Screen Resolution
1920x1080, 1920x1080
Hard Drives
Crucial SSD C300-128Gb,
Western Digital WD5002AALX - 500Gb,
Western Digital WD7501AALS - 750Gb
PSU
Seasonic 650W 80+ Gold Modular
Case
Rosewill Defender
Cooling
Stock CPU, Four 120mm case fans, PCH fan added
Keyboard
Logitech EX100 Y-RBH94 Wireless
Mouse
Logitech EX100 M-RCE95 Wireless
Internet Speed
3.0/1.5 Mbs
Antivirus
Microsoft Security Essentials
Browser
Microsoft Internet Explorer 11
Other Info
Antec Veris Premier-Multimedia IR Station,
Cyber Accoustics-3602 Speakers,
AFT XM-5U Card Reader,
Hauppauge TV-HVR-2250,
Sony LX300 USB Turntable
MalwareBytes didn't find anything. I chose the full scan option.
 

My Computer

Computer Manufacturer/Model Number
self built
OS
Windows 7 Ultimate/ Windows XP Professional
CPU
AMD Phenom 2 965 Deneb 3.4Ghz Black Edition
Motherboard
Gigabyte GA-MA790XT-UD4P
Memory
2X Mushkin 2GB DDR3 1333
Graphics Card(s)
Sapphire Radeon HD 5750 1 GB GDDR5
Sound Card
Onboard
Monitor(s) Displays
Dell E770
Hard Drives
2X Western Digital Caviar Blue 320Gb
PSU
Thermaltake Toughpower XT 750 Cable Management
Case
Thermaltake Element G
Cooling
Cooler Master Hyper 212 Plus
Agreed, I don't use MSE, so have not seen their alerts, the details would help as well. A Guy

Thanks tw33k, I could find no alert images with that color and the exclamation point. Of course, a MBAM scan is always a good thing :) Hoping we get the details still. A Guy

As one who uses Microsoft Security Essentials I can definitely say that is a legit alert color used by MSE, I've seen it myself. It's basically a warning about the software being out of date, or not having a scan done in a long time.

Now whether that particuliar alert is fake or not I can't say, but that alert color is one used by MSE.

Proof: This is my Vista copy out of date....

MSE Alert color.JPG
And no, the color has nothing to do with the OS version.
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built by me.
OS
Windows 10 Pro
CPU
Intel Core i7-4770K (3.5Ghz)
Motherboard
Gigabyte G1 Sniper 5 (F10 Bios)
Memory
32 gig Corsair Dominator Platinum (4x8Gig)
Graphics Card(s)
Sapphire Tri-X R9 Fury
Sound Card
Soundblaster ZXR
Monitor(s) Displays
NEC PA242W 24" LCD Monitor
Screen Resolution
1920 x 1200
Hard Drives
Primary - Samsung 850 Pro (512gig), Samsung 840 Pro (256gig), 2TB WD Caviar Black.
PSU
EVGA Supernova 1000 G2
Case
Cooler Master HAF X
Cooling
Corsair H100i with Corsair Air Series SP120 Quiet Fans
Keyboard
Logitech Wireless Wave
Mouse
Logitech Performance MX
Internet Speed
High Speed Cable
Antivirus
Norton Security
Browser
IE11
Other Info
Memory Timings - 1866MHz @ 9-9-9-27-1T @ 1.5 volts
I have Microsoft Security Essentials on my computer. Lately I'm getting a warning popup. Is this actually MSSE or is it malware?

I have not used MSE in a long time. Since the alert said MSE found a threat, can you do a full scan with MSE and see if it actually does find a threat? Does MSE have a Log?

Jim :geek:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built
OS
Windows 8.1 Pro w/Media Center 64bit, Windows 7 HP 64bit
CPU
Phenom II X6 1100T
Motherboard
ASUS M5A99X EVO
Memory
Crucial Balistic 8gb DDR3-1866 CL9
Graphics Card(s)
MSI R6850 Cyclone IGD5 PE
Sound Card
On Board
Monitor(s) Displays
ASUS VE258Q 25" LED with DVI-HDMI-DisplayPort
Screen Resolution
1920 x 1080
Hard Drives
Two WD Cavier Black 2TB Sata III, WD My Book Essential 2TB USB 3.0
PSU
Seasonic X650 80 Plus GOLD Modular
Case
Corsair 400R
Cooling
Antec Kuhler H2O 620, Two 120mm and four 140mm
Keyboard
Logitech K120
Mouse
Logitech Marble Mouse USB, Logitech Precision Game Pad
Internet Speed
15MB
Antivirus
Norton IS 2013, Malwarebytes Pro Beta 2
Browser
IE-11, FF-27
Other Info
APC UPS ES 750, Netgear WNR3500L Gigabit & Wireless N Router with SamKnows Test Program, Motorola SB6120 Gigabit Cable Modem. Brother HL-2170W Laser Printer, Epson V300 Scanner
I have Microsoft Security Essentials on my computer. Lately I'm getting a warning popup. Is this actually MSSE or is it malware?

I have not used MSE in a long time. Since the alert said MSE found a threat, can you do a full scan with MSE and see if it actually does find a threat? Does MSE have a Log?

Jim :geek:

History should show all the detected items.

Capture.PNG
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Home Premium 64 bit
CPU
Intel Core i7-4790
Motherboard
GA-Z87X-D3H
Memory
G.SKILL 8GB (2 x 4GB) DDR3 F3-10666CL9D-8GBNT
Graphics Card(s)
AMD Radeon R7 250
Sound Card
Realtek ALC892
Monitor(s) Displays
Samsung UN32EH5000, Dell 1703FPT
Screen Resolution
1920 x 1080, 1280 x 1024
Hard Drives
WD5003AZEX
WD10EZEX
Samsung HD103SJ
Samsung 128 GB 840 PRO
PSU
SeaSonic M12II SS-500GM
Case
Fractal Design Define R4
Cooling
Zalman CNPS9900ALED
Keyboard
Logitech K800
Mouse
Logitech M705
Internet Speed
16 Mbps
Antivirus
Avast
Browser
Firefox
Other Info
Bose Companion 2 Multimedia Speakers
I don't really think any visual means of determining a fake from a real pop-up by use of a screen capture should be considered as answers, as a decent fake is often merely a screen capture of the actual window, and they would look identical, esp if sized correctly. Clicking any "details" link, "cancel" button or "X" etc may be the equivalent of a full sized single picture link.

I would either open MSE before touching the other window (assuming it allows this) and as Sardonicus mentioned above, check the history and any logs to verify it's validity. If this is not possible, I would use alt+ctrl+del and select open task manager, then try to locate the app/process that might be clearly identifiable or run encapsulated in a service host. If you can find it close it from tsk mgr apps and/or use close process tree to shut it down, and then you should be able to run a scan or get into the history if it was not allowing you to at first attempt.

Hope you had a positive outcome, or will soon,
Mike :)
 

My Computer

Computer Manufacturer/Model Number
Custom self build - Desktop
OS
MS Windows 7 Home Premium SP1 64-bit (Family Pack Lic.) Upgrade
CPU
AMD Phenom II X6: Black Ed 1090T - AM3 / 3.2GHz / 8MB
Motherboard
Biostar TA790XE3
Memory
2 dual ch sets OCZ DDR3 PC3-10666 Platinum 1333MHz 8GB total
Graphics Card(s)
Onboard
Sound Card
Onboard 5.1 channel HD
Monitor(s) Displays
SyncMaster "Legal-sized" LCD (rotatable)
Screen Resolution
unknown (8.5"x15")? pixels are not known
Hard Drives
HDD1: WD RE3 Enterprize [p/n: WD500ABYS-NDW]
________SATA-II (3Gb/s) 500GB/7200rpm/16MB

HDD2: Deskstar 7K1000.C [p/n: HDS721010CLA332]
________SATA-II (3Gb/s) 1TB/7200rpm/32MB
PSU
Antec 900W mATX 20+4 w/6-8SATA;2MLX;4x6(+2)PCIe[p/n HCG-900]
Case
Mid 10-bay tower - free space design interior & well vented
Cooling
CPU HS cooler, 14.5" Case-sysfan1, dual sysfan2, exhaust
Keyboard
Blue Star Ergonomic - ps/2
Mouse
LED coorded w/v. roller wheel - ps/2
Internet Speed
GbLAN 10/100/1000 & WLAN - on T1 (Peer Network)
Other Info
Harmon-Karden speakers (L,R @ sub)

APC (Lead/Acid Batt backup UPC+Surge protector+etc)

Sony DVD SATA(300) - RW DVD/CD SATA-II(300)
MBAM scan came up clean.
 

My Computer

Computer Manufacturer/Model Number
self built
OS
Windows 7 Ultimate/ Windows XP Professional
CPU
AMD Phenom 2 965 Deneb 3.4Ghz Black Edition
Motherboard
Gigabyte GA-MA790XT-UD4P
Memory
2X Mushkin 2GB DDR3 1333
Graphics Card(s)
Sapphire Radeon HD 5750 1 GB GDDR5
Sound Card
Onboard
Monitor(s) Displays
Dell E770
Hard Drives
2X Western Digital Caviar Blue 320Gb
PSU
Thermaltake Toughpower XT 750 Cable Management
Case
Thermaltake Element G
Cooling
Cooler Master Hyper 212 Plus
Haven't seen it since though......... weird
 

My Computer

Computer Manufacturer/Model Number
self built
OS
Windows 7 Ultimate/ Windows XP Professional
CPU
AMD Phenom 2 965 Deneb 3.4Ghz Black Edition
Motherboard
Gigabyte GA-MA790XT-UD4P
Memory
2X Mushkin 2GB DDR3 1333
Graphics Card(s)
Sapphire Radeon HD 5750 1 GB GDDR5
Sound Card
Onboard
Monitor(s) Displays
Dell E770
Hard Drives
2X Western Digital Caviar Blue 320Gb
PSU
Thermaltake Toughpower XT 750 Cable Management
Case
Thermaltake Element G
Cooling
Cooler Master Hyper 212 Plus
This is what a real MSE alert looks like. (Courtesy of Britton30)
 

Attachments

  • WSE-Alert.JPG
    WSE-Alert.JPG
    16.7 KB · Views: 2

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Built 2/11/2011
OS
Windows 7 Pro-x64
CPU
i7-2600 3.4GHz - 3.8GHz Turbo
Motherboard
Intel DH67BL-B3
Memory
8Gb - 2x4GB, Muskin 991770 PC3-1333
Graphics Card(s)
Integrated Intel HD 2000
Sound Card
Integrated Intel 10.1 HD, RealTek ALC892
Monitor(s) Displays
Asus LCD VH222H, Haier HL24XSL2a
Screen Resolution
1920x1080, 1920x1080
Hard Drives
Crucial SSD C300-128Gb,
Western Digital WD5002AALX - 500Gb,
Western Digital WD7501AALS - 750Gb
PSU
Seasonic 650W 80+ Gold Modular
Case
Rosewill Defender
Cooling
Stock CPU, Four 120mm case fans, PCH fan added
Keyboard
Logitech EX100 Y-RBH94 Wireless
Mouse
Logitech EX100 M-RCE95 Wireless
Internet Speed
3.0/1.5 Mbs
Antivirus
Microsoft Security Essentials
Browser
Microsoft Internet Explorer 11
Other Info
Antec Veris Premier-Multimedia IR Station,
Cyber Accoustics-3602 Speakers,
AFT XM-5U Card Reader,
Hauppauge TV-HVR-2250,
Sony LX300 USB Turntable
may I ask why would a "decent" fake look any different? no holograms or photo inlays, right? not hard to make a fake that is pixel for pixel identical. pretty much a glorified screen cap.

don't mean to sound snobby about it, just fishing for some enlightenment.:)

Mike
 

My Computer

Computer Manufacturer/Model Number
Custom self build - Desktop
OS
MS Windows 7 Home Premium SP1 64-bit (Family Pack Lic.) Upgrade
CPU
AMD Phenom II X6: Black Ed 1090T - AM3 / 3.2GHz / 8MB
Motherboard
Biostar TA790XE3
Memory
2 dual ch sets OCZ DDR3 PC3-10666 Platinum 1333MHz 8GB total
Graphics Card(s)
Onboard
Sound Card
Onboard 5.1 channel HD
Monitor(s) Displays
SyncMaster "Legal-sized" LCD (rotatable)
Screen Resolution
unknown (8.5"x15")? pixels are not known
Hard Drives
HDD1: WD RE3 Enterprize [p/n: WD500ABYS-NDW]
________SATA-II (3Gb/s) 500GB/7200rpm/16MB

HDD2: Deskstar 7K1000.C [p/n: HDS721010CLA332]
________SATA-II (3Gb/s) 1TB/7200rpm/32MB
PSU
Antec 900W mATX 20+4 w/6-8SATA;2MLX;4x6(+2)PCIe[p/n HCG-900]
Case
Mid 10-bay tower - free space design interior & well vented
Cooling
CPU HS cooler, 14.5" Case-sysfan1, dual sysfan2, exhaust
Keyboard
Blue Star Ergonomic - ps/2
Mouse
LED coorded w/v. roller wheel - ps/2
Internet Speed
GbLAN 10/100/1000 & WLAN - on T1 (Peer Network)
Other Info
Harmon-Karden speakers (L,R @ sub)

APC (Lead/Acid Batt backup UPC+Surge protector+etc)

Sony DVD SATA(300) - RW DVD/CD SATA-II(300)
In THIS case, it's evident. Most drive-by attacks aren't sophisticated enough to show a copied alert. Here's both again. Look closely.
 

Attachments

  • WSE-Alert.JPG
    WSE-Alert.JPG
    16.7 KB · Views: 1
  • WSE-Fake.JPG
    WSE-Fake.JPG
    21.8 KB · Views: 0

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Built 2/11/2011
OS
Windows 7 Pro-x64
CPU
i7-2600 3.4GHz - 3.8GHz Turbo
Motherboard
Intel DH67BL-B3
Memory
8Gb - 2x4GB, Muskin 991770 PC3-1333
Graphics Card(s)
Integrated Intel HD 2000
Sound Card
Integrated Intel 10.1 HD, RealTek ALC892
Monitor(s) Displays
Asus LCD VH222H, Haier HL24XSL2a
Screen Resolution
1920x1080, 1920x1080
Hard Drives
Crucial SSD C300-128Gb,
Western Digital WD5002AALX - 500Gb,
Western Digital WD7501AALS - 750Gb
PSU
Seasonic 650W 80+ Gold Modular
Case
Rosewill Defender
Cooling
Stock CPU, Four 120mm case fans, PCH fan added
Keyboard
Logitech EX100 Y-RBH94 Wireless
Mouse
Logitech EX100 M-RCE95 Wireless
Internet Speed
3.0/1.5 Mbs
Antivirus
Microsoft Security Essentials
Browser
Microsoft Internet Explorer 11
Other Info
Antec Veris Premier-Multimedia IR Station,
Cyber Accoustics-3602 Speakers,
AFT XM-5U Card Reader,
Hauppauge TV-HVR-2250,
Sony LX300 USB Turntable
Back
Top