According to the report provided by Sophos Naked Security blog a new phony anti-virus scam is infecting machines on the Internet in the guise of a Microsoft update. The fake Microsoft pop-up appears only on PCs using Firefox browser.
Sophos says that infected in drive-by downloads from compromised sites receive the scareware that appears as urgent update notifications. These updates are fake and only come to affected machines that use Firefox. Authentic updates from Microsoft come only through the Internet Explorer.
When an unwitting mark clicks the so called urgent update their computer gets infected with malware which seizes the PC. After that a persistent pop-up would warn the user to buy anti-virus to clean up the malware.
Sophos recommends accepting updates only from vendors from whom users have requested updates.