Fake Virus Alerts, Browser Hijacking (Firefox and IE11) Using Windows 7

Anonymous
2017-05-27T01:58:55+00:00

Hi, All.   I'm trying to resolve a problem on a computer used in our senior group. Something called "Fireball" showed up on this machine. One of the other "lab rats" deleted it--I don't know exactly how they did it. What's been occurring since is this: several different kinds of fake virus alerts (to call a phone number for help--some say "Microsoft") which can be closed using Task Manager; apparent browser hijacking, because a second tab immediately opens and I can see numerous website names rotating through (google-mirror.com, ww11.home.google-mirror..., park.above.com, clicksads.club, one that says ALERT and covers the screen with **** behind a Zeus Virus alert (****.com shows in the lower left corner), with RDN/YahLover.worm... in front of it! I restricted cookies, and there are tons of pop-ups asking to save cookies: tawk.to, securityupdate9900x112.com, utm.z3wl.com, shoppons.site, scorecardresearch.com, hom.google-miriror.com, inclk.com, wkee.reddhon.com, rainbow-networks.com, com-safety-jx30.club, google.co.in, and instantcasualconnections.com (so far). There are no weird programs on the computer--that show up.

Task Manager closes these alert pop-ups and the computer is usable, but we found that every 24 hours it starts all over again. Is this some kind of Scheduled Task??

I believe the virus alerts are fake. I'm assuming someone downloaded something that was bundled with crapware. I've checked the toolbars and extensions--nothing seems wrong there. No add-ons show. I've run Malwarebytes, Adwcleaner, and CCleaner, in addition to regular scans by Defender. I have reset IE to default settings, deleted cookies, history. I've tried using SysInternals Process Explorer and Autoruns--but I don't really know what I'm looking for. I figure something weird, but I've read malware can be hidden pretty much everywhere these days. The Registry seems okay--but same story: nothing jumps out at me.

I did a system restore today, but it only went back a month, and the weirdness was still there after restart. Tomorrow I plan to run sfc /scannow and the MS System Update Readiness Tool. Will that be a waste of time? Should I just reinstall the OS?? I wonder if deleting the user accounts would get rid of any junk??

I'm out of ideas. I enjoy a challenge, but come on!! This stuff is so devious! Any thoughts would be much appreciated. I've gotten great help here with past problems... Thanks for listening...

Chris

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

44 answers

Sort by: Most helpful
  1. Anonymous
    2017-06-03T13:39:59+00:00

    Wow! Thanks for this, Carol. I wonder if this was it. I wasn't in on the initial problem/resolution with that computer, but was told about it some weeks later when we started running into all the pop ups and redirects.

    Thanks for keeping me in the loop!

    Chris

    Was this answer helpful?

    0 comments No comments
  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

  3. Anonymous
    2017-06-03T04:16:59+00:00

    Chris, I had to show you this. It was put up the 2nd.

    Chinese Company Behind Adware That Infected Over 250 Million Computers

    https://www.bleepingcomputer.com/news/security/chinese-company-behind-adware-that-infected-over-250-million-computers/

    Below are the headings in the write-up. IF it installed a backdoor on that PC, it's good thing you did a clean install. I suggest changing all passwords, just to be sure. 

    Fireball adware family is on a rampage****

    Fireball adware has backdoor trojan-level capabilities

    Fireball's fake search engines rank in Alexa Top 10K

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2017-06-02T23:27:07+00:00

    Rob, I completely forgot to go back and read that article you linked to. I apologize for that. I was so sure IE was still tightly integrated into Windows until Win10. Yes, I understand why IE was separated. I know all to well about ActiveX issues from Win 9x days. That's mainly what made IE so insecure, it supported ActiveX. Rob, I didn't misunderstand why IE was included in Win10. I just found it interesting it was under accessories, a non-issue. 

    Of course, security and privacy are two different things. Privacy has nothing to do with the security of an OS. It does have to do with MY security. IK I got off topic. I guess I wanted people to be aware of it. Thanks for that link to Ed Bott's article.  If Ed says it isn't so, re Keylogger on 10, I believe it! I don't know that it's so much gullibility, as users believing the worst about MS. It sounds as though the initial reason for those privacy settings was mainly for the Insider program.

    FWIW, you seem to think I don't understand a number of things. I do, but I understand on a different level than you do. I may not be able to explain things in highly technical terms, which is understandable since I'm not a highly trained professional. However, I spent nearly ten yrs. as one of the top regular contributors on Annoyances.org forums, before they took them down several yrs. ago. My main focus was on security issues, including malware removal. I helped countless users clean malware off their systems, step by step. That's been several yrs. ago, since Vista days.

    Carol

    Was this answer helpful?

    0 comments No comments