Fake Virus Alerts, Browser Hijacking (Firefox and IE11) Using Windows 7

Anonymous
2017-05-27T01:58:55+00:00

Hi, All.   I'm trying to resolve a problem on a computer used in our senior group. Something called "Fireball" showed up on this machine. One of the other "lab rats" deleted it--I don't know exactly how they did it. What's been occurring since is this: several different kinds of fake virus alerts (to call a phone number for help--some say "Microsoft") which can be closed using Task Manager; apparent browser hijacking, because a second tab immediately opens and I can see numerous website names rotating through (google-mirror.com, ww11.home.google-mirror..., park.above.com, clicksads.club, one that says ALERT and covers the screen with **** behind a Zeus Virus alert (****.com shows in the lower left corner), with RDN/YahLover.worm... in front of it! I restricted cookies, and there are tons of pop-ups asking to save cookies: tawk.to, securityupdate9900x112.com, utm.z3wl.com, shoppons.site, scorecardresearch.com, hom.google-miriror.com, inclk.com, wkee.reddhon.com, rainbow-networks.com, com-safety-jx30.club, google.co.in, and instantcasualconnections.com (so far). There are no weird programs on the computer--that show up.

Task Manager closes these alert pop-ups and the computer is usable, but we found that every 24 hours it starts all over again. Is this some kind of Scheduled Task??

I believe the virus alerts are fake. I'm assuming someone downloaded something that was bundled with crapware. I've checked the toolbars and extensions--nothing seems wrong there. No add-ons show. I've run Malwarebytes, Adwcleaner, and CCleaner, in addition to regular scans by Defender. I have reset IE to default settings, deleted cookies, history. I've tried using SysInternals Process Explorer and Autoruns--but I don't really know what I'm looking for. I figure something weird, but I've read malware can be hidden pretty much everywhere these days. The Registry seems okay--but same story: nothing jumps out at me.

I did a system restore today, but it only went back a month, and the weirdness was still there after restart. Tomorrow I plan to run sfc /scannow and the MS System Update Readiness Tool. Will that be a waste of time? Should I just reinstall the OS?? I wonder if deleting the user accounts would get rid of any junk??

I'm out of ideas. I enjoy a challenge, but come on!! This stuff is so devious! Any thoughts would be much appreciated. I've gotten great help here with past problems... Thanks for listening...

Chris

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

44 answers

Sort by: Most helpful
  1. Rob Koch 26,175 Reputation points Volunteer Moderator
    2017-05-30T06:23:42+00:00

    You said, "Internet Explorer hasn't been part of the operating system itself since roughly Windows 7"

    "Windows 7 includes Internet Explorer 8 as part of the operating system."

    https://answers.microsoft.com/en-us/ie/forum/ie7_6-windows_other/what-version-of-internet-explorer-comes-with/ab41ffe9-fc95-4f6f-8d2a-ee3422a00f82

    "Windows 7 includes Internet Explorer 8 as part of the operating system."

    https://www.quora.com/Which-IE-version-does-Windows-7-come-with-by-default

    "..any 3rd-party apps simply adds to the vulnerabilities as I stated earlier, so there's never a more secure operating system possible than the original installation."

    Naturally, all apps have their vulnerabilities. However, stating there's never a more secure OS possible than the original installation.. is just plain false. I know for a fact that most, if not all, experts in the security industry will strongly disagree. Windows has always been an insecure OS. I could write a book on all the tweaks and hacks I applied to XP to make it more secure! Firewall wasn't enabled by default.  Services that shouldn't have been included or enabled by default, etc. After it's release multitudes of systems became infected by that internet worm. (I don't recall the name offhand.)

    I realize there's been much improvement in 7 and 10. However, there are still out-of-the-box security issues with both OS's.  I consider privacy invasion a security issue, as well. I'm sure you're aware of all the ways MS is spying on users in Win10, and I just read somewhere they're also ways they're spying on Win7 users, but I haven't looked into it. 

    As as admin, you're applied many restrictions on the systems you maintain. I wouldn't call that out-of-the-box security. Generally speaking, though, that's just not true and never has been.

    Carol, I realize now that you are talking about the superficial point of Internet Explorer (IE) being "bundled" with Windows as if this means that IE is part of the operating system, when in reality this is nothing more than including an application with the operating system, as with any other app such as media player or notepad.

    What I was talking about is the direct integration of Internet Explorer into the operating system itself as a portion of the Windows Shell and other critical system components.  This is how earlier versions including Windows XP with IE6 were designed, which led to technical issues, especially as Microsoft worked to create the earliest version of Protected Mode within Internet Explorer 7.  This "Separation of Internet Explorer 7 from the Windows shell" article describes some of the motivations behind that separation.

    If you brief that article, you'll find a partial explanation of the groundwork that provides the highly improved security when Enhanced Protected Mode is enabled in IE11.  That's because this separation of the browser from the shell allows for the increased isolation and so enhanced security that later versions of Internet Explorer have improved upon and to a great extent carried back into the earlier version of Windows 7 that these support.

    Obviously you recognized that the various configuration items I'd discussed earlier made significant changes to the security of the operating system, so I'd assumed that either you or Christine would also understand that I was referring to the initial installation of Windows operating system files and applications, but not the default configuration of these in order to provide the best security possible.  Of course this requires additional configuration, but nothing like most of the hacks typically seen in various 3rd-party articles, often turning off services and other settings these people typically have no understanding of.

    Note that I've never turned off or changed the default services configuration of any system nor changed any other core system configurations other then those I've mentioned above, except of course a handful within Internet Explorer itself, none of which I felt worth mentioning since their effect on true security is minimal or obvious.  For example Enable SmartScreen Filter which is prompted [and enabled] at first use of IE or Empty Temporary Internet Files folder when browser is closed.

    Despite these apparently limited changes to settings, note that it's primarily these few configuration items that provide the enhancements to security, since in truth they were early releases of changes which were often made the default configuration in later versions of Windows.  For example, the DEP capabilities within Windows 7 are now the default configuration in Windows 10.

    So today we are many generations beyond the ancient history of Windows XP, but many consumers are still operating under the same delusions they held when that version was current.  The reality is far more complex, but the user base generally knows nothing more technically then they did back then, still operating within a mythology that they use to feel comfortable that they understand what's going on, when nothing could be further from the truth.

    Privacy is a separate issue and is confused by the fact that most discussing it have no idea how Microsoft treats this information any more than they do with Apple or Google.  The fact that Microsoft provides more granular and understandable control over this information escapes most consumers, while they also have no idea that Google is infamous for collecting far more with virtually no personal control over its collection.  The ability to control this information is a tradeoff with the need for access in order to use certain features such as Cortana, but that's far too confusing for the typical consumer to grasp.

    I personally don't need Cortana with my Windows 10 system, since it has no microphone and is primarily used as a media PC for browsing.  For that reason most of those features and privacy settings are turned off in my case anyway, including location, since I only wish to receive the default advertising for websites and block most of this with the Tracking Protection settings mentioned earlier anyway.

    This latter setting is enabled more to block the random malicious material pushed through the advertising networks, with the lack of personal tracking and display of most obnoxious ads simply a nice side effect.

    Rob

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2017-05-30T04:10:06+00:00

    I like that: "...any failure becomes an opportunity." I agree. So I just read a good how-to on reinstalling on a partitioned HD. That part gives me some pause, but I believe I can figure out which partition it's on by looking at the properties before I start (right?)

    I'm proud of myself for finding good info and following instructions--like a monkey! But I've found that even very experienced folks in our group don't try the things I do. I joined about 4 years ago after being able to "save" our computer after my husband downloaded some junk (evidently) and it locked up. He was convinced it was unsalvageable, but I was determined to try to fix it--and, miracle of miracles, I did, after hours and hours of "futzing." I was thrilled with myself. :)  So since then, I've successfully undertaken all kinds of "scary" things, like creating a new partition, taking apart laptops (with a youtube video, of course), a little registry editing, and helping teach classes to other seniors. And we got a "bug" a few years ago (I don't remember which one) and I found a good article in the Washington Post, I believe it was, about using a fake certification key to trick it into unlocking. I also give one-on-one assistance at our senior center to folks with all kinds of issues/problems with various devices. I've learned a lot by doing this, too. I always say, "I might not know how to do what you're asking, but I'm sure I can find the solution!" And I usually do. :)

    One of my biggest issues is that I don't know the "language" for all of these related things, so it's difficult to express myself when trying to discuss a problem--like when I saw the browser hijacking in progress with lots of various websites shooting across the tabs. I know I'm not even saying that properly, but I just don't know a lot of jargon, which makes it challenging to describe a problem in the first place.

    Anyway, you've given me great information and advice, Rob, in language I can understand. I feel encouraged and empowered! Thank you!

    Chris

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2017-05-30T03:43:52+00:00

    Haha, Carol, that's funny. :)  Yeah, I think I sound like a girl, too. :)  I understand different philosophies and experiences in this arena. Folks in my group have the same disagreements. One of our guys absolutely hates M$ (as you and he write it!) and advocates for Linux. He introduced me to it, and if I had to use it, I could learn it. But I'm comfy with MS. I'm not a super-user by any means. I recently discovered the simplicity of the Chromebook (helping my 68-year old sister make the decision, as she's terrified of computers and had still been using Vista! That's what I recommend now to seniors who don't want to deal with all of the updates and iterations of Windows. Most of us just want to browse, do email, and save pictures and music.

    This has been an educational weekend for me, thanks to you and Rob. I expected to find some good suggestions here, as I have in the past, but the two of you surpassed my expectations! I plan to do the clean install tomorrow (in between practice for a children's puppet show series this summer!)

    Thanks again!

    Chris

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2017-05-30T01:15:59+00:00

    Christine, I just knew you were a girl. :)

    I agree, Rob's posted a wealth of good info. and suggestions! I would never try to compete with him. I just disagree on some points. Even MS admitted yrs. ago security wasn't their main focus, if I recall correctly. While I suggested a few third-party apps, I realize there must be limitations in situations such as yours.

    Hope things go well for you from here on out.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2017-05-30T00:52:54+00:00

    You said, "Internet Explorer hasn't been part of the operating system itself since roughly Windows 7"

    "Windows 7 includes Internet Explorer 8 as part of the operating system."

    https://answers.microsoft.com/en-us/ie/forum/ie7_6-windows_other/what-version-of-internet-explorer-comes-with/ab41ffe9-fc95-4f6f-8d2a-ee3422a00f82

    "Windows 7 includes Internet Explorer 8 as part of the operating system."

    https://www.quora.com/Which-IE-version-does-Windows-7-come-with-by-default

    "..any 3rd-party apps simply adds to the vulnerabilities as I stated earlier, so there's never a more secure operating system possible than the original installation."

    Naturally, all apps have their vulnerabilities. However, stating there's never a more secure OS possible than the original installation.. is just plain false. I know for a fact that most, if not all, experts in the security industry will strongly disagree. Windows has always been an insecure OS. I could write a book on all the tweaks and hacks I applied to XP to make it more secure! Firewall wasn't enabled by default.  Services that shouldn't have been included or enabled by default, etc. After it's release multitudes of systems became infected by that internet worm. (I don't recall the name offhand.)

    I realize there's been much improvement in 7 and 10. However, there are still out-of-the-box security issues with both OS's.  I consider privacy invasion a security issue, as well. I'm sure you're aware of all the ways MS is spying on users in Win10, and I just read somewhere they're also ways they're spying on Win7 users, but I haven't looked into it. 

    As as admin, you're applied many restrictions on the systems you maintain. I wouldn't call that out-of-the-box security. Generally speaking, though, that's just not true and never has been.

    Was this answer helpful?

    0 comments No comments