Fake Virus Alerts, Browser Hijacking (Firefox and IE11) Using Windows 7

Anonymous
2017-05-27T01:58:55+00:00

Hi, All.   I'm trying to resolve a problem on a computer used in our senior group. Something called "Fireball" showed up on this machine. One of the other "lab rats" deleted it--I don't know exactly how they did it. What's been occurring since is this: several different kinds of fake virus alerts (to call a phone number for help--some say "Microsoft") which can be closed using Task Manager; apparent browser hijacking, because a second tab immediately opens and I can see numerous website names rotating through (google-mirror.com, ww11.home.google-mirror..., park.above.com, clicksads.club, one that says ALERT and covers the screen with **** behind a Zeus Virus alert (****.com shows in the lower left corner), with RDN/YahLover.worm... in front of it! I restricted cookies, and there are tons of pop-ups asking to save cookies: tawk.to, securityupdate9900x112.com, utm.z3wl.com, shoppons.site, scorecardresearch.com, hom.google-miriror.com, inclk.com, wkee.reddhon.com, rainbow-networks.com, com-safety-jx30.club, google.co.in, and instantcasualconnections.com (so far). There are no weird programs on the computer--that show up.

Task Manager closes these alert pop-ups and the computer is usable, but we found that every 24 hours it starts all over again. Is this some kind of Scheduled Task??

I believe the virus alerts are fake. I'm assuming someone downloaded something that was bundled with crapware. I've checked the toolbars and extensions--nothing seems wrong there. No add-ons show. I've run Malwarebytes, Adwcleaner, and CCleaner, in addition to regular scans by Defender. I have reset IE to default settings, deleted cookies, history. I've tried using SysInternals Process Explorer and Autoruns--but I don't really know what I'm looking for. I figure something weird, but I've read malware can be hidden pretty much everywhere these days. The Registry seems okay--but same story: nothing jumps out at me.

I did a system restore today, but it only went back a month, and the weirdness was still there after restart. Tomorrow I plan to run sfc /scannow and the MS System Update Readiness Tool. Will that be a waste of time? Should I just reinstall the OS?? I wonder if deleting the user accounts would get rid of any junk??

I'm out of ideas. I enjoy a challenge, but come on!! This stuff is so devious! Any thoughts would be much appreciated. I've gotten great help here with past problems... Thanks for listening...

Chris

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

44 answers

Sort by: Newest
  1. Rob Koch 26,175 Reputation points Volunteer Moderator
    2017-06-01T04:16:56+00:00

    There were some flaky problems with the GWX (Get Windows 10) app during the period when the upgrade was free, but those were either fixed or simply ended completely once the free offer had ended and Microsoft sent out a final command to remove the core GWX components off all systems that hadn't been upgraded.

    I know those problems were real, because they happened to me on the same system I finally got around to upgrading just days before the free offer ended, in late July 2016.  However, they had actually stopped when Microsoft had found the problem and fixed it several months earlier, so there's been no good reason to leave Automatic Updates disabled since then.

    I hope you actually have Office 2010, since that version should be supported until roughly the same date as Windows 7 in January 2020 and so would be the easiest situation.

    I've had both my Windows systems set for Automatic Update since before my upgrade to Windows 10 and have not had any issues.  However, mine are both stock Dell equipment with all major name peripherals like a Microsoft Wireless Keyboard/Mouse combo and HP printer, so issues with updates are highly unlikely.

    I stopped having any interest in "home built" equipment after working as a Network Administrator in an engineering school and later the regional whitebox manufacturer that supplied our systems.  This taught me the importance of extensive verification that systems and drivers be thoroughly vetted and tested with each other and any other hardware and core operating system software they'd be used with.  An individual can't do this, so home builds are simply a problem waiting to happen.  The most common problem with such systems is overheating, since thermal design of a case and components is a highly technical area that few understand.

    At least it sounds like the systems you're supporting are consistent though, since that makes troubleshooting easier as the issues should be common to all systems as well.

    Rob

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2017-06-01T03:31:04+00:00

    Thank you for another great reply, Rob. Yes, it updated after installation, although I plan to manually check again tomorrow. One bad thing is that the group decided to turn off automatic updates because of the push for Win 10 (which we have on another partition). Do you know if that's still an issue? I'm not comfortable with this setting, but the machines are manually updated every Monday.

    Regarding Office 2007, it may be 2010 that we're installing--I'll have to double check. We have MAK licenses for our software (through Tech Soup). Everything was in place when I joined the group, but after everything you've described to me, I think a re-engineering may be in order. I agree that having all of these browsers probably isn't necessary. We should offer and make available what we feel are the best tools and programs to use.

    I'm familiar with Libre Office (we have that installed), Google Docs, and the MS Suite through Outlook. It's probably true that we don't really need Office installed. We have classes (albeit "light") for using the individual programs, but that could be accomplished with any of these other programs, as well.

    I understand what you're saying about the Hosts file, that SmartScreen accomplishes the same thing with no extra maintenance duties, which I like!

    You've given me so much to ponder and investigate, Rob. And, as I said, I'm going to be sharing all of this information. I've printed out all of the replies I've received and will place them in a notebook for reference. Great stuff.

    Chris

    Was this answer helpful?

    0 comments No comments
  3. Rob Koch 26,175 Reputation points Volunteer Moderator
    2017-05-31T19:54:00+00:00

    Christine,

    Glad to hear it went well.  I didn't see any mention of performing Windows Updates though, so I hope you've done that or can get it done before anyone uses that PC on the Internet, since that's a core requirement for a secure system.

    I understand why you've chosen to install the most popular browsers, since in an open environment like yours it's likely your users might do this if you hadn't, but you now understand the additional risk this creates and that keeping these maintained and secure is an additional requirement and burden.  It sounds like you've got enough people involved that this shouldn't be a problem though.

    I note that you mentioned installing Office 2007, which if that's included on all machines will cause a significant issue for you later this year when it goes End of Life on October 10, 2017.

    This Office 2007 End of Life roadmap - Office 365 article covers this extensively, but the basic issue will be the need to replace all of those copies at once, since this can get expensive and even the subscription model becomes expensive over time.  As Carol mentioned earlier, there are third-party options, but as I also discussed, this brings it's own support costs including separate maintenance and vulnerabilities, so there's a big decision to make.

    What I'd try to determine first is whether these applications, likely just Word and possibly Excel are actually receiving much use to create new documents or are simply being used to display an occasional file received via email.  If the latter is true, you might look into the option I mentioned regarding the use of personal Microsoft Outlook.com email accounts for such occasional viewing, since that's completely free and requires no local maintenance whatsoever, as the applications are basically Office 365 operating through the email accounts.

    If you truly need the Office apps installed locally, if it's only a handful of users which is likely, this may require only a few machines supporting these apps.  I know that since I stopped working regularly, my own use of Office has dropped off drastically, since most documents today are distributed in PDF or other publishing formats rather than the Office documents more commonly used in the business world.

    As for the Hosts file, I realized something about that after having time to think about it since those earlier discussions.  It's been so long since I'd used the earlier forms of these back in roughly 2001 to 2005 that I'd also forgotten why I'd dropped using them at that point.  The reason was that along with being a fairly static set of IP addresses needing separate maintenance and also causing performance issues for browsing at the time, their purpose was basically replaced by the SmartScreen Filter (now Windows Defender SmartScreen in Win10).

    What happened is that Microsoft saw the need initially for something to block phishing websites, so as this IE7 - Introducing the Phishing Filter article discusses, this functionality was first added in 2007.  As the threats evolved, Microsoft improved this and added Anti-Malware support, creating the Internet Explorer 8 SmartScreen® Filter.  In IE9 Microsoft added SmartScreen® Application Reputation and had begun using the more broad social-engineering attack terminology to describe the types of attacks which SmartScreen was helping to protect against.

    As time has gone on, the integration between SmartScreen and both the Windows 8 & 10 operating systems, as well as Windows Defender has become much greater, allowing SmartScreen to better protect all applications that access the Internet and a cleaner interaction between it and Defender to provide less confusing notifications for the PC user.

    So all of these much more targeted protections within SmartScreen and Defender now more specifically detect and block the true threats from malicious websites, without needing to block entire IP addresses, since in some cases these may contain additional domains that are otherwise innocent.  SmartScreen's design allows it to block either individual domains pages or a specific URL path, so it has better granularity.

    It also has a much larger database than can be maintained locally on a PC, so since any PC accessing the Internet can inherently reach the SmartScreen servers as well, this provides a continuously maintained and updated set of block lists.  SmartScreen has also always had a small subset of its list, obviously the more static items that don't change often similar to the hosts file entries, stored in a local cache on the PC.  This means that not only does it provide basically the same protection as the hosts file, but also a much more dynamic list of changes that any PC using it can access as needed, with no manual updating of any sort required.

    I think from this you can see why though I originally dropped using the hosts file method due to performance issues caused by its having grown too large, I never returned to using it since its purpose is now functionally entirely gone.  I only forgot about this because I haven't taken the time to think about these hosts files in over a decade, but sorry for not thinking of it sooner.

    Rob

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2017-05-31T03:36:18+00:00

    Rob, I had to let you know how it went today. The installation went fine (I asked one of the other group members about identifying the correct partition--which turned out to be nicely labeled--before beginning the installation). However, when it completed, I had lost keyboard and internet functions. I tried swapping keyboards, even though I knew the current one was working fine. I read about making sure not to use a USB 3.0 port, so I checked that. Then I tried using a PS2. Still nothing. It took quite a while to try troubleshooting and searching for info online. Finally, I restarted and, miraculously, the keyboard started working, but no such luck with the internet. I concluded it had something to do with the driver--missing. Around this time, a recently certified MS tech walked in (our mail carrier!), and he played with it for a little while, trying to copy the driver from another computer (identical). No luck. (And then he had to go back to work!) We couldn't find a make or model number anywhere on the machines, which is when I found out they had been built by members of the group a few years ago. I really didn't want to have to open it up and mess around inside. So now what?? I asked our director if she had any knowledge of or files on the equipment and she said she could probably find some (I think she mentioned, "things like the motherboard"). So I went back and Googled how to find out which motherboard you had (How to Geek--my fave). I used the cmd.exe as administrator and typed in the lengthy command, and bingo! So then I went to Asus and looked for a driver, chose what I thought might be the right one (it was a more current version), downloaded to a flash drive, and copied to #12. But how to install it?? I opened the folder and hoped to see something with an .exe, but didn't. But I did find a "set up" file and opened it, which opened an install wizard. Yay!! Holy Crap!! I was online!!! I felt like jumping up and down!! I kept saying, "No way!!" I really thought I was going to have to hang my head and tell the group I couldn't do it, that the "real" lab rats would have to "fix" it the next time they came in. I was by myself all afternoon doing this.

    So from there I downloaded IE11 and MSE, adjusted the DEP and EPM settings, and checked to make sure Send Do Not Track Requests was checked. I updated MSE and ran a quick scan. Downloaded MBAM and ran it. Tomorrow I'll have to install a bunch of things (Adobe, MS Office 2007, CCleaner, I guess Chrome and Firefox, if we're going to keep them all the same--maybe we'll discuss NOT having all 3 browsers) and some other programs.

    Oh! In the How to Geek article on identifying the motherboard, it mentioned a program (app?) called Speccy from Piriform (CCleaner folks, so we trust them). It's amazing!! Tons of info on your machine. I didn't take the time to compare, but it might be similar to Belarc Advisor, but didn't show like security information, etc.

    Anyway, Rob, I just couldn't wait to share my news with you. Thanks again for all your time and guidance and encouragement. Not sure if I'll play with the Hosts file. I'll run it by everybody else. So 5 hours later, #12 is back in business!! And I felt wrung out, but happy!! Ta da!!!

    Chris

    Was this answer helpful?

    0 comments No comments
  5. Rob Koch 26,175 Reputation points Volunteer Moderator
    2017-05-30T06:23:42+00:00

    You said, "Internet Explorer hasn't been part of the operating system itself since roughly Windows 7"

    "Windows 7 includes Internet Explorer 8 as part of the operating system."

    https://answers.microsoft.com/en-us/ie/forum/ie7_6-windows_other/what-version-of-internet-explorer-comes-with/ab41ffe9-fc95-4f6f-8d2a-ee3422a00f82

    "Windows 7 includes Internet Explorer 8 as part of the operating system."

    https://www.quora.com/Which-IE-version-does-Windows-7-come-with-by-default

    "..any 3rd-party apps simply adds to the vulnerabilities as I stated earlier, so there's never a more secure operating system possible than the original installation."

    Naturally, all apps have their vulnerabilities. However, stating there's never a more secure OS possible than the original installation.. is just plain false. I know for a fact that most, if not all, experts in the security industry will strongly disagree. Windows has always been an insecure OS. I could write a book on all the tweaks and hacks I applied to XP to make it more secure! Firewall wasn't enabled by default.  Services that shouldn't have been included or enabled by default, etc. After it's release multitudes of systems became infected by that internet worm. (I don't recall the name offhand.)

    I realize there's been much improvement in 7 and 10. However, there are still out-of-the-box security issues with both OS's.  I consider privacy invasion a security issue, as well. I'm sure you're aware of all the ways MS is spying on users in Win10, and I just read somewhere they're also ways they're spying on Win7 users, but I haven't looked into it. 

    As as admin, you're applied many restrictions on the systems you maintain. I wouldn't call that out-of-the-box security. Generally speaking, though, that's just not true and never has been.

    Carol, I realize now that you are talking about the superficial point of Internet Explorer (IE) being "bundled" with Windows as if this means that IE is part of the operating system, when in reality this is nothing more than including an application with the operating system, as with any other app such as media player or notepad.

    What I was talking about is the direct integration of Internet Explorer into the operating system itself as a portion of the Windows Shell and other critical system components.  This is how earlier versions including Windows XP with IE6 were designed, which led to technical issues, especially as Microsoft worked to create the earliest version of Protected Mode within Internet Explorer 7.  This "Separation of Internet Explorer 7 from the Windows shell" article describes some of the motivations behind that separation.

    If you brief that article, you'll find a partial explanation of the groundwork that provides the highly improved security when Enhanced Protected Mode is enabled in IE11.  That's because this separation of the browser from the shell allows for the increased isolation and so enhanced security that later versions of Internet Explorer have improved upon and to a great extent carried back into the earlier version of Windows 7 that these support.

    Obviously you recognized that the various configuration items I'd discussed earlier made significant changes to the security of the operating system, so I'd assumed that either you or Christine would also understand that I was referring to the initial installation of Windows operating system files and applications, but not the default configuration of these in order to provide the best security possible.  Of course this requires additional configuration, but nothing like most of the hacks typically seen in various 3rd-party articles, often turning off services and other settings these people typically have no understanding of.

    Note that I've never turned off or changed the default services configuration of any system nor changed any other core system configurations other then those I've mentioned above, except of course a handful within Internet Explorer itself, none of which I felt worth mentioning since their effect on true security is minimal or obvious.  For example Enable SmartScreen Filter which is prompted [and enabled] at first use of IE or Empty Temporary Internet Files folder when browser is closed.

    Despite these apparently limited changes to settings, note that it's primarily these few configuration items that provide the enhancements to security, since in truth they were early releases of changes which were often made the default configuration in later versions of Windows.  For example, the DEP capabilities within Windows 7 are now the default configuration in Windows 10.

    So today we are many generations beyond the ancient history of Windows XP, but many consumers are still operating under the same delusions they held when that version was current.  The reality is far more complex, but the user base generally knows nothing more technically then they did back then, still operating within a mythology that they use to feel comfortable that they understand what's going on, when nothing could be further from the truth.

    Privacy is a separate issue and is confused by the fact that most discussing it have no idea how Microsoft treats this information any more than they do with Apple or Google.  The fact that Microsoft provides more granular and understandable control over this information escapes most consumers, while they also have no idea that Google is infamous for collecting far more with virtually no personal control over its collection.  The ability to control this information is a tradeoff with the need for access in order to use certain features such as Cortana, but that's far too confusing for the typical consumer to grasp.

    I personally don't need Cortana with my Windows 10 system, since it has no microphone and is primarily used as a media PC for browsing.  For that reason most of those features and privacy settings are turned off in my case anyway, including location, since I only wish to receive the default advertising for websites and block most of this with the Tracking Protection settings mentioned earlier anyway.

    This latter setting is enabled more to block the random malicious material pushed through the advertising networks, with the lack of personal tracking and display of most obnoxious ads simply a nice side effect.

    Rob

    Was this answer helpful?

    0 comments No comments