Fake Virus Alerts, Browser Hijacking (Firefox and IE11) Using Windows 7

Anonymous
2017-05-27T01:58:55+00:00

Hi, All.   I'm trying to resolve a problem on a computer used in our senior group. Something called "Fireball" showed up on this machine. One of the other "lab rats" deleted it--I don't know exactly how they did it. What's been occurring since is this: several different kinds of fake virus alerts (to call a phone number for help--some say "Microsoft") which can be closed using Task Manager; apparent browser hijacking, because a second tab immediately opens and I can see numerous website names rotating through (google-mirror.com, ww11.home.google-mirror..., park.above.com, clicksads.club, one that says ALERT and covers the screen with **** behind a Zeus Virus alert (****.com shows in the lower left corner), with RDN/YahLover.worm... in front of it! I restricted cookies, and there are tons of pop-ups asking to save cookies: tawk.to, securityupdate9900x112.com, utm.z3wl.com, shoppons.site, scorecardresearch.com, hom.google-miriror.com, inclk.com, wkee.reddhon.com, rainbow-networks.com, com-safety-jx30.club, google.co.in, and instantcasualconnections.com (so far). There are no weird programs on the computer--that show up.

Task Manager closes these alert pop-ups and the computer is usable, but we found that every 24 hours it starts all over again. Is this some kind of Scheduled Task??

I believe the virus alerts are fake. I'm assuming someone downloaded something that was bundled with crapware. I've checked the toolbars and extensions--nothing seems wrong there. No add-ons show. I've run Malwarebytes, Adwcleaner, and CCleaner, in addition to regular scans by Defender. I have reset IE to default settings, deleted cookies, history. I've tried using SysInternals Process Explorer and Autoruns--but I don't really know what I'm looking for. I figure something weird, but I've read malware can be hidden pretty much everywhere these days. The Registry seems okay--but same story: nothing jumps out at me.

I did a system restore today, but it only went back a month, and the weirdness was still there after restart. Tomorrow I plan to run sfc /scannow and the MS System Update Readiness Tool. Will that be a waste of time? Should I just reinstall the OS?? I wonder if deleting the user accounts would get rid of any junk??

I'm out of ideas. I enjoy a challenge, but come on!! This stuff is so devious! Any thoughts would be much appreciated. I've gotten great help here with past problems... Thanks for listening...

Chris

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

44 answers

Sort by: Newest
  1. Anonymous
    2017-05-29T22:52:07+00:00

    Rob, reading your replies is like a major tutorial in security!!! Feel like I'm in a classroom! :)  That's so great that you would take the time to share all of this info with me. You might have the impression that I know much more than I do about computers. Just a few years ago, I joined a computer group at our senior center. I've been tinkering with and reading about computers and their issues ever since; but I have to admit, so much of it is way beyond my grasp. What I'm pretty good at is troubleshooting, Googling, and following instructions to fix things. :) 

    I'll be printing out your replies (so I can adjust these settings, etc, step by step) and have already shared them with my fellow senior lab rats, most of whom have been using computers since the 70s, and are highly knowledgeable--way more than I. But I enjoy learning about them--and much of that is crisis driven, as in this latest instance.

    Thank you again, Rob, for sharing your knowledge with me and taking the time to write it all down!!

    Chris

    PS I should add: we have a computer lab of a dozen machines. They all have Windows 7 and 10, and some also have Linux on them, in partitions, to accommodate the various users' preferences and system familiarity. It's a lot to maintain, and we have a great team of folks who do this. But after reading your replies, I think we need to step up our security measures for greater protection. :)  

    Chris,  As I mentioned in my response to CarolLJ, I've worked in higher education (engineering) as well as many businesses as both an administrator and security consultant, so I know I tend to "teach" when posting and in fact try to.  When someone is actually willing to learn it helps not only them, but also everyone else who truly reads the thread and everyone each of them provides aid to as well, so it's always worth the effort.

    I tend to talk at a higher level for these reasons, but I know that everyone I've helped personally has told me they've caught at least some of what I've told them, so expecting more from people than what they feel they can grasp only seems to improve their abilities more as well.

    The coherent and intelligent way you described he initial situation tells all of us here you understand more than most and more importantly have a well organized thought process.  This is far more important than pure knowledge, since like myself you recognize that a key ability you have is using the Internet as a resource to research and then try the most promising items you find based on your troubleshooting.  I've simply been doing all of this far longer, since I built my first microcomputer from an early "kit" of discrete electronic components and integrated circuits back in the late 70's.

    The reason so few understand the true security abilities of Windows and critical components like Internet Explorer is that there's a computer mythology that's evolved over the years that most consumers believe is the truth.  The unfortunate fact is that this has melded with an apparent hatred for Microsoft itself, which is a foolish position to take when these are the systems most need to support and results in a closed mind towards securing the operating system in the best ways possible with what it includes.

    I don't blame others for taking this stance, since it is actually the most popular viewpoint in the consumer realm.  But it's also precisely why so many end up with infected systems, due to distorted policies like waiting too long to perform Windows Updates or using 3rd-party apps for critical security functions like browsers or antimalware.  No one can do these better than Microsoft today, but that's not the popular view since the memories are locked on issues from long ago before Bill Gates internal memo and the beginnings of the Trustworthy Computing Framework in 2002.

    Anyone managing more than a few systems will quickly learn the problems that result relating not only to security, but also scalability and the general ability to manage multiple systems.  The only real question is whether they'll learn the deeper truths behind what security actually means, since the US public has a distorted view in general that everything needs to be managed as an emergency, when in truth the best posture is always one of strong prevention.

    In general, adding things doesn't improve security, it reduces it by increasing the surface area needing to be protected.  Nothing is more secure than a Windows operating system as it initially ships, everything added later only increases risk and the management required to secure and maintain it.

    Rob

    What a great reply! Thank you for your most encouraging and kind words, Rob!! Much appreciated. I know I learn best in the face of adversity--as do we all, I guess. Because if everything is okay all the time, you don't have to go above or beyond, right? Right.

    I so very much appreciate all of your time and thoughts put to pen. I agree with your philosophy regarding MS's ability, and, I'd say, mission to make and keep their OSs as safe as possible. I hadn't thought, though, of so much added vulnerability when you introduce more layers through third-party apps. Makes so much sense. We do try to be careful about what we install, but no one monitors what our users are doing on a regular basis, so who knows?? We have the browsers set to clear when closed, but downloading things is another story. Then we end up with problems like #12... I'm pretty certain I'll be reinstalling the OS and just get on with it. 

    Christine

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2017-05-29T22:36:07+00:00

    Carol and Rob, I'm thoroughly enjoying reading your opinions and hearing about your experiences. This is a great free education for me. :)  I'll be printing out your replies and referring to them as we upgrade our security settings going forward.

    Chris(tine)

    Was this answer helpful?

    0 comments No comments
  3. Rob Koch 26,175 Reputation points Volunteer Moderator
    2017-05-29T22:34:20+00:00

    Rob, reading your replies is like a major tutorial in security!!! Feel like I'm in a classroom! :)  That's so great that you would take the time to share all of this info with me. You might have the impression that I know much more than I do about computers. Just a few years ago, I joined a computer group at our senior center. I've been tinkering with and reading about computers and their issues ever since; but I have to admit, so much of it is way beyond my grasp. What I'm pretty good at is troubleshooting, Googling, and following instructions to fix things. :) 

    I'll be printing out your replies (so I can adjust these settings, etc, step by step) and have already shared them with my fellow senior lab rats, most of whom have been using computers since the 70s, and are highly knowledgeable--way more than I. But I enjoy learning about them--and much of that is crisis driven, as in this latest instance.

    Thank you again, Rob, for sharing your knowledge with me and taking the time to write it all down!!

    Chris

    PS I should add: we have a computer lab of a dozen machines. They all have Windows 7 and 10, and some also have Linux on them, in partitions, to accommodate the various users' preferences and system familiarity. It's a lot to maintain, and we have a great team of folks who do this. But after reading your replies, I think we need to step up our security measures for greater protection. :)  

    Chris,  As I mentioned in my response to CarolLJ, I've worked in higher education (engineering) as well as many businesses as both an administrator and security consultant, so I know I tend to "teach" when posting and in fact try to.  When someone is actually willing to learn it helps not only them, but also everyone else who truly reads the thread and everyone each of them provides aid to as well, so it's always worth the effort.

    I tend to talk at a higher level for these reasons, but I know that everyone I've helped personally has told me they've caught at least some of what I've told them, so expecting more from people than what they feel they can grasp only seems to improve their abilities more as well.

    The coherent and intelligent way you described he initial situation tells all of us here you understand more than most and more importantly have a well organized thought process.  This is far more important than pure knowledge, since like myself you recognize that a key ability you have is using the Internet as a resource to research and then try the most promising items you find based on your troubleshooting.  I've simply been doing all of this far longer, since I built my first microcomputer from an early "kit" of discrete electronic components and integrated circuits back in the late 70's.

    The reason so few understand the true security abilities of Windows and critical components like Internet Explorer is that there's a computer mythology that's evolved over the years that most consumers believe is the truth.  The unfortunate fact is that this has melded with an apparent hatred for Microsoft itself, which is a foolish position to take when these are the systems most need to support and results in a closed mind towards securing the operating system in the best ways possible with what it includes.

    I don't blame others for taking this stance, since it is actually the most popular viewpoint in the consumer realm.  But it's also precisely why so many end up with infected systems, due to distorted policies like waiting too long to perform Windows Updates or using 3rd-party apps for critical security functions like browsers or antimalware.  No one can do these better than Microsoft today, but that's not the popular view since the memories are locked on issues from long ago before Bill Gates internal memo and the beginnings of the Trustworthy Computing Framework in 2002.

    Anyone managing more than a few systems will quickly learn the problems that result relating not only to security, but also scalability and the general ability to manage multiple systems.  The only real question is whether they'll learn the deeper truths behind what security actually means, since the US public has a distorted view in general that everything needs to be managed as an emergency, when in truth the best posture is always one of strong prevention.

    In general, adding things doesn't improve security, it reduces it by increasing the surface area needing to be protected.  Nothing is more secure than a Windows operating system as it initially ships, everything added later only increases risk and the management required to secure and maintain it.

    Rob

    Was this answer helpful?

    0 comments No comments
  4. Rob Koch 26,175 Reputation points Volunteer Moderator
    2017-05-29T21:48:20+00:00

    Rob, are you suggesting it'd be better security-wise to entrust our systems to Microsoft's offerings? IE has been the greatest security threat to Windows since 9x. Since IE is literally part of the OS, this makes the entire system vulnerable. MS finally had the decency to strip it from Windows, with 10, albeit a few OS's later than it should have. 

    Anyway, I disagree with you on that. On the contrary, we need a browser like Firefox to protect us from IE's vulnerabilities. ;-) Mozilla now puts out small, incremental updates and quite often sometimes. A recent wk. I had two updates. They're non-intrusive, and you can continue with your browsing. Plus, they don't just start updating, they give you a choice.. ask later or update now.

    There are better free, 3rd party apps to take place of some of MS's products, esp when it comes to security. I can see how it would make your job easier, if your clients stick with M$ though. As for Adobe, Flash is still a great security risk and needs replaced. Nothing about that has improved. Then there's that bloated Reader. There's an open source PDF reader, which I use, called Sumatra. All there is to it is the 6 MB executable. Simply brilliant. Well-known doesn't necessarily equal better. Norton's AV is another example of bloated.

    Edit: Who needs MS Office, when there are a couple good alts. like LibreOffice and Open Office?

    CarolLJ,

    In the US it's always better to use any applications built into the Windows operating system, since there's little you can do to remove most of them anyway and adding any 3rd-party apps simply adds to the vulnerabilities as I stated earlier, so there's never a more secure operating system possible than the original installation.

    Internet Explorer hasn't been part of the operating system itself since roughly Windows 7, though it was still bundled with the operating system install by default in the US, so unless you took the time to learn how to disable it completely it would remain operating.  This meant that adding a 3rd-party browser did nothing itself to improve security, only adding the vulnerabilities it contains to those discovered in Windows and Internet Explorer as well.

    Since all currently supported versions of Internet Explorer (e.g. IE11 and Edge on Win10) now contain not only SmartScreen malicious file and phishing protection, but also the hidden improvements which aren't enabled by default which I provided above, these browsers are actually far more secure than any 3rd-party's can possibly be.  That's because the Microsoft security apps, especially Windows Defender with Windows 8.1 or 10, are tightly integrated into these browsers as well.

    On top of this all of the updating required for not only the operating system, but also the browser and Microsoft provided security are included without any additional effort or knowledge required by the PC owner.  This type of integration is required for anyone supporting multiple standalone systems on a sporadic basis like Chris is doing, since he can't always be there to monitor which updates need to be performed and whether they're real or not, since users are often incapable of making these decisions.  This also allows him to tell the users not to install anything without his permission, since Microsoft only typically asks when major upgrades take place.

    There may be better options for Flash and Reader than Adobe if those are required, but we don't know the policy for these with the system's Chris manages.  Personally, if I need these apps I'll use those built-in with Windows 8.1 or 10, only dealing with these for Windows 7, which few people I know have had since the free upgrade to Win10.

    I haven't used anything other than the Microsoft free security apps on any system since Microsoft Security Essentials became available, since with the additional settings I've provided, I simply don't need to pay for the 1 or 2 commercial versions that are truly as good as these.

    I always avoided the 3rd-party office replacements, since in the past they required Java which is a security nightmare, but I see these now only require that when using the database app.  I still prefer to use Office myself, since it's cheap for the small packages or free with OneDrive or Outlook.com anyway and I don't need to worry about any compatibility, update or other maintenance issues.  However, I have relatives that simply use the Microsoft freebees now since all they typically do is view things others send them anyway, so no need for another 3rd-party app to maintain.

    Anyone like Chris needing to maintain multiple systems needs to keep the situation as simple and limited as possible, since every added program is another support burden and security risk.  Individual home users are entirely different than a multiuser situation, since they tend to care about their personal systems more.

    That's where my system's administrator and security consultant background comes into play, since I know how business systems are actually treated by users in every environment including businesses such as financial, healthcare, general corporate, government and all levels of education from 4k/elementary to colleges.

    In my experience, the strong, self-maintaining security systems I've put in place have meant I rarely if ever deal with actual malware infections, since these are typically blocked with nothing more than a rare notification from the antimalware at worst.  My last true infection on a personal system was in 2001, when I was forced to upgrade from Win95 to 2000 due to the side effects.  No Windows 7 or later personal system I've installed for friends or relatives has ever had anything worse than the recent modal dialog browser hijacks (e.g. technical support scams).

    So if anyone had something that simply running the free MBAM wouldn't easily remove, I'd probably just choose to rebuild the system from scratch, since there's likely something deeper wrong with a system in such a case and I'd rather be certain I removed it permanently.

    Rob

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2017-05-29T14:53:17+00:00

    Thank you, Carol. Lots of good suggestions and information. Perhaps I will post to Malwarebytes and see what they have to say...

    Was this answer helpful?

    0 comments No comments