Fake Virus Alerts, Browser Hijacking (Firefox and IE11) Using Windows 7

Anonymous
2017-05-27T01:58:55+00:00

Hi, All.   I'm trying to resolve a problem on a computer used in our senior group. Something called "Fireball" showed up on this machine. One of the other "lab rats" deleted it--I don't know exactly how they did it. What's been occurring since is this: several different kinds of fake virus alerts (to call a phone number for help--some say "Microsoft") which can be closed using Task Manager; apparent browser hijacking, because a second tab immediately opens and I can see numerous website names rotating through (google-mirror.com, ww11.home.google-mirror..., park.above.com, clicksads.club, one that says ALERT and covers the screen with **** behind a Zeus Virus alert (****.com shows in the lower left corner), with RDN/YahLover.worm... in front of it! I restricted cookies, and there are tons of pop-ups asking to save cookies: tawk.to, securityupdate9900x112.com, utm.z3wl.com, shoppons.site, scorecardresearch.com, hom.google-miriror.com, inclk.com, wkee.reddhon.com, rainbow-networks.com, com-safety-jx30.club, google.co.in, and instantcasualconnections.com (so far). There are no weird programs on the computer--that show up.

Task Manager closes these alert pop-ups and the computer is usable, but we found that every 24 hours it starts all over again. Is this some kind of Scheduled Task??

I believe the virus alerts are fake. I'm assuming someone downloaded something that was bundled with crapware. I've checked the toolbars and extensions--nothing seems wrong there. No add-ons show. I've run Malwarebytes, Adwcleaner, and CCleaner, in addition to regular scans by Defender. I have reset IE to default settings, deleted cookies, history. I've tried using SysInternals Process Explorer and Autoruns--but I don't really know what I'm looking for. I figure something weird, but I've read malware can be hidden pretty much everywhere these days. The Registry seems okay--but same story: nothing jumps out at me.

I did a system restore today, but it only went back a month, and the weirdness was still there after restart. Tomorrow I plan to run sfc /scannow and the MS System Update Readiness Tool. Will that be a waste of time? Should I just reinstall the OS?? I wonder if deleting the user accounts would get rid of any junk??

I'm out of ideas. I enjoy a challenge, but come on!! This stuff is so devious! Any thoughts would be much appreciated. I've gotten great help here with past problems... Thanks for listening...

Chris

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

44 answers

Sort by: Oldest
  1. Rob Koch 26,175 Reputation points Volunteer Moderator
    2017-05-28T16:17:49+00:00

    Yes, Chris, I was just as surprised as you to learn that Microsoft had included, but disabled these strong settings by default due to compatibility concerns.  However, I'll quickly explain why here and what potential tradeoffs these may create which you need to be aware of when supporting systems using them.

    First, as I mentioned the DEP setting is typically relatively safe today when used with major name applications, while operating on 64-bit is also generally more stable than it was with the 32-bit versions including Windows XP before the more stable Windows 7 you're supporting.

    It's also true that much of the vendor supported software from those like Adobe such as Flash and Reader have improved greatly in the last few years, so this reduces the chance of any issues with enabling DEP, while at the same time reducing or at least quickly patching any newly discovered vulnerabilities within these applications.  Testing all of your required apps on a single machine along with some brief browsing to major sites known to use flash or pdf downloads is usually sufficient to find any potential issues, but I wouldn't expect any with these or any other major name software at this point.

    It's easier to support a newer Windows operating system such as 8.1 that includes the Microsoft tiled Reader app and Flash operating within a sandbox in the browser itself, but I had operated both of these successfully in the past with only the relatively obvious "update Adobe Flash" and similar social engineering app update prompts to deal with.  I can't say how many of these the settings might also protect from, since I personally would never try to install any of these as I know they're all invalid.

    As the short article discussing the EPM setting mentions near the end, the ability to run a necessary extension on a trusted website does exist, but this should only be enabled when both a site and the application are truly trusted.  Obviously this still provides an opening for confused users to mistakenly enable something they shouldn't, but since most major vendor's extensions such as Flash have been converted to 64-bit since this article was published, it should be possible to recommend that your users never allow any of these without your explicit permission.

    My general operating rule for my friends and relatives is if you didn't explicitly request something, just say no!  It's always safer to return later to install something that's needed than clean up from a malware install, so don't ever accept something you don't understand or didn't specifically request.  This can be a bit of an issue with Windows 7 and Adobe apps like Flash or Reader, but since even valid updates for these can include bundled downloads it may be safer to maintain these yourself than expect the typical user to do this correctly.  Of course, the more you an automate these via settings in the app itself the better.

    Finally, the Tracking protection has the most real potential for undesired side effects such as blocking a few websites such as Forbes, which demands that you disable all ad blockers to view it.  I personally just avoid these sites, since that's not their decision to make, but if this becomes a problem you can try and determine whether there's a workaround for the rare few requiring this.  Most of the few I've seen have been lesser sites I don't care about, while I only discovered Forbes due to a friend who likes to include links to their articles on occasion, in which case I usually just search for a similar article title elsewhere.

    Note that any engineering or technical choice is always a tradeoff, with some desired result balanced by some possibly less desired side effect.  That's the choices you'll need to make with these settings, since these are fundamentally the basis for the default configurations in later versions of Windows that have included them since their release.  This means that both more recent software and website design have already taken them into account, so I'd expect you to have few if any problems with most of them.

    I do on occasion see unexplained lags with some websites which I assume is either related to the ad blocking or possibly my choice of Advanced Privacy Settings to Always block Third-party Cookies, Always prompt First-party, with Always allow session cookies checked.  I didn't mention this last set of settings due to this potential as well as the fact these are really only related to privacy and not security.  Possibly changing the First-party setting to Accept might reduce these lags as well as the noise these prompts create, since this can often cause a delayed popup to display the prompt, but I chose to control the access these have to my browsing history.

    Sorry for the length, but as a small organization's administrator I know you'll spend far more time maintaining these systems in the long run.  My own history in security consulting for large, medium and small businesses as well as aiding a few friends and relatives with their personal systems has taught me a just as broad set of relatively simple solutions that along with proper updating and maintenance, can keep most systems safe with a minimum of added work.

    Good luck,

    Rob

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2017-05-28T19:34:58+00:00

    Rob, reading your replies is like a major tutorial in security!!! Feel like I'm in a classroom! :)  That's so great that you would take the time to share all of this info with me. You might have the impression that I know much more than I do about computers. Just a few years ago, I joined a computer group at our senior center. I've been tinkering with and reading about computers and their issues ever since; but I have to admit, so much of it is way beyond my grasp. What I'm pretty good at is troubleshooting, Googling, and following instructions to fix things. :) 

    I'll be printing out your replies (so I can adjust these settings, etc, step by step) and have already shared them with my fellow senior lab rats, most of whom have been using computers since the 70s, and are highly knowledgeable--way more than I. But I enjoy learning about them--and much of that is crisis driven, as in this latest instance.

    Thank you again, Rob, for sharing your knowledge with me and taking the time to write it all down!!

    Chris

    PS I should add: we have a computer lab of a dozen machines. They all have Windows 7 and 10, and some also have Linux on them, in partitions, to accommodate the various users' preferences and system familiarity. It's a lot to maintain, and we have a great team of folks who do this. But after reading your replies, I think we need to step up our security measures for greater protection. :)

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2017-05-29T07:29:45+00:00

    Chris, I was suggesting you start a new thread on one of those forums, with the same description of the issue, IF you want to get to the bottom of it. They won't give you generic answers, and only experts in malware can assist.

    They have various tools at their disposal for different things and guide ppl step by step. They also request you post log file with results from what those apps found. That way, they know what they're dealing with.

    Btw, I forgot to add.. for the Hosts file, you should Stop the DNS Client Service and set it to manual or disable it. Reason is, Hosts files over a certain size can slow down systems. It's on that pg. for Windows 7. You can also request to be notified by email, when a new Hosts file is available. HostMan is just a standalone app, no install necessary.

    A couple other things you can do, which are quite simple. One is to install SpywareBlaster, update it and enable protection. It does NOT need to be running to protect your system. https://www.brightfort.com/spywareblaster.html

    Another is to use Open DNS https://www.opendns.com/ It's more secure other Domain Name Servers, and will actually prevent you from going to a phishing site.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2017-05-29T08:53:07+00:00

    Rob, are you suggesting it'd be better security-wise to entrust our systems to Microsoft's offerings? IE has been the greatest security threat to Windows since 9x. Since IE is literally part of the OS, this makes the entire system vulnerable. MS finally had the decency to strip it from Windows, with 10, albeit a few OS's later than it should have. 

    Anyway, I disagree with you on that. On the contrary, we need a browser like Firefox to protect us from IE's vulnerabilities. ;-) Mozilla now puts out small, incremental updates and quite often sometimes. A recent wk. I had two updates. They're non-intrusive, and you can continue with your browsing. Plus, they don't just start updating, they give you a choice.. ask later or update now.

    There are better free, 3rd party apps to take place of some of MS's products, esp when it comes to security. I can see how it would make your job easier, if your clients stick with M$ though. As for Adobe, Flash is still a great security risk and needs replaced. Nothing about that has improved. Then there's that bloated Reader. There's an open source PDF reader, which I use, called Sumatra. All there is to it is the 6 MB executable. Simply brilliant. Well-known doesn't necessarily equal better. Norton's AV is another example of bloated.

    Edit: Who needs MS Office, when there are a couple good alts. like LibreOffice and Open Office?

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2017-05-29T14:53:17+00:00

    Thank you, Carol. Lots of good suggestions and information. Perhaps I will post to Malwarebytes and see what they have to say...

    Was this answer helpful?

    0 comments No comments