Fake Virus Alerts, Browser Hijacking (Firefox and IE11) Using Windows 7

Anonymous
2017-05-27T01:58:55+00:00

Hi, All.   I'm trying to resolve a problem on a computer used in our senior group. Something called "Fireball" showed up on this machine. One of the other "lab rats" deleted it--I don't know exactly how they did it. What's been occurring since is this: several different kinds of fake virus alerts (to call a phone number for help--some say "Microsoft") which can be closed using Task Manager; apparent browser hijacking, because a second tab immediately opens and I can see numerous website names rotating through (google-mirror.com, ww11.home.google-mirror..., park.above.com, clicksads.club, one that says ALERT and covers the screen with **** behind a Zeus Virus alert (****.com shows in the lower left corner), with RDN/YahLover.worm... in front of it! I restricted cookies, and there are tons of pop-ups asking to save cookies: tawk.to, securityupdate9900x112.com, utm.z3wl.com, shoppons.site, scorecardresearch.com, hom.google-miriror.com, inclk.com, wkee.reddhon.com, rainbow-networks.com, com-safety-jx30.club, google.co.in, and instantcasualconnections.com (so far). There are no weird programs on the computer--that show up.

Task Manager closes these alert pop-ups and the computer is usable, but we found that every 24 hours it starts all over again. Is this some kind of Scheduled Task??

I believe the virus alerts are fake. I'm assuming someone downloaded something that was bundled with crapware. I've checked the toolbars and extensions--nothing seems wrong there. No add-ons show. I've run Malwarebytes, Adwcleaner, and CCleaner, in addition to regular scans by Defender. I have reset IE to default settings, deleted cookies, history. I've tried using SysInternals Process Explorer and Autoruns--but I don't really know what I'm looking for. I figure something weird, but I've read malware can be hidden pretty much everywhere these days. The Registry seems okay--but same story: nothing jumps out at me.

I did a system restore today, but it only went back a month, and the weirdness was still there after restart. Tomorrow I plan to run sfc /scannow and the MS System Update Readiness Tool. Will that be a waste of time? Should I just reinstall the OS?? I wonder if deleting the user accounts would get rid of any junk??

I'm out of ideas. I enjoy a challenge, but come on!! This stuff is so devious! Any thoughts would be much appreciated. I've gotten great help here with past problems... Thanks for listening...

Chris

Windows for home | Previous Windows versions | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

44 answers

Sort by: Most helpful
  1. Anonymous
    2017-05-28T14:57:36+00:00

    Hey, Carol. I read several of the posts on MalwareBytes' support forum, but didn't find anything as specific as what I've been reading here. Their answers are pretty generic, and I couldn't find any posts addressing my specific issues.

    Yes, I checked for browser extensions and add-ons, but didn't find anything suspicious looking. I pulled up that link to Fireball, too. Not much info, but I suspect that's what it was, or some incarnation of it.

    Thank you for taking the time to respond, Carol. You've given me some good info.  Perhaps going forward, we can tighten up our security measures and prevent this kind of thing from happening again.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2017-05-28T14:33:40+00:00

    All I can say, Rob, is wow!! Thank you so much for your very comprehensive explanation of these settings, which I have never used. Following your great instructions, I should be able to manage these. It is a 64-bit system.

    We have a dozen computers that our group (and the public) use, so I'm thinking we should make it a priority to set up these settings on all of them.

    Thanks, again, Rob, for your lengthy and understandable explanation. Computer #12 may be a lost cause, but we should be able to secure the rest of them taking these actions.

    Happy Memorial Day!

    Chris

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2017-05-28T14:24:55+00:00

    Thanks for this, Carol.

    Chris

    Was this answer helpful?

    0 comments No comments
  4. Rob Koch 26,175 Reputation points Volunteer Moderator
    2017-05-28T06:52:32+00:00

    Chris,

    I see that you've likely exhausted your cleanup options besides re-installing Windows, which in the case of multiple unknown infections is typically the best course of action anyway.  So from here the point is to try avoiding the same problems in the future.

    In the past I had played with various tools like the hosts file, though I avoided alternative browsers for the reason that any software added to a system simply adds to the potential vulnerabilities as well, since all software and especially browsers inherently have these.  Unfortunately, though a hosts file may deal with relatively static sites, it doesn't help with the dynamically changing websites from which many of the malicious items are delivered today.

    Also note that the browser which Microsoft security applications protect most effectively is always the latest version provided with that operating system.  Any 3rd-party browser will require the security add-ons which perform similar functions to those included with Windows 7 such as SmartScreen Filter (anti-malware/phishing) and the close integration that Microsoft Security Essentials provides with Internet Explorer for scripting and downloads.  All  of this simply adds to the support burden, which may be ok if it's your personal PC, but doesn't scale well when multiple PCs are being managed individually.

    If you want to keep a Windows 7 system as tightly secured as possible, the best methods are to invoke the various built-in configuration items that Microsoft has chosen to keep lax for reasons of compatibility and simplicity for users.  There are only a handful of these, but they can have a great impact most especially on the security of the browser and downloads regardless of the source.

    First, if the software normally installed on the PC is limited to the core Windows applications and major name software applications like Office or Adobe products, it should be possible to configure Windows - Data Execution Prevention to "Turn on DEP for all programs and services except those I select".  This setting is found under Control Panel, System, Advanced System settings, Performance Settings button, Data Execution Prevention tab.

    This DEP setting is compatible with most recent software, but since it doesn't allow badly behaved software that attempts to execute code in data areas, some malware will be blocked by this setting as well.

    The next setting can improve the security of Internet Explorer 11 on Windows 7, but only if it's the 64-bit version which you didn't specify above.  This is the Enable Enhanced Protected Mode setting in the IE11 Internet Options, Advanced tab, security section.  Though this Enhanced Protected Mode (EPM) blog article was written when it was first released with Internet Explorer 10 on Windows 8, the descriptions and operation are functionally the same with IE11 on 64-bit Windows 7.

    In general, the EPM setting runs everything in Internet Explorer in 64-bit mode by default, causing 32-bit add-ons to fail to run and blocking many things that are badly behaved due to various protections it includes which the article details.  This causes many of the less well written attacks on the browser to fail, which since malware is often written as quickly and simply as possible, is more common than you might think.

    None of the above settings will stop a PC user from downloading or trying to install software either on purpose or due to social engineering, but they just might manage to block some of this from successfully installing or changing the system when they do, especially the drive-by exploits often used to quietly install undesired software.

    There's another pair of settings I use that blocks most of the advertising networks which are often used to deliver both the browser hijacker type of pop-ups, as well as some drive-by downloads, and operates similar to the popular AdBlock extension.  This uses the "Send Do Not Track requests to sites you visit in Internet Explorer" setting in Internet Options, Advanced tab, security, in tandem with the free to install EasyPrivacy Tracking Protection list in manage Add-ons.

    Though this combination does aid in blocking some of the advertising network delivered malicious attacks including many of the seemingly random pop-ups, it of course also blocks much of the targeted advertising these same networks provide.  So if your users actually want these ads this may not be an effective method, but if they all use the same user account, then personalization may not matter and this also has the side effect of blocking many of these often annoying ads altogether or at least limiting them to a single static box.

    You might still want to try combining the MVP hosts file with some of these other protections, but since the above are either a one-time setting or in the case of the EasyPrivacy tracking protection list automatically updated by the IE11 browser itself, they don't require any manual maintenance as is the case with the hosts file.

    Rob

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2017-05-28T06:30:28+00:00

    The Hosts file suggestion was more to prevent future problems, but it may help in this situation too. Malware writers have also been known to hijack hosts files in the past.

    It's not as extensive as it appears. Download the .zip file and (what I do) is go to the location it'll reside in, which is C:\Windows\System32\drivers\etc . Unzip it, and that's about it. It'll make a backup of your current Hosts (no ext.) file. Or you can run the .bat file to put it in place. I also go to Properties and mark "read only".

    It's just a list of domains, which is updated monthly. Rather than going to one of those domains, it directs you back to Local Host. You can disable the Hosts file at any time using HostsMan. You can use it to update and view or edit it.

    Was this answer helpful?

    0 comments No comments