Jump to content

Mysterious Website Popping Up Randomly

So I'm not sure if this is the correct forum or even website to ask this, but this website's been popping up randomly from now to when I built my PC.

 

Here's the link: http://sh.st/AeotZ

 

and after clicking the "Skip this ad" button, it takes me to this page: http://www.symantec.com/connect/blogs/download-insight-sep-121

 

Any next steps? Thanks.

CPU: AMD A8-6600K 3.9GHz(OCed to 4.5GHz) Quad-Core Processor
CPU Cooler: Cooler Master Hyper 212 EVO 82.9 CFM Sleeve Bearing CPU Cooler
Motherboard: MSI A88XM-E45 Micro ATX FM2+ Motherboard
Memory: Kingston HyperX Fury Blue 8GB (2 x 4GB) DDR3-1600 Memory 
Storage: Kingston SSDNow V300 Series 120GB 2.5" Solid State Drive
Storage: Seagate Barracuda 120GB 3.5" Internal Hard Drive
Video Card: EVGA GeForce GTX 760 4GB Dual FTW ACX Video Card
Case: Silverstone TJ09-BW ATX Full Tower Case
Power Supply: EVGA SuperNOVA NEX 650W 80+ Gold Certified Fully-Modular ATX Power Supply

Link to comment
Share on other sites

Link to post
Share on other sites

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Windows7ge said:

I'd run a anti-virus scan. Malware scan too just to be safe.

Ran Avast full system scan, says no threat detected.

CPU: AMD A8-6600K 3.9GHz(OCed to 4.5GHz) Quad-Core Processor
CPU Cooler: Cooler Master Hyper 212 EVO 82.9 CFM Sleeve Bearing CPU Cooler
Motherboard: MSI A88XM-E45 Micro ATX FM2+ Motherboard
Memory: Kingston HyperX Fury Blue 8GB (2 x 4GB) DDR3-1600 Memory 
Storage: Kingston SSDNow V300 Series 120GB 2.5" Solid State Drive
Storage: Seagate Barracuda 120GB 3.5" Internal Hard Drive
Video Card: EVGA GeForce GTX 760 4GB Dual FTW ACX Video Card
Case: Silverstone TJ09-BW ATX Full Tower Case
Power Supply: EVGA SuperNOVA NEX 650W 80+ Gold Certified Fully-Modular ATX Power Supply

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, RandomRestore said:

Ran Avast full system scan, says no threat detected.

When does it happen exactly? When idling at desktop? In a browser? Does it happen when you click on links?

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, RandomRestore said:

Ran Avast full system scan, says no threat detected.

Run malwarebytes. might find something. 

Also, if using chrome, check your extensions. Some of them bring adware with them. 

 

Fine you want the PSU tier list? Have the PSU tier list: https://linustechtips.com/main/topic/1116640-psu-tier-list-40-rev-103/

 

Stille (Desktop)

Ryzen 9 3900XT@4.5Ghz - Cryorig H7 Ultimate - 16GB Vengeance LPX 3000Mhz- MSI RTX 3080 Ti Ventus 3x OC - SanDisk Plus 480GB - Crucial MX500 500GB - Intel 660P 1TB SSD - (2x) WD Red 2TB - EVGA G3 650w - Corsair 760T

Evoo Gaming 15"
i7-9750H - 16GB DDR4 - GTX 1660Ti - 480GB SSD M.2 - 1TB 2.5" BX500 SSD 

VM + NAS Server (ProxMox 6.3)

1x Xeon E5-2690 v2  - 92GB ECC DDR3 - Quadro 4000 - Dell H310 HBA (Flashed with IT firmware) -500GB Crucial MX500 (Proxmox Host) Kingston 128GB SSD (FreeNAS dev/ID passthrough) - 8x4TB Toshiba N300 HDD

Toys: Ender 3 Pro, Oculus Rift CV1, Oculus Quest 2, about half a dozen raspberry Pis (2b to 4), Arduino Uno, Arduino Mega, Arduino nano (x3), Arduino nano pro, Atomic Pi. 

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Windows7ge said:

When does it happen exactly? When idling at desktop? In a browser? Does it happen when you click on links?

It just happens randomly, but not frequently. Like probably just once a day.

CPU: AMD A8-6600K 3.9GHz(OCed to 4.5GHz) Quad-Core Processor
CPU Cooler: Cooler Master Hyper 212 EVO 82.9 CFM Sleeve Bearing CPU Cooler
Motherboard: MSI A88XM-E45 Micro ATX FM2+ Motherboard
Memory: Kingston HyperX Fury Blue 8GB (2 x 4GB) DDR3-1600 Memory 
Storage: Kingston SSDNow V300 Series 120GB 2.5" Solid State Drive
Storage: Seagate Barracuda 120GB 3.5" Internal Hard Drive
Video Card: EVGA GeForce GTX 760 4GB Dual FTW ACX Video Card
Case: Silverstone TJ09-BW ATX Full Tower Case
Power Supply: EVGA SuperNOVA NEX 650W 80+ Gold Certified Fully-Modular ATX Power Supply

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Brink2Three said:

Run malwarebytes. might find something. 

Also, if using chrome, check your extensions. Some of them bring adware with them. 

 

 

Alright, I will. Do I run threat or full system scan?

CPU: AMD A8-6600K 3.9GHz(OCed to 4.5GHz) Quad-Core Processor
CPU Cooler: Cooler Master Hyper 212 EVO 82.9 CFM Sleeve Bearing CPU Cooler
Motherboard: MSI A88XM-E45 Micro ATX FM2+ Motherboard
Memory: Kingston HyperX Fury Blue 8GB (2 x 4GB) DDR3-1600 Memory 
Storage: Kingston SSDNow V300 Series 120GB 2.5" Solid State Drive
Storage: Seagate Barracuda 120GB 3.5" Internal Hard Drive
Video Card: EVGA GeForce GTX 760 4GB Dual FTW ACX Video Card
Case: Silverstone TJ09-BW ATX Full Tower Case
Power Supply: EVGA SuperNOVA NEX 650W 80+ Gold Certified Fully-Modular ATX Power Supply

Link to comment
Share on other sites

Link to post
Share on other sites

Malawarebytes

 

Most anti-virus don't pick up malaware unless you pay for one of those $90 ones but who pays $90 when you have Malawarebytes for free

Insert   Dank   Signature   Here.

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, RandomRestore said:

Alright, I will. Do I run threat or full system scan?

I'd do full system.

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Windows7ge said:

I'd do full system.

Yep That

 

Fine you want the PSU tier list? Have the PSU tier list: https://linustechtips.com/main/topic/1116640-psu-tier-list-40-rev-103/

 

Stille (Desktop)

Ryzen 9 3900XT@4.5Ghz - Cryorig H7 Ultimate - 16GB Vengeance LPX 3000Mhz- MSI RTX 3080 Ti Ventus 3x OC - SanDisk Plus 480GB - Crucial MX500 500GB - Intel 660P 1TB SSD - (2x) WD Red 2TB - EVGA G3 650w - Corsair 760T

Evoo Gaming 15"
i7-9750H - 16GB DDR4 - GTX 1660Ti - 480GB SSD M.2 - 1TB 2.5" BX500 SSD 

VM + NAS Server (ProxMox 6.3)

1x Xeon E5-2690 v2  - 92GB ECC DDR3 - Quadro 4000 - Dell H310 HBA (Flashed with IT firmware) -500GB Crucial MX500 (Proxmox Host) Kingston 128GB SSD (FreeNAS dev/ID passthrough) - 8x4TB Toshiba N300 HDD

Toys: Ender 3 Pro, Oculus Rift CV1, Oculus Quest 2, about half a dozen raspberry Pis (2b to 4), Arduino Uno, Arduino Mega, Arduino nano (x3), Arduino nano pro, Atomic Pi. 

Link to comment
Share on other sites

Link to post
Share on other sites

13 minutes ago, Brink2Three said:

Yep That

 

 

Alright thanks, I will run it overnight and try to get results first thing tomorrow.

CPU: AMD A8-6600K 3.9GHz(OCed to 4.5GHz) Quad-Core Processor
CPU Cooler: Cooler Master Hyper 212 EVO 82.9 CFM Sleeve Bearing CPU Cooler
Motherboard: MSI A88XM-E45 Micro ATX FM2+ Motherboard
Memory: Kingston HyperX Fury Blue 8GB (2 x 4GB) DDR3-1600 Memory 
Storage: Kingston SSDNow V300 Series 120GB 2.5" Solid State Drive
Storage: Seagate Barracuda 120GB 3.5" Internal Hard Drive
Video Card: EVGA GeForce GTX 760 4GB Dual FTW ACX Video Card
Case: Silverstone TJ09-BW ATX Full Tower Case
Power Supply: EVGA SuperNOVA NEX 650W 80+ Gold Certified Fully-Modular ATX Power Supply

Link to comment
Share on other sites

Link to post
Share on other sites

Scan finished. Found a few PUP registry values. Removed them, restarted my computer, and if any strange website pops up, I'll let you guys know.

CPU: AMD A8-6600K 3.9GHz(OCed to 4.5GHz) Quad-Core Processor
CPU Cooler: Cooler Master Hyper 212 EVO 82.9 CFM Sleeve Bearing CPU Cooler
Motherboard: MSI A88XM-E45 Micro ATX FM2+ Motherboard
Memory: Kingston HyperX Fury Blue 8GB (2 x 4GB) DDR3-1600 Memory 
Storage: Kingston SSDNow V300 Series 120GB 2.5" Solid State Drive
Storage: Seagate Barracuda 120GB 3.5" Internal Hard Drive
Video Card: EVGA GeForce GTX 760 4GB Dual FTW ACX Video Card
Case: Silverstone TJ09-BW ATX Full Tower Case
Power Supply: EVGA SuperNOVA NEX 650W 80+ Gold Certified Fully-Modular ATX Power Supply

Link to comment
Share on other sites

Link to post
Share on other sites

No strange websites have popped up in the past two days, quite good news. Everything seems to be working quite nicely. If you guys can still see this, thank you!

 

However, two-days is a somewhat short period of time, so if an mysterious website pops up again, I will require further assistance, but you guys have still done a lot for me so I'm very thankful anyways. Have a good day!

CPU: AMD A8-6600K 3.9GHz(OCed to 4.5GHz) Quad-Core Processor
CPU Cooler: Cooler Master Hyper 212 EVO 82.9 CFM Sleeve Bearing CPU Cooler
Motherboard: MSI A88XM-E45 Micro ATX FM2+ Motherboard
Memory: Kingston HyperX Fury Blue 8GB (2 x 4GB) DDR3-1600 Memory 
Storage: Kingston SSDNow V300 Series 120GB 2.5" Solid State Drive
Storage: Seagate Barracuda 120GB 3.5" Internal Hard Drive
Video Card: EVGA GeForce GTX 760 4GB Dual FTW ACX Video Card
Case: Silverstone TJ09-BW ATX Full Tower Case
Power Supply: EVGA SuperNOVA NEX 650W 80+ Gold Certified Fully-Modular ATX Power Supply

Link to comment
Share on other sites

Link to post
Share on other sites

  • 2 weeks later...

Just signed up to say I have the same issue (just downloaded Malwarebytes!), and have noticed that the issue is related to plugging my laptop in to charge!
 Each night when my battery gets low, I plug it in, then Hello! There's a new tab open.

Link to comment
Share on other sites

Link to post
Share on other sites

29 minutes ago, VeganPirate said:

Just signed up to say I have the same issue (just downloaded Malwarebytes!), and have noticed that the issue is related to plugging my laptop in to charge!
 Each night when my battery gets low, I plug it in, then Hello! There's a new tab open.

Try all the steps mentioned here (Anti virus, malwarebytes) and you can also check your Chrome (or FireFox) extensions, maybe there is something malicious there.

"We're all in this together, might as well be friends" Tom, Toonami.

 

mini eLiXiVy: my open source 65% mechanical PCB, a build log, PCB anatomy and discussing open source licenses: https://linustechtips.com/topic/1366493-elixivy-a-65-mechanical-keyboard-build-log-pcb-anatomy-and-how-i-open-sourced-this-project/

 

mini_cardboard: a 4% keyboard build log and how keyboards workhttps://linustechtips.com/topic/1328547-mini_cardboard-a-4-keyboard-build-log-and-how-keyboards-work/

Link to comment
Share on other sites

Link to post
Share on other sites

On June 30, 2016 at 5:54 AM, VeganPirate said:

Just signed up to say I have the same issue (just downloaded Malwarebytes!), and have noticed that the issue is related to plugging my laptop in to charge!
 Each night when my battery gets low, I plug it in, then Hello! There's a new tab open.

Might be related to bloatware that your PC came with, try using PCDecrapifier, a self-contained program that scans and removes bloat and crapware pre installed by the manufacturer of your PC.

 

https://www.pcdecrapifier.com

 

If this doesn't work, run a full system scan with malwarebytes and remove anything that shows up, unless you trust any of the results and know that it is a false positive.

 

Your last resort would probably be to go to a malware removal forum and ask there.

 

I don't really have too much experience with malware, but hey, welcome to the LTT forums. You will notice that the members of this forum are anything but toxic, and are pretty helpful guys. Hope you enjoy it here!

CPU: AMD A8-6600K 3.9GHz(OCed to 4.5GHz) Quad-Core Processor
CPU Cooler: Cooler Master Hyper 212 EVO 82.9 CFM Sleeve Bearing CPU Cooler
Motherboard: MSI A88XM-E45 Micro ATX FM2+ Motherboard
Memory: Kingston HyperX Fury Blue 8GB (2 x 4GB) DDR3-1600 Memory 
Storage: Kingston SSDNow V300 Series 120GB 2.5" Solid State Drive
Storage: Seagate Barracuda 120GB 3.5" Internal Hard Drive
Video Card: EVGA GeForce GTX 760 4GB Dual FTW ACX Video Card
Case: Silverstone TJ09-BW ATX Full Tower Case
Power Supply: EVGA SuperNOVA NEX 650W 80+ Gold Certified Fully-Modular ATX Power Supply

Link to comment
Share on other sites

Link to post
Share on other sites

  • 2 weeks later...

I have the same problem, and manage to solve it . Here's the solution.

check if you have the following folder:  C:\ProgramData\Bonanza\

delete it.

under computer management - task scheduler

check if you have the following item "rundll", it runs every hour, disable it or delete it.

you should find the item "PPI Update", it's installed by KMSpico

it opens this website "http://insightlk.com/download/index.php?mn=9995"

which then jumps to "http://sh.st/AeotZ"

 

delete or disable this item

 

Link to comment
Share on other sites

Link to post
Share on other sites

  • 1 month later...
On 7/14/2016 at 6:32 AM, manfred_exz said:

I have the same problem, and manage to solve it . Here's the solution.

check if you have the following folder:  C:\ProgramData\Bonanza\

delete it.

under computer management - task scheduler

check if you have the following item "rundll", it runs every hour, disable it or delete it.

you should find the item "PPI Update", it's installed by KMSpico

it opens this website "http://insightlk.com/download/index.php?mn=9995"

which then jumps to "http://sh.st/AeotZ"

 

delete or disable this item

 

You are quite the genius sir,Thank you for helping all the pirates in us.

System

  • CPU
    i3 3220 3.3GHz
  • Motherboard
    H61H2-MV
  • RAM
    8GB no name
  • GPU
    Radeon HD 4870
  • Case
    Thermaltake Core V21
  • Storage
    1TB HDD, 700gb HDD, 320gb HDD and 256gb SSD
  • PSU
    Corsair CX600
  • Display(s)
    Flatron L1960TR , MAG MS776I , ViewSonic VA903m ( all of them are 1280x1024,dad found em) and a Fujicom FJ-32V TV
  • Cooling
    1 200M front fan, and unknowen CPU tower(low profile)
  • Keyboard
    HP QY776AT
  • Mouse
    LUOM G10
  • Sound
    Jamo E 4 CEN, Jamo E470 and Jamo E410 with a KENWOOD S505D
  • Operating System
    Windows 10 Pro N
Link to comment
Share on other sites

Link to post
Share on other sites

  • 1 month later...

Yes, i'm necro because this dude has the best answer & i'd like to confirm it :)

 

paid malwarebytes isn't finding a damn thing (license via work don't hate) for me on win10, popup in chrome. 

On 7/13/2016 at 11:32 PM, manfred_exz said:

I have the same problem, and manage to solve it . Here's the solution.

check if you have the following folder:  C:\ProgramData\Bonanza\

delete it.

under computer management - task scheduler

check if you have the following item "rundll", it runs every hour, disable it or delete it.

you should find the item "PPI Update", it's installed by KMSpico

it opens this website "http://insightlk.com/download/index.php?mn=9995"

which then jumps to "http://sh.st/AeotZ"

 

delete or disable this item

 

this is what happens when your girl uses your windows profile. smh. 

 

in my instance the task is set to run @ 4:53 every day 

 

you'll most likely find other garbage you can delete from the task scheduler while removing this item. 

Link to comment
Share on other sites

Link to post
Share on other sites

  • 4 weeks later...
On 7/13/2016 at 10:32 PM, manfred_exz said:

I have the same problem, and manage to solve it . Here's the solution.

check if you have the following folder:  C:\ProgramData\Bonanza\

delete it.

under computer management - task scheduler

check if you have the following item "rundll", it runs every hour, disable it or delete it.

you should find the item "PPI Update", it's installed by KMSpico

it opens this website "http://insightlk.com/download/index.php?mn=9995"

which then jumps to "http://sh.st/AeotZ"

 

delete or disable this item

 

I specially registered to this website, just to say "thank you" to this dude. This problem is not big, but it's big enough to drive you crazy. And I just open the Scheduled Task on windows and found PPI Update, I manually run it and the pop up happened. So I'm nearly 100% sure that disabling it will solve this problem. 

Link to comment
Share on other sites

Link to post
Share on other sites

  • 2 weeks later...

I stepping stone to this thread, although it is not very recent, for those who had yet to come across this problem (which is anything but uncommon)

 

JFYI, there's no need to run anti-malwares in order to remove sh.st junks.

 

Just check under C:\Windows\System32\Tasks and you have to find a task named as "PPI Update". It contains the following code:

 

    <Exec>
      <Command>C:\Windows\explorer.exe</Command>
      <Arguments>"http://insightcdn.online/download/index.php?mn=9995"</Arguments>
    </Exec>

That URL redirects to sh.st/AeotZ

 

Anyway using Malawarebytes Anti-Malware to perform a periodical scan is one of the basic rules to always keep in mind ;) 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Odd how it directed to Symantec's blog, maybe they were doing it to make it seem like the malware wasn't really malware, even though that wouldn't work well.  

Glad it's fixed anyway, I would run a scan with Norton Power Eraser https://security.symantec.com/nbrt/npe.aspx  No matter what anyone says about Norton it's used widely in the enterprise, and works well, lately Symantec's signatures have been fantastic, and NPE (Norton power eraser) can scan for bootkits by loading before Windows does.  This is pretty important.  

 

While it's rare you have anything beyond this basic shitty junk on your system which was removed, A lot of malware actively downloads other malware to your PC such as this, it's possible that the malware was removed previously or that the malware was downloaded and then the executable for the downloader deleted itself and used a registry key instead of a data file or executable file which would have been more obvious and less effecient.  

 

I know this isn't much help, but I hope it.  Just look out for malwarebytes too, it's good but it's not a fully fledged antivirus, and is not a scanner that I would suggest against serious malware,  good for home use though.  

Link to comment
Share on other sites

Link to post
Share on other sites

On 24/11/2016 at 5:23 AM, Mike_The_B0ss said:

Odd how it directed to Symantec's blog, maybe they were doing it to make it seem like the malware wasn't really malware, even though that wouldn't work well.  

Glad it's fixed anyway, I would run a scan with Norton Power Eraser https://security.symantec.com/nbrt/npe.aspx  No matter what anyone says about Norton it's used widely in the enterprise, and works well, lately Symantec's signatures have been fantastic, and NPE (Norton power eraser) can scan for bootkits by loading before Windows does.  This is pretty important.  

 

While it's rare you have anything beyond this basic shitty junk on your system which was removed, A lot of malware actively downloads other malware to your PC such as this, it's possible that the malware was removed previously or that the malware was downloaded and then the executable for the downloader deleted itself and used a registry key instead of a data file or executable file which would have been more obvious and less effecient.  

 

I know this isn't much help, but I hope it.  Just look out for malwarebytes too, it's good but it's not a fully fledged antivirus, and is not a scanner that I would suggest against serious malware,  good for home use though.  

I ran a scan using NPE and did find a few files, but I'm guessing that they were false positives since I have memory of installing those applications and when I uploaded them to VirusTotal, they looked for the most part; clean. I did find a problem with a file called HOSTS in a subdirectory in the \Windows folder, but I have past memory that I edited that file to block additional IPs, since I didn't want Windows to be tracking me.

CPU: AMD A8-6600K 3.9GHz(OCed to 4.5GHz) Quad-Core Processor
CPU Cooler: Cooler Master Hyper 212 EVO 82.9 CFM Sleeve Bearing CPU Cooler
Motherboard: MSI A88XM-E45 Micro ATX FM2+ Motherboard
Memory: Kingston HyperX Fury Blue 8GB (2 x 4GB) DDR3-1600 Memory 
Storage: Kingston SSDNow V300 Series 120GB 2.5" Solid State Drive
Storage: Seagate Barracuda 120GB 3.5" Internal Hard Drive
Video Card: EVGA GeForce GTX 760 4GB Dual FTW ACX Video Card
Case: Silverstone TJ09-BW ATX Full Tower Case
Power Supply: EVGA SuperNOVA NEX 650W 80+ Gold Certified Fully-Modular ATX Power Supply

Link to comment
Share on other sites

Link to post
Share on other sites

  • 2 months later...
I was having this problem for a long time looking for a solution to it, and now I found in your page and thank you to the person who placed the solution member manfred_exz he is my hero.
Link to comment
Share on other sites

Link to post
Share on other sites

Guest
This topic is now closed to further replies.

×