Jump to content

Possible Browser Hijack?

KayTees

Long story short, don't know whenever I sign into my user account and open Chrome. I get redirected to some russian mail site.

No clue on how I got this. Ran MalwareBytes, got rid of the folder in my /Local, resetted browser settings, signed out of Google account, removed all extensions but no luck.

599c892fc9d6e3653999df89dfd7304e.png

Main Rig

 

Case: NZXT H440 White | CPU: Intel Core i5-4690K @5.2GHz | CPU Cooler: Corsair H80i Hydro Series | Motherboard: MSI Z97S Krait Edition | RAM: HyperX Fury White & Black Series 16GB (4x4GB) OC to 2133MHz | Graphics Card: Zotac GeForce GTX 980 Ti ArcticStorm | SSD: Intel 730 Series 480GB & Samsung 840 256GB | HDD: Seagate Barracuda 2TB 7200rpm | PSU: EVGA 750W Supernova G2 80+ Gold | Display: BenQ XL2420G & Samsung S20D300 | Headset: Corsair 1500 | Mouse: Logitech G700S | Keyboard: Corsair Vengeance K70 Silver RED LED

 XENON Build:  

 

Intel Xeon E3-1230 V2 @3.3GHz | Intel DZ68BC | Corsair Dominator Platinum 2x4GB 1866MHz | Kingston HyperX 3k 240GB | MSI GeForce GTX 680 | Fractal Design Define R4 Titanium Grey | Seasonic 520W 80+ Platinum Fanless

Office Build:

 

Case: Fractal Focus G White | CPU: i5-8600K | CPU Cooler: Cooler Master Hyper 212 Evo | Motherboard: MSI Z370-A PRO | RAM: Corsair LPX 16GB-2666 | GPU: MSI GTX 1060 6GB GAMING X | SSD: Kingston A400 240GB | HDD: Seagate Barracuda 2TB 7200rpm | PSU: EVGA BT 450W+ Bronze

 

Phone

 

iPhone XS Max 512GB Gold

 

Link to comment
Share on other sites

Link to post
Share on other sites

did you install pirated game on your pc?

Amd phenom ii x4 955 Asus crosshair iv formula Kingston hyperx fury 8GB 1600mhz ASUS Radeon R9 280X DirectCU II
Cooler master haf xb evo Antec 750w 500gb wd black BenQ gw2760hs Samsung 850 EVO 250GB 2.5" Solid State Drive 

Link to comment
Share on other sites

Link to post
Share on other sites

did you install pirated game on your pc?

Nope, no pirated games. 

Main Rig

 

Case: NZXT H440 White | CPU: Intel Core i5-4690K @5.2GHz | CPU Cooler: Corsair H80i Hydro Series | Motherboard: MSI Z97S Krait Edition | RAM: HyperX Fury White & Black Series 16GB (4x4GB) OC to 2133MHz | Graphics Card: Zotac GeForce GTX 980 Ti ArcticStorm | SSD: Intel 730 Series 480GB & Samsung 840 256GB | HDD: Seagate Barracuda 2TB 7200rpm | PSU: EVGA 750W Supernova G2 80+ Gold | Display: BenQ XL2420G & Samsung S20D300 | Headset: Corsair 1500 | Mouse: Logitech G700S | Keyboard: Corsair Vengeance K70 Silver RED LED

 XENON Build:  

 

Intel Xeon E3-1230 V2 @3.3GHz | Intel DZ68BC | Corsair Dominator Platinum 2x4GB 1866MHz | Kingston HyperX 3k 240GB | MSI GeForce GTX 680 | Fractal Design Define R4 Titanium Grey | Seasonic 520W 80+ Platinum Fanless

Office Build:

 

Case: Fractal Focus G White | CPU: i5-8600K | CPU Cooler: Cooler Master Hyper 212 Evo | Motherboard: MSI Z370-A PRO | RAM: Corsair LPX 16GB-2666 | GPU: MSI GTX 1060 6GB GAMING X | SSD: Kingston A400 240GB | HDD: Seagate Barracuda 2TB 7200rpm | PSU: EVGA BT 450W+ Bronze

 

Phone

 

iPhone XS Max 512GB Gold

 

Link to comment
Share on other sites

Link to post
Share on other sites

run Malwarebytes

Archangel (Desktop) CPU: i5 4590 GPU:Asus R9 280  3GB RAM:HyperX Beast 2x4GBPSU:SeaSonic S12G 750W Mobo:GA-H97m-HD3 Case:CM Silencio 650 Storage:1 TB WD Red
Celestial (Laptop 1) CPU:i7 4720HQ GPU:GTX 860M 4GB RAM:2x4GB SK Hynix DDR3Storage: 250GB 850 EVO Model:Lenovo Y50-70
Seraph (Laptop 2) CPU:i7 6700HQ GPU:GTX 970M 3GB RAM:2x8GB DDR4Storage: 256GB Samsung 951 + 1TB Toshiba HDD Model:Asus GL502VT

Windows 10 is now MSX! - http://linustechtips.com/main/topic/440190-can-we-start-calling-windows-10/page-6

Link to comment
Share on other sites

Link to post
Share on other sites

Nope, no pirated games. 

free/pirated programs?

Amd phenom ii x4 955 Asus crosshair iv formula Kingston hyperx fury 8GB 1600mhz ASUS Radeon R9 280X DirectCU II
Cooler master haf xb evo Antec 750w 500gb wd black BenQ gw2760hs Samsung 850 EVO 250GB 2.5" Solid State Drive 

Link to comment
Share on other sites

Link to post
Share on other sites

check for adware and PUPs...

do a scan with malwarebytes and check all of your web browser shortcuts..

Link to comment
Share on other sites

Link to post
Share on other sites

Cyka Blyat? /s

 

Srs though check for Spyware and such. Check your ipconfig too.

Hiya :)

Feel free to quote me in a reply so I can see your reply :)

Link to comment
Share on other sites

Link to post
Share on other sites

you might have installed a probram that has adware on it.

 

it won't be necessarily detected by Malwarebytes. Some shady programs have these stuff attached 

|CPU: Intel i7-5960X @ 4.4ghz|MoBo: Asus Rampage V|RAM: 64GB Corsair Dominator Platinum|GPU:2-way SLI Gigabyte G1 Gaming GTX 980's|SSD:512GB Samsung 850 pro|HDD: 2TB WD Black|PSU: Corsair AX1200i|COOLING: NZXT Kraken x61|SOUNDCARD: Creative SBX ZxR|  ^_^  Planned Bedroom Build: Red Phantom [quadro is stuck in customs, still trying to find a cheaper way to buy a highend xeon]

Link to comment
Share on other sites

Link to post
Share on other sites

If malwarebytes keeps missing the thing, it could be this simple trick: the shortcut you use to open chrome could be changed to point to the URL instead of chrome.exe. Of course, in addition to the startup page being changed to it. I had it happen to me once after installing some free software. Malwarebytes spotted the executable that did the change but not the change itself. I finally found it after using the File Explorer search for the parts of the URL in question. I can't remember what the program or the URL was but the the URL contained the part number for my main SSD.

Link to comment
Share on other sites

Link to post
Share on other sites

This is what it says in the Extensions for IE.

ee4e1260f2de344eadfc31e99245c5c2.png

 

run Malwarebytes

That's the first thing I did.

 

free/pirated programs?

None installed recently.

 

check for adware and PUPs...

do a scan with malwarebytes and check all of your web browser shortcuts..

Tried doing that, no luck. 

 

If malwarebytes keeps missing the thing, it could be this simple trick: the shortcut you use to open chrome could be changed to point to the URL instead of chrome.exe. Of course, in addition to the startup page being changed to it. I had it happen to me once after installing some free software. Malwarebytes spotted the executable that did the change but not the change itself. I finally found it after using the File Explorer search for the parts of the URL in question. I can't remember what the program or the URL was but the the URL contained the part number for my main SSD.

 

Before it shows the "mail.ru" URL, there is something that redirects it but its too fast for me to cancel to reveal that link.

Main Rig

 

Case: NZXT H440 White | CPU: Intel Core i5-4690K @5.2GHz | CPU Cooler: Corsair H80i Hydro Series | Motherboard: MSI Z97S Krait Edition | RAM: HyperX Fury White & Black Series 16GB (4x4GB) OC to 2133MHz | Graphics Card: Zotac GeForce GTX 980 Ti ArcticStorm | SSD: Intel 730 Series 480GB & Samsung 840 256GB | HDD: Seagate Barracuda 2TB 7200rpm | PSU: EVGA 750W Supernova G2 80+ Gold | Display: BenQ XL2420G & Samsung S20D300 | Headset: Corsair 1500 | Mouse: Logitech G700S | Keyboard: Corsair Vengeance K70 Silver RED LED

 XENON Build:  

 

Intel Xeon E3-1230 V2 @3.3GHz | Intel DZ68BC | Corsair Dominator Platinum 2x4GB 1866MHz | Kingston HyperX 3k 240GB | MSI GeForce GTX 680 | Fractal Design Define R4 Titanium Grey | Seasonic 520W 80+ Platinum Fanless

Office Build:

 

Case: Fractal Focus G White | CPU: i5-8600K | CPU Cooler: Cooler Master Hyper 212 Evo | Motherboard: MSI Z370-A PRO | RAM: Corsair LPX 16GB-2666 | GPU: MSI GTX 1060 6GB GAMING X | SSD: Kingston A400 240GB | HDD: Seagate Barracuda 2TB 7200rpm | PSU: EVGA BT 450W+ Bronze

 

Phone

 

iPhone XS Max 512GB Gold

 

Link to comment
Share on other sites

Link to post
Share on other sites

Before it shows the "mail.ru" URL, there is something that redirects it but its too fast for me to cancel to reveal that link.

Nasty. :/ There's probably a rediction chain in there. So if you click back, it'll send you back to the last link which directs you back to 'mail.ru'. Usually it's possible to get to the root by clicking back several times very fast. There's probably more eloquent ways but I can't think of any right now. 

Link to comment
Share on other sites

Link to post
Share on other sites

Nasty. :/ There's probably a rediction chain in there. So if you click back, it'll send you back to the last link which directs you back to 'mail.ru'. Usually it's possible to get to the root by clicking back several times very fast. There's probably more eloquent ways but I can't think of any right now. 

Update:

 

The link before seems to be a avdile.ru link. Also found this "Account Unknown". Tried to remove it but doesn't allow me.

 

0027a92a7d023b60d3fabbc1988b707c.png

Main Rig

 

Case: NZXT H440 White | CPU: Intel Core i5-4690K @5.2GHz | CPU Cooler: Corsair H80i Hydro Series | Motherboard: MSI Z97S Krait Edition | RAM: HyperX Fury White & Black Series 16GB (4x4GB) OC to 2133MHz | Graphics Card: Zotac GeForce GTX 980 Ti ArcticStorm | SSD: Intel 730 Series 480GB & Samsung 840 256GB | HDD: Seagate Barracuda 2TB 7200rpm | PSU: EVGA 750W Supernova G2 80+ Gold | Display: BenQ XL2420G & Samsung S20D300 | Headset: Corsair 1500 | Mouse: Logitech G700S | Keyboard: Corsair Vengeance K70 Silver RED LED

 XENON Build:  

 

Intel Xeon E3-1230 V2 @3.3GHz | Intel DZ68BC | Corsair Dominator Platinum 2x4GB 1866MHz | Kingston HyperX 3k 240GB | MSI GeForce GTX 680 | Fractal Design Define R4 Titanium Grey | Seasonic 520W 80+ Platinum Fanless

Office Build:

 

Case: Fractal Focus G White | CPU: i5-8600K | CPU Cooler: Cooler Master Hyper 212 Evo | Motherboard: MSI Z370-A PRO | RAM: Corsair LPX 16GB-2666 | GPU: MSI GTX 1060 6GB GAMING X | SSD: Kingston A400 240GB | HDD: Seagate Barracuda 2TB 7200rpm | PSU: EVGA BT 450W+ Bronze

 

Phone

 

iPhone XS Max 512GB Gold

 

Link to comment
Share on other sites

Link to post
Share on other sites

This is what it says in the Extensions for IE.

ee4e1260f2de344eadfc31e99245c5c2.png

 

That's the first thing I did.

 

None installed recently.

 

Tried doing that, no luck. 

 

 

Before it shows the "mail.ru" URL, there is something that redirects it but its too fast for me to cancel to reveal that link.

That's IE, you are using Chrome. What about the extension in Chrome? I can't read.

Also, yup, you're infected.

CPU: AMD Ryzen 3700x / GPU: Asus Radeon RX 6750XT OC 12GB / RAM: Corsair Vengeance LPX 2x8GB DDR4-3200
MOBO: MSI B450m Gaming Plus / NVME: Corsair MP510 240GB / Case: TT Core v21 / PSU: Seasonic 750W / OS: Win 10 Pro

Link to comment
Share on other sites

Link to post
Share on other sites

That's IE, you are using Chrome. What about the extension in Chrome? I can't read.

Also, yup, you're infected.

Possible solution?

Main Rig

 

Case: NZXT H440 White | CPU: Intel Core i5-4690K @5.2GHz | CPU Cooler: Corsair H80i Hydro Series | Motherboard: MSI Z97S Krait Edition | RAM: HyperX Fury White & Black Series 16GB (4x4GB) OC to 2133MHz | Graphics Card: Zotac GeForce GTX 980 Ti ArcticStorm | SSD: Intel 730 Series 480GB & Samsung 840 256GB | HDD: Seagate Barracuda 2TB 7200rpm | PSU: EVGA 750W Supernova G2 80+ Gold | Display: BenQ XL2420G & Samsung S20D300 | Headset: Corsair 1500 | Mouse: Logitech G700S | Keyboard: Corsair Vengeance K70 Silver RED LED

 XENON Build:  

 

Intel Xeon E3-1230 V2 @3.3GHz | Intel DZ68BC | Corsair Dominator Platinum 2x4GB 1866MHz | Kingston HyperX 3k 240GB | MSI GeForce GTX 680 | Fractal Design Define R4 Titanium Grey | Seasonic 520W 80+ Platinum Fanless

Office Build:

 

Case: Fractal Focus G White | CPU: i5-8600K | CPU Cooler: Cooler Master Hyper 212 Evo | Motherboard: MSI Z370-A PRO | RAM: Corsair LPX 16GB-2666 | GPU: MSI GTX 1060 6GB GAMING X | SSD: Kingston A400 240GB | HDD: Seagate Barracuda 2TB 7200rpm | PSU: EVGA BT 450W+ Bronze

 

Phone

 

iPhone XS Max 512GB Gold

 

Link to comment
Share on other sites

Link to post
Share on other sites

@warzkaz @TetraSky @Naeaes @DigitalHermit @huilun02 @Section35 @RedSphyxis 

 

Another update, seems like whenever I remove a "person", Chrome restarts and the "Extensions" come back.

 

72d5384b3a2ebbc6f6c28befff67a7ed.png c5b20e0600788a5846d1320acd31f068.png

Main Rig

 

Case: NZXT H440 White | CPU: Intel Core i5-4690K @5.2GHz | CPU Cooler: Corsair H80i Hydro Series | Motherboard: MSI Z97S Krait Edition | RAM: HyperX Fury White & Black Series 16GB (4x4GB) OC to 2133MHz | Graphics Card: Zotac GeForce GTX 980 Ti ArcticStorm | SSD: Intel 730 Series 480GB & Samsung 840 256GB | HDD: Seagate Barracuda 2TB 7200rpm | PSU: EVGA 750W Supernova G2 80+ Gold | Display: BenQ XL2420G & Samsung S20D300 | Headset: Corsair 1500 | Mouse: Logitech G700S | Keyboard: Corsair Vengeance K70 Silver RED LED

 XENON Build:  

 

Intel Xeon E3-1230 V2 @3.3GHz | Intel DZ68BC | Corsair Dominator Platinum 2x4GB 1866MHz | Kingston HyperX 3k 240GB | MSI GeForce GTX 680 | Fractal Design Define R4 Titanium Grey | Seasonic 520W 80+ Platinum Fanless

Office Build:

 

Case: Fractal Focus G White | CPU: i5-8600K | CPU Cooler: Cooler Master Hyper 212 Evo | Motherboard: MSI Z370-A PRO | RAM: Corsair LPX 16GB-2666 | GPU: MSI GTX 1060 6GB GAMING X | SSD: Kingston A400 240GB | HDD: Seagate Barracuda 2TB 7200rpm | PSU: EVGA BT 450W+ Bronze

 

Phone

 

iPhone XS Max 512GB Gold

 

Link to comment
Share on other sites

Link to post
Share on other sites

Link to comment
Share on other sites

Link to post
Share on other sites

Long story short, don't know whenever I sign into my user account and open Chrome. I get redirected to some russian mail site.

No clue on how I got this. Ran MalwareBytes, got rid of the folder in my /Local, resetted browser settings, signed out of Google account, removed all extensions but no luck.

599c892fc9d6e3653999df89dfd7304e.png

Is this only a problem with Chrome? Does IE, Edge, or Firefox (or whatever other browsers you have) behave in this same fashion? If not and the problem is only linked to Chrome try uninstalling Chrome the reinstall making sure that you have cleared out all cache settings so that you have completely clean version of Chrome.

The only thing we have to fear is... Stupidity...

Link to comment
Share on other sites

Link to post
Share on other sites

Is this only a problem with Chrome? Does IE, Edge, or Firefox (or whatever other browsers you have) behave in this same fashion? If not and the problem is only linked to Chrome try uninstalling Chrome the reinstall making sure that you have cleared out all cache settings so that you have completely clean version of Chrome.

For Chrome, IE and Torch. Already tried clean removal.

Main Rig

 

Case: NZXT H440 White | CPU: Intel Core i5-4690K @5.2GHz | CPU Cooler: Corsair H80i Hydro Series | Motherboard: MSI Z97S Krait Edition | RAM: HyperX Fury White & Black Series 16GB (4x4GB) OC to 2133MHz | Graphics Card: Zotac GeForce GTX 980 Ti ArcticStorm | SSD: Intel 730 Series 480GB & Samsung 840 256GB | HDD: Seagate Barracuda 2TB 7200rpm | PSU: EVGA 750W Supernova G2 80+ Gold | Display: BenQ XL2420G & Samsung S20D300 | Headset: Corsair 1500 | Mouse: Logitech G700S | Keyboard: Corsair Vengeance K70 Silver RED LED

 XENON Build:  

 

Intel Xeon E3-1230 V2 @3.3GHz | Intel DZ68BC | Corsair Dominator Platinum 2x4GB 1866MHz | Kingston HyperX 3k 240GB | MSI GeForce GTX 680 | Fractal Design Define R4 Titanium Grey | Seasonic 520W 80+ Platinum Fanless

Office Build:

 

Case: Fractal Focus G White | CPU: i5-8600K | CPU Cooler: Cooler Master Hyper 212 Evo | Motherboard: MSI Z370-A PRO | RAM: Corsair LPX 16GB-2666 | GPU: MSI GTX 1060 6GB GAMING X | SSD: Kingston A400 240GB | HDD: Seagate Barracuda 2TB 7200rpm | PSU: EVGA BT 450W+ Bronze

 

Phone

 

iPhone XS Max 512GB Gold

 

Link to comment
Share on other sites

Link to post
Share on other sites

Try running a free trial of Kaspersky Total or Bitdefender Total. Should detect it

AMD Ryzen 7 3700X | ASUS X570 Crosshair VIII Dark Hero | EVGA GeForce GTX 1080 Ti SC2 HYBRID | 32GB DDR4-3600

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×