Jump to content

Annoying browser hijack.

Today I've been getting hammered by some adware or browser hijack. What happens is that at random times when I want to open a new tab, the tab I was on previously will redirect to some stupid gambling website, a sweepstakes website, or to a page advertising some junk Chrome extension. Today is the first time this has happened, and I haven't installed anything over the last several weeks. I did visit a website (extremetech.com) that hit me hard with ads, even though I have Adblock Plus with only a select few websites whitelisted.

 

To address this I've deleted my Chrome user data from the past week, and I've run Malwarebytes 4 times along with Ad-aware, Junkware Removal tool, RKill, and Hitman Pro. Hijackthis revealed nothing out of the ordinary.

 

Malwarebytes is the only program so far that has actually found anything. On the first scan it found 4 PUPs for some crap called NewTabTV. Rebooted after first scan. Second and third scans found nothing. Rebooted again. Fourth scan found 4 more PUPs for Mindspark. Rebooted for a third time. 

 

So far nothing, but I won't be surprised if this continues.

 

 

New Build (The Compromise): CPU - i7 9700K @ 5.1Ghz Mobo - ASRock Z390 Taichi | RAM - 16GB G.SKILL TridentZ RGB 3200CL14 @ 3466 14-14-14-30 1T | GPU - ASUS Strix GTX 1080 TI | Cooler - Corsair h100i Pro | SSDs - 500 GB 960 EVO + 500 GB 850 EVO + 1TB MX300 | Case - Coolermaster H500 | PSUEVGA 850 P2 | Monitor - LG 32GK850G-B 144hz 1440p | OSWindows 10 Pro. 

Peripherals - Corsair K70 Lux RGB | Corsair Scimitar RGB | Audio-technica ATH M50X + Antlion Modmic 5 |

CPU/GPU history: Athlon 6000+/HD4850 > i7 2600k/GTX 580, R9 390, R9 Fury > i7 7700K/R9 Fury, 1080TI > Ryzen 1700/1080TI > i7 9700K/1080TI.

Other tech: Surface Pro 4 (i5/128GB), Lenovo Ideapad Y510P w/ Kali, OnePlus 6T (8G/128G), PS4 Slim.

Link to comment
Share on other sites

Link to post
Share on other sites

What did you d/l or install?

 

Look at your programs running and delete. RIght click bottom bar, Start Task Manager.

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, yathis said:

What did you d/l or install?

 

Look at your programs running and delete. RIght click bottom bar, Start Task Manager.

I've already been over that. First thing I thought of.

 

I haven't installed anything in over a week.

New Build (The Compromise): CPU - i7 9700K @ 5.1Ghz Mobo - ASRock Z390 Taichi | RAM - 16GB G.SKILL TridentZ RGB 3200CL14 @ 3466 14-14-14-30 1T | GPU - ASUS Strix GTX 1080 TI | Cooler - Corsair h100i Pro | SSDs - 500 GB 960 EVO + 500 GB 850 EVO + 1TB MX300 | Case - Coolermaster H500 | PSUEVGA 850 P2 | Monitor - LG 32GK850G-B 144hz 1440p | OSWindows 10 Pro. 

Peripherals - Corsair K70 Lux RGB | Corsair Scimitar RGB | Audio-technica ATH M50X + Antlion Modmic 5 |

CPU/GPU history: Athlon 6000+/HD4850 > i7 2600k/GTX 580, R9 390, R9 Fury > i7 7700K/R9 Fury, 1080TI > Ryzen 1700/1080TI > i7 9700K/1080TI.

Other tech: Surface Pro 4 (i5/128GB), Lenovo Ideapad Y510P w/ Kali, OnePlus 6T (8G/128G), PS4 Slim.

Link to comment
Share on other sites

Link to post
Share on other sites

This is for a Windows PC correct?

 

Have you deleted Chrome? Does this occur in other browsers?

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

check the properties of your browser. could have some weird extension added to it. and you definitely have something still installed. check your startup services, your startup list in task manager, your hidden folder's under %appdata%, delete any folder that looks malware-ish. might have to go into safemode to do it.

Link to comment
Share on other sites

Link to post
Share on other sites

14 minutes ago, DrMacintosh said:

This is for a Windows PC correct?

 

Have you deleted Chrome? Does this occur in other browsers?

Yes, Windows 10. 

 

Yes I reinstalled Chrome. The problem does not occur on other browsers, mostly because I never use them. I only used Edge to download Chrome.

5 minutes ago, vaiwalker said:

check the properties of your browser. could have some weird extension added to it. and you definitely have something still installed. check your startup services, your startup list in task manager, your hidden folder's under %appdata%, delete any folder that looks malware-ish. might have to go into safemode to do it.

I already checked for any strange extensions for my browser, I've run the Chrome cleanup tool, and I've looked through my startup programs. I have a very clean startup list, with only the bare essentials needed (plus CUE for my Corsair peripherals).

New Build (The Compromise): CPU - i7 9700K @ 5.1Ghz Mobo - ASRock Z390 Taichi | RAM - 16GB G.SKILL TridentZ RGB 3200CL14 @ 3466 14-14-14-30 1T | GPU - ASUS Strix GTX 1080 TI | Cooler - Corsair h100i Pro | SSDs - 500 GB 960 EVO + 500 GB 850 EVO + 1TB MX300 | Case - Coolermaster H500 | PSUEVGA 850 P2 | Monitor - LG 32GK850G-B 144hz 1440p | OSWindows 10 Pro. 

Peripherals - Corsair K70 Lux RGB | Corsair Scimitar RGB | Audio-technica ATH M50X + Antlion Modmic 5 |

CPU/GPU history: Athlon 6000+/HD4850 > i7 2600k/GTX 580, R9 390, R9 Fury > i7 7700K/R9 Fury, 1080TI > Ryzen 1700/1080TI > i7 9700K/1080TI.

Other tech: Surface Pro 4 (i5/128GB), Lenovo Ideapad Y510P w/ Kali, OnePlus 6T (8G/128G), PS4 Slim.

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, Phentos said:

mostly because I never use them.

well use Edge for a while and see what happens. 

 

Otherwise if its just a Chrome thing then I think you are SOL. 

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

Does Adwcleaner reveal anything?

| Intel i7-3770@4.2Ghz | Asus Z77-V | Zotac 980 Ti Amp! Omega | DDR3 1800mhz 4GB x4 | 300GB Intel DC S3500 SSD | 512GB Plextor M5 Pro | 2x 1TB WD Blue HDD |
 | Enermax NAXN82+ 650W 80Plus Bronze | Fiio E07K | Grado SR80i | Cooler Master XB HAF EVO | Logitech G27 | Logitech G600 | CM Storm Quickfire TK | DualShock 4 |

Link to comment
Share on other sites

Link to post
Share on other sites

37 minutes ago, xAcid9 said:

Does Adwcleaner reveal anything?

No.

 

Popped up a window just now telling me there's a date nearby for me. How wonderful.

39 minutes ago, DrMacintosh said:

well use Edge for a while and see what happens. 

 

Otherwise if its just a Chrome thing then I think you are SOL. 

I'd rather live with this issue than go back to using a Microsoft browser. 

New Build (The Compromise): CPU - i7 9700K @ 5.1Ghz Mobo - ASRock Z390 Taichi | RAM - 16GB G.SKILL TridentZ RGB 3200CL14 @ 3466 14-14-14-30 1T | GPU - ASUS Strix GTX 1080 TI | Cooler - Corsair h100i Pro | SSDs - 500 GB 960 EVO + 500 GB 850 EVO + 1TB MX300 | Case - Coolermaster H500 | PSUEVGA 850 P2 | Monitor - LG 32GK850G-B 144hz 1440p | OSWindows 10 Pro. 

Peripherals - Corsair K70 Lux RGB | Corsair Scimitar RGB | Audio-technica ATH M50X + Antlion Modmic 5 |

CPU/GPU history: Athlon 6000+/HD4850 > i7 2600k/GTX 580, R9 390, R9 Fury > i7 7700K/R9 Fury, 1080TI > Ryzen 1700/1080TI > i7 9700K/1080TI.

Other tech: Surface Pro 4 (i5/128GB), Lenovo Ideapad Y510P w/ Kali, OnePlus 6T (8G/128G), PS4 Slim.

Link to comment
Share on other sites

Link to post
Share on other sites

 

1 hour ago, Phentos said:

No.

 

Popped up a window just now telling me there's a date nearby for me. How wonderful.

I'd rather live with this issue than go back to using a Microsoft browser. 

check your programs list in control panel and sort it by date and see what's the last thing that was installed. it might not have been installed by you, probably some other program that a PUP.

Link to comment
Share on other sites

Link to post
Share on other sites

opn elevated cmd prompt

run 

netstat -n -b -t 3

keep this window open and when redirected see ip appear ....

add firewall rule for inbound from and to that ip

Link to comment
Share on other sites

Link to post
Share on other sites

14 hours ago, Phentos said:

I'd rather live with this issue than go back to using a Microsoft browser.

That is some irrational thinking here. 

 

You could use any other browser, it was just a suggestion that you use Edge since its built in and is 1st party. 

Laptop: 2019 16" MacBook Pro i7, 512GB, 5300M 4GB, 16GB DDR4 | Phone: iPhone 13 Pro Max 128GB | Wearables: Apple Watch SE | Car: 2007 Ford Taurus SE | CPU: R7 5700X | Mobo: ASRock B450M Pro4 | RAM: 32GB 3200 | GPU: ASRock RX 5700 8GB | Case: Apple PowerMac G5 | OS: Win 11 | Storage: 1TB Crucial P3 NVME SSD, 1TB PNY CS900, & 4TB WD Blue HDD | PSU: Be Quiet! Pure Power 11 600W | Display: LG 27GL83A-B 1440p @ 144Hz, Dell S2719DGF 1440p @144Hz | Cooling: Wraith Prism | Keyboard: G610 Orion Cherry MX Brown | Mouse: G305 | Audio: Audio Technica ATH-M50X & Blue Snowball | Server: 2018 Core i3 Mac mini, 128GB SSD, Intel UHD 630, 16GB DDR4 | Storage: OWC Mercury Elite Pro Quad (6TB WD Blue HDD, 12TB Seagate Barracuda, 1TB Crucial SSD, 2TB Seagate Barracuda HDD)
Link to comment
Share on other sites

Link to post
Share on other sites

maybe the malware changed your proxy settings so you should check that

Link to comment
Share on other sites

Link to post
Share on other sites

Fixed the issue by reinstalling Chrome and deleting all of my user data. Sucks, but oh well.

 

Thanks for the suggestions everyone.

New Build (The Compromise): CPU - i7 9700K @ 5.1Ghz Mobo - ASRock Z390 Taichi | RAM - 16GB G.SKILL TridentZ RGB 3200CL14 @ 3466 14-14-14-30 1T | GPU - ASUS Strix GTX 1080 TI | Cooler - Corsair h100i Pro | SSDs - 500 GB 960 EVO + 500 GB 850 EVO + 1TB MX300 | Case - Coolermaster H500 | PSUEVGA 850 P2 | Monitor - LG 32GK850G-B 144hz 1440p | OSWindows 10 Pro. 

Peripherals - Corsair K70 Lux RGB | Corsair Scimitar RGB | Audio-technica ATH M50X + Antlion Modmic 5 |

CPU/GPU history: Athlon 6000+/HD4850 > i7 2600k/GTX 580, R9 390, R9 Fury > i7 7700K/R9 Fury, 1080TI > Ryzen 1700/1080TI > i7 9700K/1080TI.

Other tech: Surface Pro 4 (i5/128GB), Lenovo Ideapad Y510P w/ Kali, OnePlus 6T (8G/128G), PS4 Slim.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×