At the beginning of the month I updated MBAM and a trial of the premium edition. During that time with the premium edition the realtime protection blocked a few things whilst I was using Chrome. I didn’t think anything of it at the time, because I noticed the word ‘bywinners’ in the domain name and assumed it had something to do with the online betting websites I sometimes play on. Anyway, since the premium trial has ended I have since noticed on a couple of occasions tabs pop up in Chrome that I didn’t click on. The first couple of times this occured I simply dismissed it as me having accidently clicked on an online ad, but today I came upon a Chrome tab with the domain ‘hXXp://babittedwinner.men’ with a Microsoft-style tab icon and a recorded voice telling me I had won an Iphone (or other such thing). Obviously, I was rather taken aback and suspicious. I’ve ran MBAM, Avast and SuperAntiSpyware over the past few weeks and they’ve picked up no malware threats. Which is why I’m seeking your guidance. Please help!
Please find attached an MBAM reports, FRST logs, and also copies of the MBAM premium edition realtime logs from when they blocked these websites. I’ve included them below. For some reason MBAM at the time picked up multiple events in the same day (and time!) and I’ve included each one, hence there seems to be duplicates of the same event. Only thing I noticed is that the domain on each day seems to change to something else!
Should be noted, I also use Firefox, and I seem to have had no issues with that.
Looking at the Wireless IP config section of the fixlog, it mentions neither the local area network or the wireless network could be fixed as they were disconnected. I did switch off my internet when the scan was on (since FRST closed my web browsers whilst it was running the fix I saw no point in leaving it on). Did I mess up there? Should I have left my internet connected?
I have used a couple of USB sticks in the past week. Could I have passed malware onto those?
My system seems to be running as normal, but these extra Chrome tabs only popped up every couple of days, so I guess I would have to keep things running for a week before I was confident nothing more is amiss, so I’ll wait 7 days before reporting back.
Where is a good place to d/l CryptoPrevent, and are there any specific settings that I need to apply to it, or it just a case of hitting the default settings/protection button once I’ve started it up?
Where is a good place to d/l CryptoPrevent, and are there any specific settings that I need to apply to it, or it just a case of hitting the default settings/protection button once I've started it up?
What about CryptoPrevent website / userguide / FAQ ?
I’m unsure what the CryptoPrevent website proper is, that’s why I asked. And I asked if any extra settings need be applied because I didn’t want to go in blind and mess things up further.
I d/l CryptoPrevent from foolishit, I assume this was the correct place to d/l it (I prefer to ask incase it was fake). On startup, it seemed to run a scan without asking and reset my computer on completion. I assume this is normal? On resumption, I started up CryptoPrevent again and pressed the ‘Applied Protection Plan’ button using the default setting.
We just need you monitor your system and tell us if you still get the redirects / ads from the winners.men websites.
As to CryptoPrevent, the logs showed you had this installed on your system already. I just wanted you to refresh the protection it offered as the Fixlist script you ran removed all the settings CryptoPrevent had set previously.
Hi, just got another tab appear in Chrome for a bmwork or something like that. Again, the tab had a Microsoft style icon and again a voice congratulated my for winning something. :-\
I took your advice, d/l Poper Blocker for Chrome, but within hours I got the same tab problem come up again. So remembering that I used Adwcleaner many, many years ago for a previous problem I d/l that and ran a scan. It seemed to pick up something odd (I included the log below) and I deleted it.
I scanned with Adwcleaner a further couple of times over last week and was told my system was clean. I’ve had no more tabs with those “congratulations you’ve won xxx” come up, so I don’t know if that has fixed the problem.
… but …
A couple of days ago, whilst I was about to make a last minute bid on Ebay my Ebay page was redirected! I think Avast stopped anything from happening, but checking Chrome’s history, it seems I was diverted to:
Yesterday I ran an Avast and Mbam scan, they picked up nothing. So also tried Chrome Cleanup Tool and Hitman Pro (which didn’t pick up anything but some cookies, which I promptly deleted). Last night I was on Ebay again, and my page was diverted to this:
Again, Avast blocked it. I’ve taken a screen grab of how it looked on my desktop. Any suggestions? And is it related to the previous problem you’ve been helping me with?
I included MBAM and FRST scans of my computer as of today.
It just seems to happen with Chrome only. I use Firefox with extensions like Adblock Plus and NoScript for general browsing and it runs just fine. Chrome I tend to use only for online shopping and social media. If this keeps happening with Chrome I might get rid of it and use another browser altogether.
I’ll try your recommendation over the weekend though, thanks!