Firefox Apple Iphone X Browser Survey Scam - Malware?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by minni, Feb 7, 2019.

  1. minni

    minni Private E-2

    Hi - my main Q is whether the following incident which just happened to me, caused my system to become infected, and if i'm at personal risk as well?

    I was about to check out my last post at another majorgeeks thread, when out of the blue on my FF browser - an Apple Iphone X browser survey popup displayed asking if i'd like to answer Qs on a Firefox opinion survey, whereupon i can get an Apple Iphone X for $1 (please see screenshot at end of this post).
    When i agreed, a timer began timing me, for approx. 10? 15? min. whereupon the $1 offer would expire.

    It's probably a Firefox version of this scam:
    https://www.onlinethreatalerts.com/...iphone-x-visitor-browser-opinion-survey-scam/

    and consisted of a huge URL starting with:
    http://apps4852.not-this-way42.live/?utm_campaign=etc.etc.etc.

    and wound up informing me:
    APPROVED! Thank you for joining sexy dating scene!
    With a button stating: ENTER MEMBERS AREA
    (below that informing me of my "username" & "password" and that if i click the link above, i'll be automatically enrolled in the site below blah blah.


    ------------------

    Believe me, this particular twist never happened to me before. It had appeared like a legitimate Firefox survey, but it was a scam which charged my debit card approx. $39, and involved TWO of my debit cards, one Visa, the other Mastercard (all because i didn't know that CVV meant the security code on rear). So the Visa card's info stated "rejected", and it then asked me to enter an alt. card number. Meanwhile, because i'd entered the 3-digit code of my Visa anyway (after i researched what CVV meant), i needed to rush to block both cards. One or both will need to be disputed by the respective banks. I was unable to reach the Visa-associated bank (to find out if the fraudsters charged that one as well), due to it being after hours. That was very frustrating. The criminal-fraudsters are located in the UK, and now have my name and zip-code.

    Is the latter a personal risk for me, and could they have infected me with malware?

    I do have MSE, but turned off updates for fear that MS would auto-download extraneous stuff i cannot afford to have on my 80gb system. Especially not an auto-download of Win10 in place of Win7-Home!

    Here's a screenshot of the scam-popup-page:

    survey.jpg
     
  2. minni

    minni Private E-2

    P.S. here is the AdwCleaner log file:

    adwcleaner.jpg

    # -------------------------------
    # Malwarebytes AdwCleaner 7.2.7.0
    # -------------------------------
    # Build: 01-30-2019
    # Database: 2019-02-06.2 (Cloud)
    # Support: https://www.malwarebytes.com/support
    #
    # -------------------------------
    # Mode: Scan
    # -------------------------------
    # Start: 02-07-2019
    # Duration: 00:00:24
    # OS: Windows 7 Home Premium
    # Scanned: 31844
    # Detected: 56


    ***** [ Services ] *****

    PUP.Optional.Legacy YahooAUService

    ***** [ Folders ] *****

    PUP.Optional.AdvancedSystemCare C:\ProgramData\IObit\Advanced SystemCare V7
    PUP.Optional.AdvancedSystemCare C:\ProgramData\IObit\Advanced SystemCare V8
    PUP.Optional.AdvancedSystemCare C:\Users\Administrator\AppData\Roaming\IObit\Advanced SystemCare V8
    PUP.Optional.AdvancedSystemCare C:\Users\Administrator\AppData\LocalLow\IObit\Advanced SystemCare
    PUP.Optional.AdvancedSystemCare C:\Users\Administrator\AppData\Roaming\IObit\Advanced SystemCare
    PUP.Optional.Legacy C:\Program Files\Yahoo!\Companion
    PUP.Optional.Legacy C:\Windows\System32\config\systemprofile\AppData\LocalLow\Yahoo!\Companion
    PUP.Optional.Legacy C:\ProgramData\Yahoo! Companion
    PUP.Optional.Legacy C:\Windows\System32\config\systemprofile\AppData\LocalLow\Yahoo! Companion
    PUP.Optional.Legacy C:\Users\Administrator\AppData\LocalLow\AVG SafeGuard toolbar

    ***** [ Files ] *****

    PUP.Optional.Legacy C:\Program Files\Yahoo!\Common\unyt.exe

    ***** [ DLL ] *****

    No malicious DLLs found.

    ***** [ WMI ] *****

    No malicious WMI found.

    ***** [ Shortcuts ] *****

    No malicious shortcuts found.

    ***** [ Tasks ] *****

    No malicious tasks found.

    ***** [ Registry ] *****

    PUP.Optional.AdvancedSystemCare HKLM\Software\IObit\RealTimeProtector
    PUP.Optional.AdvancedSystemCare HKLM\Software\IObit\Advanced SystemCare
    PUP.Optional.AdvancedSystemCare HKLM\Software\IOBIT\ASC
    PUP.Optional.AdvancedSystemCare HKLM\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shellex\ContextMenuHandlers\Advanced SystemCare
    PUP.Optional.AdvancedSystemCare HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\Advanced SystemCare
    PUP.Optional.AdvancedSystemCare HKLM\SOFTWARE\CLASSES\LNKFILE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
    PUP.Optional.AdvancedSystemCare HKLM\SOFTWARE\CLASSES\DRIVE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
    PUP.Optional.AdvancedSystemCare HKLM\SOFTWARE\CLASSES\DIRECTORY\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
    PUP.Optional.Legacy HKU\S-1-5-18\Software\Yahoo\YFriendsBar
    PUP.Optional.Legacy HKU\.DEFAULT\Software\Yahoo\YFriendsBar
    PUP.Optional.Legacy HKU\S-1-5-18\Software\AppDataLow\Software\Yahoo\Companion
    PUP.Optional.Legacy HKU\.DEFAULT\Software\AppDataLow\Software\Yahoo\Companion
    PUP.Optional.Legacy HKU\S-1-5-18\Software\Yahoo\Companion
    PUP.Optional.Legacy HKU\.DEFAULT\Software\Yahoo\Companion
    PUP.Optional.Legacy HKLM\Software\Yahoo\Companion
    PUP.Optional.Legacy HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
    PUP.Optional.Legacy HKLM\SOFTWARE\Classes\AppID\ytbbroker.EXE
    PUP.Optional.Legacy HKLM\SOFTWARE\Classes\AppID\yt.DLL
    PUP.Optional.Legacy HKLM\Software\Classes\CLSID\{9DE77B51-89F6-468E-9402-16050382E950}
    PUP.Optional.Legacy HKLM\Software\Classes\CLSID\{8E74A0AE-F0ED-47ED-A940-A8E99687646B}
    PUP.Optional.Legacy HKLM\Software\Classes\CLSID\{7DB8B625-DBF0-4491-B544-5A06F7B17BB4}
    PUP.Optional.Legacy HKLM\Software\Classes\CLSID\{3C16E079-E4C7-493C-BE9F-E0F2BB0B7430}
    PUP.Optional.Legacy HKLM\Software\Classes\TypeLib\{F6C2BABA-9E4C-425F-9AEC-24AB8F2B640D}
    PUP.Optional.Legacy HKLM\Software\Classes\Interface\{8FD65019-BF09-45DA-AD81-E95AE911F1FD}
    PUP.Optional.Legacy HKLM\Software\Classes\Interface\{7F124846-5453-4BB8-A41D-E11481FFC9DF}
    PUP.Optional.Legacy HKLM\Software\Classes\Interface\{371AD4A5-1520-4AA2-A8A4-F9AD3BAC6957}
    PUP.Optional.Legacy HKLM\Software\Classes\AppID\{7375D127-3955-4654-8E7D-1949A7A9C902}
    PUP.Optional.Legacy HKLM\Software\Classes\Interface\{63B73044-FC1A-4FE1-991B-FDBD4CDAA868}
    PUP.Optional.Legacy HKLM\Software\Classes\Interface\{367BD1CD-74A3-451F-B1A4-6A2DE4129A2D}
    PUP.Optional.Legacy HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
    PUP.Optional.Legacy HKLM\Software\Classes\AppID\{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
    PUP.Optional.Legacy HKLM\Software\Classes\AppID\{1CAE874F-F5C7-4BCC-BA46-9AD26DF35B93}
    PUP.Optional.Legacy HKLM\Software\Classes\CLSID\{31371420-098D-4C0E-A11E-EBEC2305DD01}
    PUP.Optional.Legacy HKLM\Software\Classes\CLSID\{1E57256D-9F39-4267-AB39-D7813D644C5A}
    PUP.Optional.Legacy HKLM\Software\Classes\TypeLib\{61A2027D-B837-4080-A925-6E30E10DEF32}
    PUP.Optional.Legacy HKLM\Software\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
    PUP.Optional.Legacy HKLM\Software\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
    PUP.Optional.Legacy HKLM\Software\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
    PUP.Optional.Legacy HKLM\Software\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
    PUP.Optional.Legacy HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    PUP.Optional.Legacy HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    PUP.Optional.Legacy HKLM\Software\Classes\Sample.YTBPartnerSample
    PUP.Optional.Legacy HKLM\Software\Classes\Sample.BrowserHandler
    PUP.Winlogon.Heuristic HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon|Shell

    ***** [ Chromium (and derivatives) ] *****

    No malicious Chromium entries found.

    ***** [ Chromium URLs ] *****

    No malicious Chromium URLs found.

    ***** [ Firefox (and derivatives) ] *****

    No malicious Firefox entries found.

    ***** [ Firefox URLs ] *****

    No malicious Firefox URLs found.



    ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########
     
    Last edited: Feb 7, 2019
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please follow the Read and Run First instructions and ATTACH the resulting logs to your next reply. And please remember, if it looks too good to be true...it probably is a scam!!
     
  4. minni

    minni Private E-2


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds