Hacked


Judy in Texas

Active member
Member
Local time
3:24 PM
Posts
82
OS
Windows 11
Getting popups that sometimes refer me to Norton or Macafee. Small alarmingly worded box pops up, when I close it I get a page pop up which I can also close. Task Manager reports activity by BRhosthelper and antimalware service executor. I have cleared Firefox cache and shut down and rebooted. Ran scans with Windows Defender and HP Wolf security. It is still there. One of the screens referred to Zeus.2000.

Just 2 days ago I downloaded and ran a Malwarebytes scan (from its own web site) because I thought the computer was running too slow. It found nothing.

What now?

Thank you.
 

My Computers

System One System Two

  • OS
    Windows 11
    Computer type
    Tablet
    Manufacturer/Model
    Microsoft Surface 7
  • Operating System
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Z G9
    CPU
    Intel
    Memory
    32G
    Graphics card(s)
    Nvidia
Reset your browser, it's most likely a browser hijacker pushing what's called scareware (aka fake alerts that can look convincingly like you are infected)
 

My Computer

System One

  • OS
    Linux Mint
    Computer type
    Laptop
    Manufacturer/Model
    System76 Lemur Pro
Had a bit of throuble gettng snipping too to see it, since it is a popup. Sorry my edges are so ragged:
threat.webp
 

My Computers

System One System Two

  • OS
    Windows 11
    Computer type
    Tablet
    Manufacturer/Model
    Microsoft Surface 7
  • Operating System
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Z G9
    CPU
    Intel
    Memory
    32G
    Graphics card(s)
    Nvidia
Yeah those are just fake scareware alerts
 

My Computer

System One

  • OS
    Linux Mint
    Computer type
    Laptop
    Manufacturer/Model
    System76 Lemur Pro
Had a bit of throuble gettng snipping too to see it, since it is a popup. Sorry my edges are so ragged:
You have not been hacked. This is a web pop-up.
Clean up cookies and cache from your browser.
 

My Computers

System One System Two

  • OS
    All Branches but Release
    Computer type
    Laptop
    Manufacturer/Model
    Acer Nitro ANV15-51
    CPU
    AMD Ryzen 7 7735HS 3200-4500 Mhz 8 cores x 2
    Motherboard
    Sportage_RBH
    Memory
    32 GB DDR5
    Graphics Card(s)
    Radeon Graphic / NVIDIA GeForce RTX 4060 8 GB GDDR6
    Sound Card
    AMD/Realtek(R) Audio
    Monitor(s) Displays
    Integrated Monitor (15.3"vis)
    Screen Resolution
    FHD 1920X1080 16:9 144Hz
    Hard Drives
    KINGSTON OM8SEP4512Q-AA 1TB
    Western Digital 256GB
    PSU
    19V DC 6.32 A 120 W
    Cooling
    Dual Fans
    Mouse
    MS Bluetooth
    Internet Speed
    Fiber 1GB Cox -us & 1GB Orange-fr
    Browser
    Edge Canary- Firefox Nightly-Chrome Dev-Chrome Dev
    Antivirus
    Windows Defender
  • Operating System
    Windows 11 Beta
    Computer type
    Laptop
    Manufacturer/Model
    Asus X751BP
    CPU
    AMD A9-9420
    Memory
    8 GB of DDR4
    Graphics card(s)
    AMD Radeon R5
    Screen Resolution
    1600x900
    Hard Drives
    Seagate 1 TB
I downloaded and ran a Malwarebytes scan (from its own web site) because I thought the computer was running too slow. It found nothing.


Try this instead...

 

My Computers

System One System Two

  • OS
    Win 11 Home ♦♦♦26200.8457 ♦♦♦♦♦♦♦25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® [May 2020]
    CPU
    AMD Ryzen 7 3700X
    Motherboard
    Asus Pro WS X570-ACE (BIOS 5302)
    Memory
    G.Skill (F4-3200C14D-16GTZKW)
    Graphics Card(s)
    EVGA RTX 2070 (08G-P4-2171-KR)
    Sound Card
    Realtek ALC1220P / ALC S1220A
    Monitor(s) Displays
    Dell U3011 30"
    Screen Resolution
    2560 x 1600
    Hard Drives
    2x Samsung 860 EVO 500GB,
    WD 4TB Black FZBX - SATA III,
    WD 8TB Black FZBX - SATA III,
    DRW-24B1ST CD/DVD Burner
    PSU
    PC Power & Cooling 750W Quad EPS12V
    Case
    Cooler Master ATCS 840 Tower
    Cooling
    CM Hyper 212 EVO (push/pull)
    Keyboard
    Ducky DK9008 Shine II Blue LED
    Mouse
    Logitech Optical M-100
    Internet Speed
    300/300
    Browser
    Firefox (latest)
    Antivirus
    Bitdefender Total Security
    Other Info
    Speakers: Klipsch Pro Media 2.1
  • Operating System
    Windows XP Pro 32bit w/SP3
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® (not in use)
    CPU
    AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)
    Motherboard
    ASUS M2N32-SLI Deluxe Wireless Edition
    Memory
    TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)
    Graphics card(s)
    EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Sound Card
    Onboard
    Monitor(s) Displays
    ViewSonic G90FB Black 19" Professional (CRT)
    Screen Resolution
    up to 2048 x 1536
    Hard Drives
    WD 36GB 10,000rpm Raptor SATA
    Seagate 80GB 7200rpm SATA
    Lite-On LTR-52246S CD/RW
    Lite-On LH-18A1P CD/DVD Burner
    PSU
    PC Power & Cooling Silencer 750 Quad EPS12V
    Case
    Generic Beige case, 80mm fans
    Cooling
    ZALMAN 9500A 92mm CPU Cooler
    Keyboard
    Logitech Classic Keybooard 200
    Mouse
    Logitech Optical M-BT96a
    Internet Speed
    300/300
    Browser
    Firefox 3.x ??
    Antivirus
    Symantec (Norton)
    Other Info
    Still assembled, still runs. Haven't turned it on for 15 years?
Interesting. It wants to quarantine 4 apps that are installed courtesy of my HP Wolf security.
 

My Computers

System One System Two

  • OS
    Windows 11
    Computer type
    Tablet
    Manufacturer/Model
    Microsoft Surface 7
  • Operating System
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Z G9
    CPU
    Intel
    Memory
    32G
    Graphics card(s)
    Nvidia
I asked it to not do that, but if the ADWcleaner scan doesn't fix the problem, tomorrow I will call HP. I do appreciate the personal service from HP, thanks to buying my workstation at a big discount.
 

My Computers

System One System Two

  • OS
    Windows 11
    Computer type
    Tablet
    Manufacturer/Model
    Microsoft Surface 7
  • Operating System
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Z G9
    CPU
    Intel
    Memory
    32G
    Graphics card(s)
    Nvidia
I've never had an HP computer, so I know diddly about Wolf Security.
 

My Computers

System One System Two

  • OS
    Win 11 Home ♦♦♦26200.8457 ♦♦♦♦♦♦♦25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® [May 2020]
    CPU
    AMD Ryzen 7 3700X
    Motherboard
    Asus Pro WS X570-ACE (BIOS 5302)
    Memory
    G.Skill (F4-3200C14D-16GTZKW)
    Graphics Card(s)
    EVGA RTX 2070 (08G-P4-2171-KR)
    Sound Card
    Realtek ALC1220P / ALC S1220A
    Monitor(s) Displays
    Dell U3011 30"
    Screen Resolution
    2560 x 1600
    Hard Drives
    2x Samsung 860 EVO 500GB,
    WD 4TB Black FZBX - SATA III,
    WD 8TB Black FZBX - SATA III,
    DRW-24B1ST CD/DVD Burner
    PSU
    PC Power & Cooling 750W Quad EPS12V
    Case
    Cooler Master ATCS 840 Tower
    Cooling
    CM Hyper 212 EVO (push/pull)
    Keyboard
    Ducky DK9008 Shine II Blue LED
    Mouse
    Logitech Optical M-100
    Internet Speed
    300/300
    Browser
    Firefox (latest)
    Antivirus
    Bitdefender Total Security
    Other Info
    Speakers: Klipsch Pro Media 2.1
  • Operating System
    Windows XP Pro 32bit w/SP3
    Computer type
    PC/Desktop
    Manufacturer/Model
    Built by Ghot® (not in use)
    CPU
    AMD Athlon 64 X2 5000+ (OC'd @ 3.2Ghz)
    Motherboard
    ASUS M2N32-SLI Deluxe Wireless Edition
    Memory
    TWIN2X2048-6400C4DHX (2 x 1GB, DDR2 800)
    Graphics card(s)
    EVGA 256-P2-N758-TR GeForce 8600GT SSC
    Sound Card
    Onboard
    Monitor(s) Displays
    ViewSonic G90FB Black 19" Professional (CRT)
    Screen Resolution
    up to 2048 x 1536
    Hard Drives
    WD 36GB 10,000rpm Raptor SATA
    Seagate 80GB 7200rpm SATA
    Lite-On LTR-52246S CD/RW
    Lite-On LH-18A1P CD/DVD Burner
    PSU
    PC Power & Cooling Silencer 750 Quad EPS12V
    Case
    Generic Beige case, 80mm fans
    Cooling
    ZALMAN 9500A 92mm CPU Cooler
    Keyboard
    Logitech Classic Keybooard 200
    Mouse
    Logitech Optical M-BT96a
    Internet Speed
    300/300
    Browser
    Firefox 3.x ??
    Antivirus
    Symantec (Norton)
    Other Info
    Still assembled, still runs. Haven't turned it on for 15 years?
Check to see if there is a browser extension that is causing it. Disable them one by one to check.
 
Last edited:

My Computers

System One System Two

  • OS
    Windows 11 Pro x64
    Computer type
    PC/Desktop
    Manufacturer/Model
    📷🔈🎧 🪛 DIY Photoshop/Audio/Game/tinker
    CPU
    i9 14900K P/E 5.8/4.5 GHz, cache 5.0 GHz
    Motherboard
    Asus ROG Maximus Z790 Dark Hero
    Memory
    🐏 96GB (2x48) G.skill Ripjaws 6800 MT/s
    Graphics Card(s)
    Asus ROG Strix 4070 Ti OC
    Sound Card
    🔊Bowers & Wilkins 606 S3 speakers; Audiolabs 7000a integrated amp; RSL 10S Mk2 sub; Creative Pebble Pro Minimilist
    Monitor(s) Displays
    🖥️🖥️ Eizo CG2730 ColorEdge, ViewSonic VP2768
    Screen Resolution
    🖥️🖥️ 2560 x 1440p x 2
    Hard Drives
    💾 WDC SN850X 4TB nvme, SN850 1TB nvme, SK-Hynix 2 TB P41 nvme,. Sabrent USB-C DS-SC5B 5-bay docking station: 6TB WDC Black, 6TB Ironwolf Pro; 2x 2TB WDC Black HDD
    PSU
    ⚡️ 850W Seasonic Vertex PX-850 ATX 3.0/PCI-E 5.0
    Case
    Fractal Design North XL Mesh, Black Walnut
    Cooling
    ❄️ EK Nucleus black 360 AIO w/Phanteks T30-120 fans, 2 Noctua NF-A14 Chromax case fan, 1 T30-120 fan cooling memory
    Keyboard
    ⌨️ Keychron Q3 Max TKL with custom GMK Redsuns Red Samuri keycaps, TX Stabs
    Mouse
    🖱️ Logitech G305 wireless gaming
    Internet Speed
    ⬇️ 500 Mb/s ⬆️ 12 Mb/s
    Browser
    🔥🦊 Firefox
    Antivirus
    🦺 Defender, Macrium Reflect X 🏆
    Other Info
    Phangkey Amaterasu V2 Desk Mat
  • Computer type
    Laptop
    Manufacturer/Model
    💻 Apple 13" Macbook Pro 2020 (m1)
    CPU
    Apple M1
    Screen Resolution
    2560x1600
    Browser
    Firefox
@Judy in Texas
Let AdwCleaner quarantine the "fake malware" pop-ups. What does it want to quarantine from HP?
 

My Computers

System One System Two

  • OS
    Windows 11 Home 25H2 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Pavilion TP01-2xxx
    CPU
    AMD Ryzen 3 5300G
    Memory
    8gb
    Graphics Card(s)
    Radeon Graphics 4.00GHZ
    Monitor(s) Displays
    ViewSonic
    Keyboard
    HP
    Mouse
    wireless Microsoft
    Browser
    FireFox
    Antivirus
    Avira
  • Operating System
    Updated Windows 10 to 11 25H2 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP
    CPU
    Intel Core i3 8100 @3.60 GHz
    Motherboard
    HP 8653 (U3E1)
    Memory
    8.GB
    Graphics card(s)
    Intel UHD 360 (HP)
    Sound Card
    Realtek High Def
    Monitor(s) Displays
    ViewSonic
    Other Info
    #3 System: HP laptop Windows 25H2 11Pro 26200.7840
ADW messsage.webp
 

My Computers

System One System Two

  • OS
    Windows 11
    Computer type
    Tablet
    Manufacturer/Model
    Microsoft Surface 7
  • Operating System
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Z G9
    CPU
    Intel
    Memory
    32G
    Graphics card(s)
    Nvidia
Jacee, this computer is an HP workstation and has had HP Wolf Security since I bought it.
 

My Computers

System One System Two

  • OS
    Windows 11
    Computer type
    Tablet
    Manufacturer/Model
    Microsoft Surface 7
  • Operating System
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Z G9
    CPU
    Intel
    Memory
    32G
    Graphics card(s)
    Nvidia
HP support to the rescue! To eliminate this popup, look at the ragged image of the scare message in one of my earlier posts. Note the three dots at the right end of a line in the middle. Click it. This opens a menu of three choices. The middle one is "quit sending me messages." Click it. Done.

Jacee, Ryan at HP told me that ADW cleaner will recommend quarantining anything it doesn't recognize.

Thank you to all of you, and I hope my experience and its resolution helps others.

Will close this thread. Probably should have called it "Persistently popuped," but at the time I didn't know that's what it was.
 

My Computers

System One System Two

  • OS
    Windows 11
    Computer type
    Tablet
    Manufacturer/Model
    Microsoft Surface 7
  • Operating System
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Z G9
    CPU
    Intel
    Memory
    32G
    Graphics card(s)
    Nvidia
@Judy in Texas
If you want to keep all the HP software that came bundled with your computer, just cancel the quarantine for them. I have to do the same thing.
 

My Computers

System One System Two

  • OS
    Windows 11 Home 25H2 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Pavilion TP01-2xxx
    CPU
    AMD Ryzen 3 5300G
    Memory
    8gb
    Graphics Card(s)
    Radeon Graphics 4.00GHZ
    Monitor(s) Displays
    ViewSonic
    Keyboard
    HP
    Mouse
    wireless Microsoft
    Browser
    FireFox
    Antivirus
    Avira
  • Operating System
    Updated Windows 10 to 11 25H2 26200.8524
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP
    CPU
    Intel Core i3 8100 @3.60 GHz
    Motherboard
    HP 8653 (U3E1)
    Memory
    8.GB
    Graphics card(s)
    Intel UHD 360 (HP)
    Sound Card
    Realtek High Def
    Monitor(s) Displays
    ViewSonic
    Other Info
    #3 System: HP laptop Windows 25H2 11Pro 26200.7840
I'll just post the same post I always make about these.............
That is the reason it is called scareware, it does literally nothing, but it scares people into doing something bad and stupid!
Exactly we see so many posts from the windows notification center coming from browsers, the computer is almost never infected, its always just needs to be turned off in the notification center which is so easy to do. Despite what the notification looks like, it will always have the application name as seen here. Notice the "via microsoft edge." Click the three dots next to the x and turn them off. If you want notifications from your browser, go the web browsers settings and remove any websites you do not recognize listed there.

1771420401239.webp

Anytime you see something similar to the first posts image, it is almost always browser notifications. These are not actual infections, but scareware. This is why scans never reveal anything, same as adwcleaner.

Malwarebytes has a good write up here:


Always easy to solve.

Turn off notifications from within your browser and windows itself.


You can turn off the notifications for just edge, chrome, whatever browser you use.

As well as within chrome and edge:

Chrome:


Edge:




 

My Computers

System One System Two

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom Built
    CPU
    Ryzen 7 5700 X3D
    Motherboard
    MSI MPG B550 GAMING PLUS
    Memory
    64 GB DDR4 3600mhz Gskill Ripjaws V
    Graphics Card(s)
    RTX 4070 Super , 12GB VRAM Asus EVO Overclock
    Monitor(s) Displays
    Gigabyte M27Q (rev. 2.0) 2560 x 1440 @ 170hz HDR
    Hard Drives
    2TB Samsung nvme ssd
    4TB Western Digital nvme ssd
    PSU
    CORSAIR RMx SHIFT Series™ RM750x 80 PLUS Gold Fully Modular ATX Power Supply
    Case
    CORSAIR 3500X ARGB Mid-Tower ATX PC Case – Black
    Cooling
    ID-COOLING FROSTFLOW X 240 CPU Water Cooler
    Keyboard
    Logitech G213
    Mouse
    Logitech G203
    Internet Speed
    1.2gbps Fiber 😎
  • Operating System
    Chrome OS
    Computer type
    Laptop
    Manufacturer/Model
    HP Chromebook
    CPU
    Intel Pentium Quad Core
    Memory
    4GB LPDDR4
    Monitor(s) Displays
    14 Inch HD SVA anti glare micro edge display
    Hard Drives
    64 GB emmc
HP support to the rescue! To eliminate this popup, look at the ragged image of the scare message in one of my earlier posts. Note the three dots at the right end of a line in the middle. Click it. This ...

This ... initiates action that is unknown to you.
I'm astounded that HP support told you to do that.

You might have given these scammers access to your computer as well as your shoe size & your online banking passwords.
Your computer was probably not infected before. It might well be infected now.


Denis
 

My Computer

System One

  • OS
    Windows 11 Home x64 Version 25H2 Build 26200.8037
This ... initiates action that is unknown to you.
I'm astounded that HP support told you to do that.

You might have given these scammers access to your computer as well as your shoe size & your online banking passwords.
Your computer was probably not infected before. It might well be infected now.


Denis

Depends... If she called any number from that notification, then yes.

If she called her own old HP support number that she's been using for years, then probably no.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 25H2 build: (26200.7623)
    Computer type
    Laptop
    Manufacturer/Model
    Microsoft Surface Pro
    Memory
    32GB
  • Operating System
    Microsoft 25H2 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Dell Pro 14 - PC14250
    CPU
    Intel Core Ultra 7
    Memory
    64GB
    Graphics card(s)
    Intel Integrated Graphics
    Hard Drives
    Micron 1TB SSD
Depends... If she called any number from that notification, then yes.

If she called her own old HP support number that she's been using for years, then probably no.
I would never expect any tech sp to tell somebody to interact with a scammer's onscreen dialog.
The common advice has always been not to do so.
How To Remove "WARNING! Virus Detected" Pop-up Scam - Malwarebytes
How to stop and remove a fake virus alert on your device -Norton
How to Identify and Stop Fake Virus Warnings - Avast
How to Spot a Fake Virus Warning and Avoid It - AVG

fake malware warnings 1.webp

fake malware warnings 2.webp

fake malware warnings 3.webp

fake malware warnings 4.webp


All the best,
Denis
 
Last edited:

My Computer

System One

  • OS
    Windows 11 Home x64 Version 25H2 Build 26200.8037
Back
Top Bottom