VirtualNomad.ga Browser Hijack Vexing Me - No Malware Detected or Other Reports

DefRef

Diamond Member
Nov 9, 2000
4,041
1
81
The other day I launched Chrome and the all my previous tabs were gone, replaced with a www dot virtualnomad dot ga (Gabon) page that makes Chrome as if I want to translate it. It also popped an error that Chrome hadn't shut down properly and would I like to reopen it? Doing so makes Chrome crash and reopen to either a blank start page or this VirtualNomad page.

Launch Firefox and the metric shitton of saved tabs there are annihilated, replaced by this same interloper. Huh? Run a Malwarebytes scan which comes up with a few unrelated PUPs. Check about:config and find the start page has been changed. Blank that out and restored an old sessionstore file to get most of my tabs back.

I can't find a single reference to this thing anywhere with Google. Trying to find a source, the only software I'd updated concurrent with this starting last Saturday (it's Thursday now; first work trying to fix was Tuesday and Wednesday nights) was my Gigabyte App Center updated. Had a corrupted update slipped through? Am I the only one using this junk? On a hunch, I uninstalled all the utilities and initially it appeared to fix things; I thought I'd licked it.

Nope! Last night and into tonight, it's back again, crashing Chrome and eating Firefox. Searched the URL in Registry and found IE's home page had been changed. (Never use IE; Edge seems unaffected.) Other than those two hits, nada. Updated MWB and rescanned in hopes a later def file would spot it and nothing.

Right now, Chrome seems clear, but it seemed that way before. I'm posting from Firefox, so can't retest it. Anyone have any suggestions for sorting this out and swatting this malware?

Rig in sig. TIA!
 

Ketchup

Elite Member
Sep 1, 2002
14,546
238
106
Malwarebytes is good, but isn't the only software for this type of thing. Superantispyware is another good one.
I don't like to run it all the time personally, but the free version of AVG is also good at ridding this sort of thing.

Lastly, ones like these usually hide in your user temp folder. So if you clean out the folder, and it gets stuck on a suspicious exe, check and see if you can end it from task manager, as that might be the rascal you are looking for.
Bear in mind my tips are in no particular order. Nowadays I like to see if I can rid this stuff manually before waiting on scans to complete.
 
Last edited:

DefRef

Diamond Member
Nov 9, 2000
4,041
1
81
Thank you for your reply.

I was going to try SuperAntiSpyware, but in the past I've been annoyed at how it stays resident and whines that you buy it. Getting home tonight, I had the bright idea to roll back to an earlier System Restore point from a week ago, before the weirdness started and so far, so good. Chrome and Firefox both launched without issue. Fingers crossed.
 

deustroop

Golden Member
Dec 12, 2010
1,916
354
136
My experience suggests that the few times this system fell victim was from web pages or content therefrom and not by way of infected applications from known publishers. A removal tool I have used with success is Hijackthis
https://sourceforge.net/projects/hjt/
 

VirtualLarry

No Lifer
Aug 25, 2001
56,453
10,120
126
Some malware, actually re-writes the shortcuts to the browsers, and adds a parameter to open those web pages upon launch. That can be annoying to get rid of, since Malwarebytes generally won't report malware, because there's no EXE or registry entries for any sort of malware.
 

DefRef

Diamond Member
Nov 9, 2000
4,041
1
81
Some malware, actually re-writes the shortcuts to the browsers, and adds a parameter to open those web pages upon launch. That can be annoying to get rid of, since Malwarebytes generally won't report malware, because there's no EXE or registry entries for any sort of malware.
My experience suggests that the few times this system fell victim was from web pages or content therefrom and not by way of infected applications from known publishers. A removal tool I have used with success is Hijackthis
https://sourceforge.net/projects/hjt/
I tried Hijackthis and didn't see anything amiss in its scan, but then thanks to MWB's forcing a trial of their Premium package on me, I discovered a clue which appears to have led me to some discoveries.

I noticed it was popping up a notice that it was blocking an outbound connection to a site called coinuri[dot]com:50928. Try to enter that and it got blocked. Digging into the reports found something called C:\ProgramData\mvfm\mvfm.exe was making the call. Looking at that, it showed no ID info and nothing on Google to legitimize it, so I renamed it .exe-BAD and the block alerts ceased immediately.

Searching the Registry for that file turned up four hits:

Computer\HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store
Computer\HKEY_USERS\S-1-....\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store

C:\ProgramData\mvfm\mvfm.exe
--------------
Computer\HKEY_CURRENT_USER\Software\mvfm.exe
Computer\HKEY_USERS\S-1-....\Software\mvfm.exe

NAME DATA
03L4FtDy724Kj5X || HYFraC-YNeb-{Ha(jLiI-:EZw|6=8?o+c>9{&r<I6)*1
cgy9alI8x4ZfrrLkk3ZdJ9K0Sv3 || 1AXFvaI(k'f8o_r8jFZLM{!dH]S!%;#?|Dm>3~[\e+:YzlBWQb\aB|'}}8)F+r`H6sGfT2FvI)`fyh=%7$-16.&*
NqIIp || I&TN"4X\z['PD@#MygcE`$Q *O&W'jd'mb?c:mf*Inih?)?I8`Mm#c;Fe;**g"bTPQ:ZZ<W)h:],&EvQ:;%G
oyJMgE9p2a4xytQaJhIhkGXeI0t1n || B@35\^0e#x0'rn8fS{EKCGh@2ZwY1xCi#8^gU(@W<q)ftONQ'JC#n+pzcb!cFP^#4T5%hctxYs`&;R4KsSBGH{eN


(sorry about the wrapping; there are four keys - the || separate name from data)

Judging from the gibberish and context, I'm guessing something non-English in nature. Going to that folder and even directly scanning that exe with Windows Defender, Malwarebytes and SuperAntiSpyware ALL report it as benign. (Whut?)

Re-running HijackThis and looking for the critter found this entry: O4 - Startup: Dirk.lnk = C:\ProgramData\mvfm\mvfm.exe

HJT info on the item screams exactly what has been happening: It can load a Registry script, change IE start pages, etc. Used HJT to remove that item and repair the IE start-page.

Hard-deleted the mvfm.exe file (which was 204MB!) and Windows said it was a system file. Yeah, right.

Deleted the four keys from Registry, getting an error about not being able to open one of them. Did second sweep and found no entries.

Reset home page in Firefox back to what I wanted.

Rebooting....

After reboot, no mvfm folder or exe. Registry show neither that nor the hijacked URL. Chrome launched OK, but Firefox came up with just the pinned tabs and the correct homepage. IE launches to MSN page.

/fingers crossed
 
Last edited:

mikeymikec

Lifer
May 19, 2011
18,060
10,241
136
Run some more scans now that you think you've found the culprit because other stuff may be detected now (though it would be likely to be part of the original malware package).

Running a scan in safe mode might not be a bad idea either.
 

RYJCO

Junior Member
Jun 10, 2020
1
0
6
Hi,
I actually have this issue now but the steps you took to remove it have not worked for me.

If anyone has any suggestions for removing this virtualnomad.ga tab that always opens when I start chrome please let me know

Nothing I have tried has removed it I've scanned and scanned countless things to try and get rid of this headache tab
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |