Author Topic: Office 360 Subscription Renewal Opens Additional Link to www.77b.com  (Read 2382 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Hello all,

Recently, my Office 360 subscription was up for renewal. When I click the link from any Office application to renew the subscription, a microsoft URL is called in my default browser and an additional one in a separate tab is also. The latter is flagged by Avast as malicious.

I've attached one of the ways to cause this to happen and the result I get.

Please help me track down the problem.

Thanks,
_t

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Office 360 Subscription Renewal Opens Additional Link to www.77b.com
« Reply #1 on: February 13, 2016, 11:37:46 PM »
https://forum.avast.com/index.php?topic=53253.0

As alternative for MS-Office I recommend Libre Office.
It is free and has a lot more things than MS-Office.

REDACTED

  • Guest
Re: Office 360 Subscription Renewal Opens Additional Link to www.77b.com
« Reply #2 on: February 14, 2016, 02:03:03 AM »
Thanks Eddy. I produced the files required. I am in the process of sanitizing them and I will upload them when I'm done.

REDACTED

  • Guest
Re: Office 360 Subscription Renewal Opens Additional Link to www.77b.com
« Reply #3 on: February 14, 2016, 03:29:37 AM »
All files attached as per sticky post.

mbam_scan-log01 is the first scan with MBAM.
mbam_scan-log02 is a custom scan I conducted by additionally including rootkit scanning and all drives.

Reached attachment limit, will post aswMBR log in next message.

REDACTED

  • Guest
Re: Office 360 Subscription Renewal Opens Additional Link to www.77b.com
« Reply #4 on: February 14, 2016, 03:30:55 AM »
aswMBR attached here.

Please let me know if I missed uniquely identifiable information in the files attached other than usernames (sgnups and signups2), PC name (laptop0), network addresses (10.1.abc.xyz), the 3 categories, I've changed.
« Last Edit: February 14, 2016, 04:02:57 AM by fesignups2 »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Office 360 Subscription Renewal Opens Additional Link to www.77b.com
« Reply #5 on: February 14, 2016, 01:16:34 PM »
No apparent malware on the system.  However, the IP is suspect http://whois.domaintools.com/77b.com  http://77b.com.ipaddress.com/


The only way I could see this happening is if the update module  for office was subverted or the DNS has been hijacked (although I would expect further alerts for this)

REDACTED

  • Guest
Hi all,

I rolled back my Windows install to a restore point a few months earlier and the problem disappeared. Unfortunately, by doing so, I rolled back a lot of changes so it's going to be hard to pinpoint what exactly caused the issue.

_t