Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 5th, 2009, 11:27 PM
ohblu ohblu is offline
Regular Poster
 
Join Date: Jul 2008
Location: Colorado
Posts: 78
Default Firefox hijacked

Could someone please suggest what customized scanner to use to detect malware that has hijacked Firefox? I used the installed AV scanner (Webroot) and I also used MBAM. I then used Trend Micro's online scanner. They find some but not all of the infected files. They're missing some that are in the Windows\System 32 folder. Even when they get all the infected files, Firefox is still being hijacked. I tried running a rootkit scanner and some other online scanner but they take more than 4hrs to scan and both times the electric went off. Go figure! So a customized scanner would be more convenient.

I really don't have the time or patience to post to a malware removal forum. So many of those people there are so condescending and rude and I'm sick of them. The infected computer is my grandmother's and she's getting ready to go on vacation so I need to get this malware off soon.

I'm not asking for anyone to help me remove this malware. I'm just looking for suggestions about which tools to use. I'm usually really good at getting malware off a computer, but this time I'm getting my butt kicked.
  #2  
Old December 5th, 2009, 11:55 PM
cheater87's Avatar
cheater87 cheater87 is offline
Massive Poster
 
Join Date: Apr 2005
Location: West Chester Pennsylvania.
Posts: 3,005
Default Re: Firefox hijacked

Try Superantispyware and Spyware Terminator's HIPS to see if that can find and block it.
__________________
I have Windows 7 64 bit Comodo Firewall 6 set to block, Avast Free Edition, K9 Web Protection set to block malicious and phishing sites only, Zemana Free Anti Keylogger, Comodo DNS, Firefox with Noscript, Adblock Plus, WOT set to block, Secunia PSI, and common sense. ^_^
  #3  
Old December 6th, 2009, 01:22 AM
pegr pegr is offline
Very Frequent Poster
 
Join Date: Apr 2008
Location: UK
Posts: 1,616
Default Re: Firefox hijacked

All of the following free programs are also worth trying: Avira AntiVir, Avast!, Microsoft Security Essentials, Panda Cloud Antivirus, and Prevx. Panda Cloud Antivirus and Prevx both require an Internet connection for the duration of the scan.

One point to bear in mind: The free version of Prevx won't remove what it finds (it will remove adware and MBR rootkits but only the paid version has full removal capability) but it scans very quickly, usually taking only a few minutes.

It's worth running Prevx as well because in my experience Prevx will sometimes identify components of malware infections missed by other scanners. If Prevx does identify something, at least you'll have the necessary information to attempt manual cleanup if the infection can't be removed by any other means.
  #4  
Old December 6th, 2009, 01:51 AM
tipstir's Avatar
tipstir tipstir is offline
Frequent Poster
 
Join Date: Jun 2008
Location: CT, USA
Posts: 827
Default Re: Firefox hijacked

Quote:
Originally Posted by ohblu
Could someone please suggest what customized scanner to use to detect malware that has hijacked Firefox? I used the installed AV scanner (Webroot) and I also used MBAM. I then used Trend Micro's online scanner. They find some but not all of the infected files. They're missing some that are in the Windows\System 32 folder. Even when they get all the infected files, Firefox is still being hijacked. I tried running a rootkit scanner and some other online scanner but they take more than 4hrs to scan and both times the electric went off. Go figure! So a customized scanner would be more convenient.

I really don't have the time or patience to post to a malware removal forum. So many of those people there are so condescending and rude and I'm sick of them. The infected computer is my grandmother's and she's getting ready to go on vacation so I need to get this malware off soon.

I'm not asking for anyone to help me remove this malware. I'm just looking for suggestions about which tools to use. I'm usually really good at getting malware off a computer, but this time I'm getting my butt kicked.

Run this in safe mode
Norman Malware Cleaner

Next time subscribe to Malware Blocker Subscriptions for Adblock Plus add-on
This will slow down FireFox then install the add-on called FasterFox Lite.

I have a family member ran into the same problem you're having. He had everything that was suggested. SmitFraudfix did remove the pest but left the system in a odd state. Now it has to be either restored from a safe backup or blow out the OS and re-install it then start all over again.
__________________

Network |TP-LINK: 3x TL-WR1043ND V1.7 |Stock ROM|
System |FW-7U/32/64-BIT |MSE |UAC |DEP ALL PROGRAMS |HOST-MVP |ASC Pro |M-SAS |M-MBS |
Browser |Chrome |Flash Block |Ad Block |Click & Clear |Personal Block |Disconnect |Select Out |Vanilla |
  #5  
Old December 6th, 2009, 02:20 AM
ohblu ohblu is offline
Regular Poster
 
Join Date: Jul 2008
Location: Colorado
Posts: 78
Default Re: Firefox hijacked

Quote:
Originally Posted by tipstir

I have a family member ran into the same problem you're having. He had everything that was suggested. SmitFraudfix did remove the pest but left the system in a odd state. Now it has to be either restored from a safe backup or blow out the OS and re-install it then start all over again.

I should hope Grandma doesn't have to rely on backups since she never bothered to do any.
  #6  
Old December 6th, 2009, 09:49 AM
Keyboard_Commando's Avatar
Keyboard_Commando Keyboard_Commando is offline
Frequent Poster
 
Join Date: Mar 2009
Posts: 682
Default Re: Firefox hijacked

http://forums.majorgeeks.com/showthread.php?t=182559

Try GooRedFix.
  #7  
Old December 6th, 2009, 04:36 PM
ohblu ohblu is offline
Regular Poster
 
Join Date: Jul 2008
Location: Colorado
Posts: 78
Default Re: Firefox hijacked

Quote:
Originally Posted by Keyboard_Commando

I tried it and it did remove something but Firefox is still being redirected. I've run several different anti-malware scanners including online scanners and they're not finding anything. Right now I'm in the middle of running Root Repeal. I hope something turns up. I'm at a loss as to what to do. I've never encountered a problem like this before.
  #8  
Old December 6th, 2009, 04:53 PM
Tarq57's Avatar
Tarq57 Tarq57 is offline
Frequent Poster
 
Join Date: Oct 2006
Location: Wellington NZ
Posts: 966
Default Re: Firefox hijacked

Windows XP?
Navigate to "C:\WINDOWS\system32\drivers\etc" and double click on the file "HOSTS". Open it with notepad, and do not tick the box to always open this file with this program.
It should look a bit like this:
Quote:
# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine (host) name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
etc.
Have a look at this.
__________________
Avast Home, MVPS Hostsfile,Secunia PSI Autorun Eater, Windows Firewall, MBAM (demand), XP SP3.
  #9  
Old December 6th, 2009, 05:17 PM
ohblu ohblu is offline
Regular Poster
 
Join Date: Jul 2008
Location: Colorado
Posts: 78
Default Re: Firefox hijacked

I'm already a step ahead of you. I checked the HOSTS file the other day and it was clean. I'm thinking this is some sort of TCP/IP hijacking and/or the atapi.sys file is infected. How would I go about replacing that file? Grandma doesn't know where any of her installation or rescue disks are. The computer is Win XP.
  #10  
Old December 6th, 2009, 06:16 PM
Saraceno's Avatar
Saraceno Saraceno is offline
Very Frequent Poster
 
Join Date: Mar 2008
Posts: 2,398
Default Re: Firefox hijacked

I'd try:

a-squared free - www.emsisoft.com/en/software/free/ (excellent for toolbars, redirections and so on, use a deep scan for the first time)
a-squared online version - www.emsisoft.com/en/software/ax/ (must use IE)

Hitman Pro - www.hitmanpro.com (free scanning, 30 day removal which can be activated anytime)

If none of the above, you might want to try to back up your bookmarks, save the file to your desktop, uninstall firefox with www.revouninstaller.com in advanced mode removing all traces of firefox in the registry (including firefox add-ons, and anything related to firefox etc - be sure to review the list of the registry scan, and check all the necessary files).

Then re-install firefox. You could also sort the installations in revo by installation date, see if anything was installed on a specific date without your knowledge. http://www.revouninstaller.com/ - it's free, I use the portable version which doesn't need to install.

Name:  revo.jpg
Views: 565
Size:  146.5 KB
__________________
Fine Art Landscape Photography

Last edited by Saraceno : December 6th, 2009 at 06:23 PM.
  #11  
Old December 6th, 2009, 09:30 PM
chronomatic chronomatic is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,324
Default Re: Firefox hijacked

Quote:
Originally Posted by ohblu
Could someone please suggest what customized scanner to use to detect malware that has hijacked Firefox? I used the installed AV scanner (Webroot) and I also used MBAM. I then used Trend Micro's online scanner. They find some but not all of the infected files. They're missing some that are in the Windows\System 32 folder.

Stop running as admin. Problem solved.
  #12  
Old December 7th, 2009, 11:52 AM
Keyboard_Commando's Avatar
Keyboard_Commando Keyboard_Commando is offline
Frequent Poster
 
Join Date: Mar 2009
Posts: 682
Default Re: Firefox hijacked

Quote:
Originally Posted by chronomatic
Stop running as admin. Problem solved.

Helpful comment. NOT!
  #13  
Old December 9th, 2009, 12:38 PM
ohblu ohblu is offline
Regular Poster
 
Join Date: Jul 2008
Location: Colorado
Posts: 78
Default Re: Firefox hijacked

I was not able to find any infections with any of the malware/rootkit scanners I tried. Every night it develops a Vundo infection but there's something else on there that I can't find. I even uninstalled and upgraded to a different version of Firefox with no luck. What I did discover is that this redirect problem is more noticeable and happens more when using a toolbar such as the Google or Yahoo toolbar. In fact, the average user probably wouldn't even notice anything if they weren't using a toolbar.

After I discovered the computer would no longer boot into safe mode, I told grandma she needed to have a professional look at it. So she's going to have them reformat the C drive since it needed it anyway.
  #14  
Old December 9th, 2009, 02:51 PM
Searching_ _ _'s Avatar
Searching_ _ _ Searching_ _ _ is offline
Very Frequent Poster
 
Join Date: Jan 2008
Location: iAnywhere
Posts: 1,988
Default Re: Firefox hijacked

Couple of simple things to try.

Turn off and unplug the router.
WipeCMOS <---not a requirement, just a thought.
(On 1 of my HDD I have an infection that attacks the CMOS from boot up.
I'll get around to wiping the drive someday.)
Turn Off and unplug computer.
Make a cup of coffee or tea.
Turn all back on.
__________________
Americans are the enemy? Mil. can arrest you?
What the heck is going on?
  #15  
Old December 10th, 2009, 02:17 AM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,517
Default Re: Firefox hijacked

I'm infected - What do I do now?
  #16  
Old December 10th, 2009, 09:32 PM
TheQuest's Avatar
TheQuest TheQuest is offline
Very Frequent Poster
 
Join Date: Jun 2003
Location: Kent. UK by the sea
Posts: 2,226
Default Re: Firefox hijacked

Hi Searching_ _ _

Quote:
(On 1 of my HDD I have an infection that attacks the CMOS from boot up.
I think your find it is [was] the boot sector of the HDD, not the CMOS under attack.

Take Care
TheQuest
__________________
When Nothing is Certain, Anything is Possible.
  #17  
Old December 10th, 2009, 11:18 PM
Searching_ _ _'s Avatar
Searching_ _ _ Searching_ _ _ is offline
Very Frequent Poster
 
Join Date: Jan 2008
Location: iAnywhere
Posts: 1,988
Default Re: Firefox hijacked

Quote:
Originally Posted by TheQuest
I think your find it is [was] the boot sector of the HDD, not the CMOS under attack.
Yes I know. But it liked to change the CMOS time, so I wiped it just in case.
I use the Black Flag method. Hold breath and spray everything.
__________________
Americans are the enemy? Mil. can arrest you?
What the heck is going on?
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:26 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums