Firefox Home Page hijack and more

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by commus, Mar 15, 2015.

  1. commus

    commus Private E-2

    This has probably already been covered before but here goes.

    A week or so ago I was trying to print coupons and was directed to allow software install (i know....stupid). I did. I had multiple Firefox windows and multiple tabs withing windows open. The thing went crazy.

    Since then Firefox is a mess.
    1. Slow.
    2. home page is going to yahoo while I had it set to AOL. it is now set to aol but when a new tab is open it goes to YAHOO. Clicking on the Home page icon will send it to aol.
    3. Windows will flip back and forth
    4. Session manager is a mess. It will not update.
    I hope I have attached all the correct files
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you deliberately set up to use a proxy of any type?
    Re run Hitman and have it remove the "Malware Remnants" and Potentially Unwanted Programs.

    Reboot..
    rescan with Hitman again (just a scan) and attach log.


    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  3. commus

    commus Private E-2

    done and done.

    thanks
     

    Attached Files:

  4. commus

    commus Private E-2

    Forgot MGlogs
    still getting home page hijack to yahoo and
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there, could you re run RogueKiller please and attach log.
     
  6. commus

    commus Private E-2

    Yes, just reran it
    Not sure but followed the original instructions that said not to delete anything just scan
    log is attached.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    How are things running? :)

    Are all these showing in RK because of the proxy software you have installed??

     
  8. commus

    commus Private E-2

    No. I have not had or used proxy software in over 15 years.
    Unless it was installed without my knowledge.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then fix those items using RogueKiller and then let me know if you still have issues.
     
  10. commus

    commus Private E-2

    Corrected with Rogue Killer, rebooted and reran RK.
    Still problem.
    Log attached.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Remind me what is the problem..? Because your home page is set to yahoo you think this is malware? Please elaborate.
     
  12. commus

    commus Private E-2

    Here is the original post

    Since then Firefox is a mess.
    1. Slow.
    2. home page is going to yahoo while I had it set to AOL. it is now set to aol but when a new tab is open it goes to YAHOO. Clicking on the Home page icon will send it to aol.
    3. Windows will flip back and forth
    4. Session manager is a mess. It will not update.
    I hope I have attached all the correct files


    Specific to #1 the home page in the options is set to "http://www.aol.com/"
    When Firefox is opened or any new tab is opened it goes to "https://www.yahoo.com/?fr=befhp&type=ffhp-3.16-1503" instead of the aol page.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That is not a malware problem. Do you have any actual malware issues?
     
  14. commus

    commus Private E-2

    So my browser is redirected to somewhere it is not supposed to go is not malware?
    then what is it?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is how you have your new tab settings set in Firefox. You logs showed you have it set as below
    If you don't want this to happen you need to set it to what you want in your Firefox options. This is not a malware problem. See the below:

    https://support.mozilla.org/en-US/kb/new-tab-page-show-hide-and-customize-top-sites
     
  16. commus

    commus Private E-2

    I never set it that way.
    Where is this setting?
    I only set browser settings in the options screens.
    TOOLS>OPTIONS
    With your link I have modified it but have not changed it myself.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It may have been changed if you downloaded or installed anything related to Yahoo and their search engine. iBut it is still not malware.
     
  18. commus

    commus Private E-2

    I don't even use Yahoo I use Google for maps or searches and I use the browser of neither.

    So I guess this no longer applies:

    http://en.wikipedia.org/wiki/Malware

    Malware, short for malicious software, is any software used to disrupt computer operation, gather sensitive information, or gain access to private computer systems.[1] Malware is defined by its malicious intent, acting against the requirements of the computer user, and does not include software that causes unintentional harm due to some deficiency. The term badware is sometimes used, and applied to both true (malicious) malware and unintentionally harmful software.

    So I guess it would be badware and you do not support it.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The point is that it is just a settings issue that needs to be set back to what you want. We do not know and neither do any scanners know, what you want for your home pages or what you want to happen when you create new tabs. The only time it would be fixed by us or a scanner would be if the information/content was going to a malware related URL. yahoo is not considered malware just like google is not.

    Many settings on a PC can be changed that we would have no idea whether it is what you wanted or not. Just like if your actual home page itself had been changed or your screen resolution had been changed.....etc. You just need to set it back to what you want. If any malware were still in control or causing the setting to be changed then it would probably just be changed back to the undesired values or potentially you could be blocked from making a change. But even being blocked from making changes may not be due to malware, it could be due to problems within Windows that have messed up permissions. This happens all the time in Windows without having malware being the root cause.
     
  20. commus

    commus Private E-2

    Okay.

    I was gooing to say something but never mind.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  22. commus

    commus Private E-2

    AS can be seen from the original post I am still having all the other problems but as has been pointed out they are not malware so not appropriate here.
    I will hopefully find a friendly place to address them. rolleyes
     
  23. commus

    commus Private E-2

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Many issues with Firefox are just due to bad add-ons or settings changes. And sometimes the most expedient way to fix these kinds of issues is to just reset Firefox back to default settings. See the below:

    Reset Firefox to Defaults
     
  25. commus

    commus Private E-2

    And among other things destroys

    Extensions and themes, website permissions, modified preferences, added search engines, download history, DOM storage, security settings, download actions, plugin settings, toolbar customizations, user styles and social features will be removed.
     
  26. commus

    commus Private E-2

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it does! Many people are not capable of doing all the manually editing that can be required to cleanup all the junk that can get hook into Firefox. And Firefox does not give easy ways to delete all the junkware extensions and add-ons too as is evident from the hundreds of people posting here each week with problems that they cannot resolve in Firefox without either resetting to defaults or by uninstalling and reinstalling. And in fact an uninstall/reinstall usually does not work because you also have to delete all the Firefox folders too in order to remove the hooks that are embedded into the files that will remain and be reused.

    If you have the knowledge, you can attempt to manually edit and remove unwanted items from Firefox's configuration files. AdwCleaner and JRT will get rid of many issues but they do not always get everything.
     
  28. commus

    commus Private E-2

    Look...you claim that it is not malware. So why do you continue top argue just changing the subject to something other than the original.
    I will not reply as you have told me that my posting is inappropriate for this topic as are all of yours.


    Now you are justified in making final statement that cannot be addressed and locking down the thread.
     
    Last edited: Mar 22, 2015
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have no idea what you are talking about. My last message just agreed with you that resetting to defaults changes other settings too.

    And then I went on to juts say that many people do not have the ability to make changes/edits to their settings. And then in the last sentence I just said, if you know how to make the changes then just go ahead and make then manually so that you do not have to reset to defaults since apparently you did not want to do a reset.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds