firefox hijacked by fire search

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by toa monty, Feb 24, 2008.

  1. toa monty

    toa monty Private E-2

    Hi, my firefox homepage has been hijacked by "firesearch" I don't like it. Even when i use Internet explaorer instead of google it comes up with "ie search"
    Never seen these before.:(
     

    Attached Files:

  2. Lev

    Lev MajorGeek

  3. toa monty

    toa monty Private E-2

    Hi here are the three files. my apologies for not doing all steps at first.
    Look forward to hearing from you. cheers:eek:
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please remove C:\Documents and Settings\Janet\Desktop\MGtools.exe from your Desktop. This is not where we asked you to put it.

    Are you sure that in FireFox that your Home Page is set to what you actually want? Take a look and see. Click on Tools > Options > Main tab

    Accoring to your logs, you do not have a Home Page even setup for IE so it will just goto the default.

    Is the below folder something you created?
    Code:
    "C:\Documents and Settings\All Users\Application Data\"
    README~1      23 Feb 2008              "Readme Live Axis Tons"

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 3

    Now we need to use ComboFix delete a file and collect some info on others.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    File::
    C:\WINDOWS\system32\SystemV.dll
    
    DirLook::
    C:\Documents and Settings\All Users\Application Data\Readme Live Axis Tons
    FileLook::
    C:\WINDOWS\system32\CNQ4805C.DLL
    C:\WINDOWS\system32\CNQ4805L.DLL
    C:\WINDOWS\system32\CNQ4805O.DLL
    C:\WINDOWS\system32\CNQ4805I.DLL
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. toa monty

    toa monty Private E-2

    hi, apologies for misplacing mgtools. I have no idea what "Readme Live Axis Tons" is. I have been able to reset my browser back to Firefox. I have also realised that my firewall "Comodo" gets cranky and kept dropping me offline. Iwill monitor it and let you know how things go. thanking you , toa monty.:)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then I suggest that you delete the below folder since it is empty anyway:

    C:\Documents and Settings\All Users\Application Data\Readme Live Axis Tons


    You may want to try uninstalling it, then reboot (do not skip the reboot), and then reinstall. And see it there is any change in the behavior.


    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
     
  7. toa monty

    toa monty Private E-2

    Hi, all final instructions are complete. I have Comodo firewall in place. AVG, new java etc. Created clean restore point. PC is working very well. Also grabbed Glubber. Thanks for all your help and patience.:wave cheers - toa monty
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds