Firefox hijack?

Discussion in 'Malware Help (A Specialist Will Reply)' started by zakrz1, Jul 16, 2007.

  1. zakrz1

    zakrz1 Private First Class

    For the last week I've been seeing either transferring data fom a1040.g.akamai.net or from switch.atdmt.com on the bottom status bar of Firefox, preventing me from accessing bookmarks (I have to actually go to manage bookmarks to open anything!). Doesn't happen in I.E.
    Firefox latest version. Ran Ccleaner, Counterspy, Spybot, Hauri's ViRobot (anti-virus), Bitdefender, Getrunkey, Shownew, Hijackthis. Even tried adding those 2 to hosts pointing to 127.0.0.1 which didn't help..... Any ideas?
    Thanks,
    Zakrz1
     
    Last edited: Jul 16, 2007
  2. zakrz1

    zakrz1 Private First Class

    I haven't submitted any logs, in case someone identifies this problem for a particular scan first...
    Zakrz1
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The only way we will really be able to help you is if you complete ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support and attach all of the logs for us to look at. This is nothing in your first message that is really going to help us. akamai is used by many ISPs and atdmt is normally just a cookie. Neither of these would block you from getting to your Favorites. In fact, that does not even sound like a malware problem. You may want to first just try uninstalling FireFox, rebooting, and then reinstall and make sure you have the current version Mozilla FireFox
     
  4. zakrz1

    zakrz1 Private First Class

    OK ran Panda (that should cover, all scans completed), reinstalled Firefox, no difference.
    Attaching logs. Many new files because rebuild HD recently.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to install and rename HijackThis as requested and attach a new log.

    Also you need to attach the other three requested logs:
    • CounterSpy
    • BitDefender
    • PandaActiveScan
     
  6. zakrz1

    zakrz1 Private First Class

    Panda didn't find anything or offer to save a log....
    Zakrz1


     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
      [*]It will create a folder named HostsXpert in whatever folder you extract it to.
      [*]Run HostsXpert.exe, click Restore Microsoft's Hosts File and then click OK.
      [*]Click the X to exit the program

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_10
    Java(TM) SE Runtime Environment 6 Update 1

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) -
    O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanage...ex-2.2.1.2.cab

    After clicking Fix, exit HJT.

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 8 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  8. zakrz1

    zakrz1 Private First Class

    Ok, did as instructed. It blew out my Counterspy (icon turned black). Tech support e-mailed the following fix: 1. Click on the link below to download and install the Microsoft Installer Clean Up utility:
    http://tinyurl.com/3eukh
    2. Run the utility by clicking on Start -> All Programs -> Windows Installer Clean Up
    3. Select any entry regarding Sunbelt CounterSpy and click "Remove"
    4. Use the link below to download and install CounterSpy 2.1
    http://go.sunbelt-software.com/?linkid=410

    I'm going to have to rebuild my hosts file again so I can map and work on remote servers...
    Zakrz1

     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing we did has anything to do with CounterSpy.

    I assume this means you are using a paid version of CounterSpy?

    You logs are clean. Are you still having problems?
     
  10. zakrz1

    zakrz1 Private First Class

    Yes, paid ver. Counterspy. I fixed and reinstalled it and updated my hosts file. Firefox launched without the original problem. Wish I knew what caused it..?
    Thanks much!
    Zakrz1
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I would suggest you keep a backup of your hosts file in another folder (do not keep it where the real hosts file is). Many times when PCs are being cleaned of malware the hosts file is going to be reset to default since it is a very common place for malware to insert itself. Large hosts files make it easy for malware to hide and it is rarely necessary to put anything in a hosts file.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    2. After doing the above, you should work thru the below link:
     
  12. zakrz1

    zakrz1 Private First Class

    Came back..... (see attached screen dump....) Just keeps saying transferring data from .akamai. in the case of my dogpile homepage or forums.majorgeeks.com as the case is with this reply to thread scr3een open.
    Zakrz1
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That URL appears to be used inorder to get access to dogpile. I just loaded up dogpile and observed it in the status bar too. Thus it is related to whatever you are doing at dogpile.
     
  15. zakrz1

    zakrz1 Private First Class

    No that O16 line did not return. Dogpile, being the homepage, should load and display "Done" on the bottom status bar. Instead it will get stuck on akamai.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but that is not due to malware. It is part of something going on when you access dogpile. For some reason it is not completing. Does it happen if you use IE to access the site?
     
  17. zakrz1

    zakrz1 Private First Class

    Doesn't happen in I.E. I changed my homepage to google and it hangs on that!
    Even reinstalled Firefox again....
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I doubt it has anything to do with malware. It could be related to something you have configured in FireFox. Perhaps a plugin of some type or possibly you have configured something else on your system that is blocking cookies....etc on FireFox.

    READ ALL OF THE BELOW BEFORE DOING ANYTHING:

    Try uninstalling FireFox and rebooting. Then delete all the associated folders for FireFox. Like C:\Program Files\Mozilla Firefox and C:\Documents and Settings\zak\Application Data\Mozilla

    Then reinstall FireFox and keep it barebones to start and see how it works. You may wish to make a backup of the above folders first to avoid loosing any plugins and settings, favorites..etc. Just in case this does not help you can just copy everything back from these backups. Also make sure you are using the new version of FireFox that just came out: Mozilla Firefox
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds