Firefox always connecting to a site.

Discussion in 'Malware Help (A Specialist Will Reply)' started by NuMs1, Dec 29, 2010.

  1. NuMs1

    NuMs1 Private E-2

    Heya.

    So I will often open the Resource Monitor to check whats going on every now and then and I noticed that Firefox.exe and msnmsgr.exe are connecting to www.onlinerewardscenter.com. Firefox is always trying to connect when its open and msn will be doing it most of the time.

    http://img207.imageshack.us/img207/3766/firefoxb.th.png
    ^ Whenever firefox is open, that's what it shows.

    From what I can gather it's not a website you'd want to go to so why are they both trying to connect to it >.<

    I've tried blocking it using the hostfiles trick (127.0.0.1 <url>) and I have also added it to my routers blocked sites filter which I know probably wont do anything.

    I run firefox with adblock and noscript. I even have it set to ask me whenever a website wants to set a cookie so I'm not sure how I could of gotten this (if it is infact malware)

    Anyway, I have Windows 7 Home 64 bit and I've run the Vista/7 cleaning steps posted here.
    http://forums.majorgeeks.com/showthread.php?t=139681.

    Here are the logs.
    Can anyone please help >.<
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you run combofix as per the instructions and also attach that log. C:\Combofix.txt

    Thanks.
     
  3. NuMs1

    NuMs1 Private E-2

    Thank you for replying.

    I am trying to run Combofix but when it tries to create the log a window pops up saying.

    "PEV.cfxxe has stopped working"
     
  4. NuMs1

    NuMs1 Private E-2

    Ok, it worked now.

    Posting the log

    Looking at the resource monitor again.
    svchost.exe and wmpnetwk.exe are also connecting to that site on startup.
     

    Attached Files:

    Last edited: Dec 29, 2010
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm I am not seeing anything unusual. Run Ccleaner. (Not the registry section just the cleaner)

    Now be sure to reboot the machine.

    Run this:

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Still seeing the onlinereward site showing up?
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oh and Malware Bytes was outdated, so open up the program > locate the update tab > re-scan > and attach the log regardless of what it does or does not find.
     
  7. NuMs1

    NuMs1 Private E-2

    Ran CC cleaner.
    TDSS Killer found nothing.
    Updated Malwarebytes and rescanned, found nothing.

    Still happening >.<
     

    Attached Files:

    Last edited: Dec 29, 2010
  8. NuMs1

    NuMs1 Private E-2

    Given up on me? >.<
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please read this:
    Don't Bump! It Only Hurts You!!!

    Kes is under the weather and has gone to rest.

    Try doing this:
    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks:
    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla FireFox

    You will need to exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.
    After reboot, delete the below folders:

    C:\Documents and Settings\UserAccount\Local Settings\Application Data\Mozilla
    C:\Program Files\Mozilla Firefox

    where UserAccount is the actual user account name being used.

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).


    Is FireFox working okay now?
     
  10. NuMs1

    NuMs1 Private E-2

    Hi Tim.

    I have tried that. When firefox is uninstalled, Internet Explorer will do it.

    svchost.exe and wmpnetwork.exe will also do it.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you running through a router? Are other computers using the router also being redirected? If you are, try resetting the router by pressing the red recessed buttom on the back or bottom of the router and hold it for a few moments. You will have to reset your configuration if you made any custom settings.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, bumping gets you nowhere. You are just lucky that we have not been too busy otherwise it would have cost you a wait time. :( We have lives to lead outside of the forum and I take pride in my fast responses. I have flu at the moment and am trying to juggle that, a visit with my Father AND the malware forum.

    As well as what TimW suggested try the below.

    Run this and attach the results.

    Using ESET's Online Scanner

    Now run this:

    GMER - running with a random name
     
  13. NuMs1

    NuMs1 Private E-2

    TimW:
    I am on a router, the other computers are fine.
    I'm not being redirected, just whenever Firefox/Internet Explorer is open its constantly opening connections to that site.
    msnmsgr.exe is also occasionally doing it.
    svchost.exe and wmpnetwk.exe are both doing it on startup as well.

    Kestrel13!:
    I ran both scans, neither of them picked up anything.
    Every scan I've done so far hasn't picked up anything yet its still doing it >.<

    Was going to do a system restore but all the restore points seem to have disappeared.

    Might just have to completely reinstall windows.

    Both scans didn't give me a log, where do they save them?
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It tells you in the instructions. (In the links I gave)
     
  15. NuMs1

    NuMs1 Private E-2

    I've decided to just do a complete format of the HDD and reinstall windows.
    No scans were getting anything >.<

    Thank you Kestrel and Tim for all your help :)
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Would have been interesting to have dug deeper. What software did you say you had installed which was showing the onlinesurvey stuff? :confused
     
  17. NuMs1

    NuMs1 Private E-2

    I didn't have any new software doing it.

    Svchost.exe, wmpnetwk.exe, msgmsgr.exe and firefox/iexplorer.exe were doing it/
     
  18. NuMs1

    NuMs1 Private E-2

    msnmsgr.exe*

    Not even sure how I got it in the first place, I hadn't downloaded anything or been to any unusual sites.

    Whenever a web browser was open or whenever MSN was open it was connecting to that site, was weird.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The screenshot you posted originally. What was that from?
     
  20. NuMs1

    NuMs1 Private E-2

    The resource monitor that Windows 7 (and probably vista) has.
    It will show Disk, Network, Memory and CPU usage and the services of whatever program is running.

    Task Manager > Performance Tab > Resource Monitor.
     
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm very strange indeed. Would have been nice to have got to the bottom of it. How are things running since you formatted?
     
  22. NuMs1

    NuMs1 Private E-2

    Perfectly.

    Haven't had any issues.
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  24. NuMs1

    NuMs1 Private E-2

    Will do.

    Thanks again for the help, you too Tim :)
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds