Firefox Hijack - seventhdayslubmer.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by scriberuk, Apr 14, 2009.

  1. scriberuk

    scriberuk Private E-2

    Hi all,

    For a few days now it has become clear that something has hijacked firefox 3.0.8... sometimes clicking on google search results sends me to a different link, mainly obscure search engines. It also occasionally tries to get me to download "Web Media Player" (screenshot attached).

    I have also been getting an email related error (screenshot attached) on startup which appears to run as csrss.exe, is that something to worry about?

    I have tired every anit-virus,spyware,malware program under the sun (mcafee av, stopzilla, adaware, malwarebyte, avira av, comodo av, spyware doctor, windows defender to name a few) and yet I still appear to have the problem! :(

    Help! :)

    Kindest regards,

    Andrew
     

    Attached Files:

  2. scriberuk

    scriberuk Private E-2

    Redirects to:
    - approvedchoices.com
    - britanniasearch.co.uk
    - seventhdayslubmer.com/WebMediaPlayerInstallation
    - google.co.uk/undefined
     
  3. scriberuk

    scriberuk Private E-2

    - bestsoft09.com/eu/GB/ (Web Media Player download from 216.12.161.18, digitally signed by "FAVORIT NETWORK S.L.")
    - videotoolsfree.com
     
  4. scriberuk

    scriberuk Private E-2

    Looking at the status bar, I noticed that the domain "poiskin.ru" came up a few times and after further searching around on your site I came across GooredFix.

    That showed the following entry in the log file:

    =====Suspect Goored Entries=====

    C:\Program Files\Mozilla Firefox\extensions\{2FF38137-073B-459F-A2E5-24A7E9E5E15B}

    And... after running it a second time, it appears to have fixed the problem! :)

    On further investigation it would appear that "overlay.xul" was sealing requests made to google, yahoo, altavista and the like and redirecting them to a site picked from "http://v1.adwarefeed.com/..." based on the search engine used and the term serached.

    For good measure, I also added the following to my hosts file:

    127.0.0.1 poiskin.ru
    127.0.0.1 v1.adwarefeed.com
    127.0.0.1 seventhdayslubmer.com
    127.0.0.1 216.12.161.18
    127.0.0.1 bestsoft09.com

    I hope all that helps someone?

    Andrew
     
  5. scriberuk

    scriberuk Private E-2

    Lastly I'll just add this to help someone identify the same problem...

    It also redirected me to:

    - thetop10.com
    - stop-sign.com
    - 2009softwarereviews.com

    and also tried to download "Web Media Player" again but instead of the dialog box appearing from "seventhdayslubmer.com" it appeared from:

    - videotoolsfree.com

    with the message (screenshot attached):

    Firefox 3.0.8. Warning! Latest version of Web Media Player is available.
    Please start updating Web Media Player components.

    OK/Cancel

    Clicking "Cancel" didn't make any difference!
     
  6. scriberuk

    scriberuk Private E-2

    Two more screenshots added.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to avoid making unnecessary posts after making your first post with logs. Additional post cause bumping and add significant additional delay. See this sticky thread: Don't Bump! It Only Hurts You!!!

    You did not install and run SUPERAntiSpyware as requested.
    Also you have Malwarebytes installed but you did not attach log from it that we requested. We stated that logs need to be attach even if nothing is found.

    Who gave you instructions to run CFScript.txt with ComboFix?

    Your problem was quite simple. You just needed to delete the below file.

    Code:
    C:\Program Files\Mozilla Firefox\extensions\{2FF38137-073B-459F-A2E5-24A7E9E5E15B}\chrome\content\
    overlay.xul   29 Mar 2009        6001  "overlay.xul"
    Are you still having problems?

    Oh and you need to uninstall all the below old Sun Java versions and install the current versions as requested in step 1 of the READ & RUN ME:
    J2SE Runtime Environment 5.0 Update 16
    Java(TM) 6 Update 11
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6

    You also need to uninstall all but one antivirus as reqested. You have Avira and Comodo installed and also have left overs from an incomplete uninstall of McAfee.
     
    Last edited: Apr 19, 2009
  8. scriberuk

    scriberuk Private E-2

    Hello,

    Many thanks for help. Sorry I was a little impatient, its a little hard not to be when it feel like a personal attack; of course it isn't but it can feel like it...

    I agree that the problem was just that "overlay.xul" file and having deleted it the problem has gone away.

    I work for a software company and our product is Java based, hence the reason why I have so many versions installed. Is there a way that I can safely keep them installed or should I perhaps run them on a virtual machine?

    Again, many thanks,

    Andrew
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Old Java versions have security issues. If you are developing applications that require old versions of Java then your applications can be putting peoples PCs at risk. Yes you could potentially use a virtual machine in your environment which could help mitigate problems that could occur due to outdated Java versions but you should be suggesting that users of your software get updated where possible and your software should be tested for compatiblity.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds