Trojan or Virus Help Please.

Discussion in 'Malware Help (A Specialist Will Reply)' started by seanme, Sep 27, 2006.

  1. seanme

    seanme Private E-2

    I have done the recommended steps before posting and I am still having problems. When I open my firefox browser I get tcp connections to:
    static-fxfeeds.nslb.sj.mozilla.com
    newslb14.thdo.bbc.co.uk

    There is a similar thread here that I've read through but is not exactly the same (I think) so I havnt followed the fix's recommended there.
    http://forums.majorgeeks.com/showthread.php?t=102001

    This problem only seems to effect firefox, IE is not effected by it. Everything is up to date like recommended. I have also done all the steps to do before posting and am including the logs. Hopefully with some help this can be fixed. Thanks.
     

    Attached Files:

  2. seanme

    seanme Private E-2

    Here are the rest of the logs.
     

    Attached Files:

  3. seanme

    seanme Private E-2

    I hate to post again to bring this back to the end of the line but I'm starting to assume you can't help me with my problem (posts started after mine are being dealt with) If thats the case please say so and I'll take the drastic measures of formating everything and starting from scratch. My biggest concern is all my passwords have been compromised online banking, email, etc etc. Please any advice would be great. Thanks.
     
  4. seanme

    seanme Private E-2

    I decided to install Kerio Personal firewall (got it from here) and in my nips logs it has logged 2 entries. I've included a screenshot of it.
     

    Attached Files:

  5. seanme

    seanme Private E-2

    Just informing you I'm reformating, so disregard my previous posts.
     
  6. seanme

    seanme Private E-2

    Thought I'd update my thread with the problem solved. After doing a full format of all drives and reinstall of windows as soon as I installed firefox my problem was back. So after searching and searching I finally found this:

    "It is for the default BBC rss feed in FireFox.
    It is just d/l'ing the current headlines."

    "As I don't use any RSS feeds, I deleted the RSS tab and the connections are gone."

    I did the same and deleted the tab and the connections are gone. 100 gig's of lost data later for nothing lol Hope this helps someone so they don't go through what I just did.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry about this! Some how you kept slipping thru under the radar! But I'm happy see you have figured out why those connections existed. It should have been a little obvious from the connection URLs that you listed in your first message that these were related to Mozilla and BBC. But sometimes the obvious is just not so obvious at the time.;) Thanks for coming back and posting your followup. I'm sure, just like you, that others would worry about these connections if they found them.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds