Wikiposts
Search

Notices
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Firefox Hijacked

Thread Tools
 
Search this Thread
 
Old 21st July 2011 | 15:45
  #1 (permalink)  
Thread Starter
20 Anniversary
 
Joined: Jul 2003
Posts: 238
Likes: 15
From: Cow Corner
Firefox Hijacked

My parents back in Bombay have a unique problem. They were hit by a trojan that, amongst other things, replaced the default Firefox start page with an ad for a "Pharma" site. The trojan has been removed by an AVG bootable disk, but NOTHING gets rid of the Firefox issue. Not the usual Tools > Options sequence, not an about:config solution (whatever they try keeps getting replaced with the Pharma URL).

I even tried to get them to uninstall FF, but there seems to be no uninstaller. Eventually, they've installed Chrome, and I'm advising them to delete the FF directory and User Data and do a manual fresh install. There's only so much I can do on the phone from 5,000 miles.

But how does this happen, and how can it be prevented? They run a limited user account and I believe their antivirus was up to date. Also, I'd installed Adblock for them last time around, though not NoScript.

If I was hit by such an infection, what would be a good way to solve it?
BombayDuck is offline  
Reply
Old 21st July 2011 | 16:25
  #2 (permalink)  

Usual disclaimers apply!
 
Joined: Nov 1999
Posts: 843
Likes: 0
From: EGGW
Snoop

Try Malwarebytes : Malwarebytes Anti-Malware is a free download that removes viruses and malware from your computer update then run and see if that clears it.
gas path is offline  
Reply
Old 21st July 2011 | 17:47
  #3 (permalink)  
More bang for your buck
 
Joined: Nov 2005
Posts: 3,513
Likes: 1
From: land of the clanger
Try deleting the User.js file which is located in your 'Profile' folder. You can search for user.js to locate. Make sure that show hidden files/folders is enabled as the Profile folder is hidden in Win2K and XP unless you set show all files/folders.
green granite is offline  
Reply
Old 21st July 2011 | 18:21
  #4 (permalink)  
Thread Starter
20 Anniversary
 
Joined: Jul 2003
Posts: 238
Likes: 15
From: Cow Corner
green granite, I've asked my brother-in-law to do that. Anyway, they've shifted to Chrome for now. I'm still troubled and annoyed, this is not something I expect with Firefox. I was hit with a Trojan on a drive-by last month, in spite of running a fairly tight ship.
BombayDuck is offline  
Reply
Old 22nd July 2011 | 04:07
  #5 (permalink)  
20 Anniversary
 
Joined: Dec 2005
Posts: 1,694
Likes: 15
From: Wellington,NZ
If you don't have NoScript installed on Firefox, you're wide open to any drive-by downloads that are not detected by the AV.

Most browsers default to allowing a certain level of script permission. From what I've seen, that default level is not very secure.

Another useful add-on that might have prevented this is a "super-cookie" (flash cookie) cleaner, it's another add-on for Fx, and called BetterPrivacy.

I don't know whether that would have prevented it, as I don't know the vehicle for the browser hijack.

Definitely recommend running MBAM, also.
Tarq57 is offline  
Reply

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.