My wife started having some unusual browser hijacks over the last two days (she uses the latest version of Firefox). Rather than coming up with the standard fare (fake antivirus messages, ransomware, etc.) they are pop-ups for websites that are similar to ones that she searches for or visits frequently - news blogs, crafting sites etc., but they are obviously bad news. I've tried a number of different things.
1) Updated and ran malwarebytes multiple times (strangely, it keeps on believing it needs to update, every time it loads. unsure if this is a symptom or not): sometimes this discovers and eliminates 1 or more trojan downloaders, other times it does not.
2) Updated and ran avast multiple times: again, it occasionally finds things, most of the time not. Avast's web shield also blocks about 50% of the randomly opening pop-ups
3) Installed and ran HijackThis!: I tried this after I noticed an odd file in Startup that wasn't being spotted by malwarebytes or avast - ylzoe.exe. HijackThis could not remove it, so I FileAssassinated it through MBAM.
4) Tried a system restore, which failed. (uh oh)
5) Installed and ran Spybot S&D: like MBAM and avast, it found a couple of things and removed them.
6) Tried running Windows Update - the site is blank as if it is down.
7) Disabled all add-ons in Firefox. There was a Java extension running with known security vulnerabilities, but disabling it had no noticeable effect.
8) Before posting, I looked for other similar cases that were reported here, and noticed some similarities to rootkit infections (she's already had one, which I only got rid of by completely wiping her hard drive and starting over with a fresh build). So I ran a RootRepeal report, which found things. I will refrain from posting the log since this forum says 'no logs', and let someone direct me to where I should post it (if at all). I can also post a fresh HJ log, but it isn't finding the mystery items anymore.
Computer is running Windows XP Professional (SP 3), and the browser in question is Firefox v 3.6.3. Let me know if you need any other information. I really appreciate any help you can offer - I'm stumped!
Edited by treehouse916, 23 May 2010 - 10:34 AM.