Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Google Search on Firefox hijacked


  • Please log in to reply
4 replies to this topic

#1 pleinairbrooks

pleinairbrooks

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:05:28 PM

Posted 10 April 2013 - 08:10 PM

When I seach with google on firefox I get what looks like a good list of hits. However, when I click on a google selected site an advertizement site come up. for example: http://www.gamezone.com/videos came up for a site that should have been: Mark Rothko Nation art museum.? this just started today and i have not tried anything yet. I came here first.

brooks



BC AdBot (Login to Remove)

 


#2 pleinairbrooks

pleinairbrooks
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:05:28 PM

Posted 10 April 2013 - 08:16 PM

I just tried Internet Explorer and the first site I selected worked fine (wikipedia), but the second click I got this ad site:http://www.glam.com/fashion/lookswelove/?utm_source=ADK&utm_medium=cpc&utm_campaign=liz_dick&utm_term=78177-S70005

clueless,

brooks



#3 doinmeedin

doinmeedin

  • Members
  • 455 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:01:28 AM

Posted 11 April 2013 - 06:02 AM

Open firefox in safe mode and check see if you still have the problem,

Press start button>right click firefox>select "Firefox Safe Mode"

 

If your still having the same problem download and run mbam from this link :  http://www.bleepingcomputer.com/download/malwarebytes-anti-malware/ after running remove anything infected that it finds, then reboot !!

 

If this dosen't do the trick, then repost into (" Am I Infected What Do I Do Forum ") as usually bho's and browser hijackers can only be removed using HJT, under the supervision of one of the Mods, or Malware Fighters !

 

Hope this helps !


If life is not an option then why are we not given the option in the first place !


#4 Queen-Evie

Queen-Evie

    Official Bleepin' G.R.I.T.S. (and proud of it)


  • Staff Emeritus
  • 16,485 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:My own little corner of the universe (somewhere in Alabama). It's OK, they know me here
  • Local time:07:28 PM

Posted 11 April 2013 - 09:43 AM

If you post in Am I Infected do not post Hijack This logs in that forum. Some tools are NOT allowed outside Malware Removal Logs. HJT is one one them. You should make a detailed post about your issues and someone will let you know what to do and which scans to run.

Also, Bleeping Computer no longer recommends HJT. There are better tools available which the malware removal team uses now.

#5 pleinairbrooks

pleinairbrooks
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:05:28 PM

Posted 11 April 2013 - 01:30 PM

thanks all, MalwareBytes found the bugger in the registry and removed it. here is what they found (AVG did not find this)

Memory Processes Detected: 1
C:\ProgramData\IBUpdaterService\ibsvc.exe (PUP.InstallBrain) -> 2020 -> No action taken.

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 2
HKLM\SYSTEM\CurrentControlSet\Services\IBUpdaterService (PUP.InstallBrain) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Updater Service (PUP.InstallBrain) -> No action taken.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 1
C:\ProgramData\IBUpdaterService (PUP.InstallBrain) -> No action taken.

Files Detected: 5
C:\Users\b\AppData\Local\Temp\0.07945306858672274 (Trojan.Dropper.ED) -> No action taken.
C:\Users\b\Downloads\Setup.exe (PUP.IBryte) -> No action taken.
C:\Users\b\Local Settings\Temporary Internet Files\Content.IE5\PYJUNCE3\Firefox_setup.exe (PUP.IBryte) -> No action taken.
C:\ProgramData\IBUpdaterService\ibsvc.exe (PUP.InstallBrain) -> No action taken.
C:\ProgramData\IBUpdaterService\repository.xml (PUP.InstallBrain) -> No action taken.
 






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users