Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Firefox Problems


  • Please log in to reply
6 replies to this topic

#1 buyer120

buyer120

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:22 AM

Posted 15 October 2013 - 01:44 PM

Mod Edit:  Split from http://www.bleepingcomputer.com/forums/t/507829/multiple-tabs-and-window-opening-automatically-in-firefox-photos-axxfbcdnnet/ - Hamluis.

 

Didnt wanted to start a new htead for the same problem
so i am bumping up my old thread

 

This problem have again came back and it has only affected firefox

It seems that this only happens on start up.
reseting the firefox everytime is not feasible
So guys please tell some other solution.

I think it is some kind of browser hijacker


Edited by hamluis, 16 October 2013 - 09:20 AM.
PM sent new OP - Hamluis.


BC AdBot (Login to Remove)

 


#2 buyer120

buyer120
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:22 AM

Posted 17 October 2013 - 04:37 AM

Here is the problem i faced in the initial thread

 

From last few days I am noticing strange problems in firefox

On each boot, when I open Mozilla Firefox, few tabs and windows (around 3-4) automatically gets open.
They contain the following addresshttps://photos-a.xx.fbcdn.net/hphotos-prn1/hellocdn.html?v=1 I have searched a bit and found out its a some kind of malware (AFAIK).
But i don't know the root cause of this problem and how eliminate it.
 
Any help to remove this malware is much appreciated
Screen shot of automatically opened tab:
https://ssl-proxy-updated.herokuapp.com/12398f1661869a07f3a41d5f151cef17fa83bd73/687474703a2f2f7332312e706f7374696d672e6f72672f717231666c7a6a7a622f73637265656e73686f745f3138382e706e67/
 
screenshot_188.png
Regards
Abhisheak

the solution (temporary) was :
 

 

Reset Firefox: https://support.mozilla.org/en-US/kb/reset-firefox-easily-fix-most-problems

 

 

Now

This problem have again came back and it has only affected firefox

It seems that this only happens on each start up.
reseting the firefox everytime is not feasible
So guys please tell some other solution.

I think it is some kind of browser hijacker



#3 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,895 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:05:52 PM

Posted 17 October 2013 - 07:51 AM


Please download AdwCleaner by Xplode and save to your Desktop.
  • Double-click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • Click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
-- Note: The contents of the AdwCleaner log file may be confusing. Unless you see a program name that you recognize and know should not be removed, don't worry about it. If you see an entry you want to keep, return to AdwCleaner before cleaning...all detected items will be listed (and checked) in each tab. Click on each one and uncheck any items you want to keep (except you cannot uncheck Chrome and Firefox preferences lines).


Please download Junkware Removal Tool thisisujrt.gif and save it to your Desktop.
  • Close all open programs and shut down any protection/security software now to avoid potential conflicts.
  • Double-click on JRT.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log file named JRT.txt will automatically open and be saved to your Desktop.
  • Copy and paste the contents of JRT.txt in your next reply.

.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#4 buyer120

buyer120
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:22 AM

Posted 18 October 2013 - 03:45 AM

 

  • Copy and paste the contents of AdwCleaner logfile in your next reply.

 

# AdwCleaner v3.008 - Report created 18/10/2013 at 13:28:13
# Updated 17/10/2013 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
# Username : Abhisheak - OM
# Running from : C:\Users\Abhisheak\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\Users\Abhisheak\AppData\Local\apn
Folder Deleted : C:\Users\Abhisheak\AppData\Local\Babylon
Folder Deleted : C:\Users\VB\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Abhisheak\AppData\Roaming\Mozilla\Firefox\Profiles\72eeipsc.default-1379242431529\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
Folder Deleted : C:\Users\Abhisheak\AppData\Roaming\Mozilla\Firefox\Profiles\n9vdaxk7.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
Folder Deleted : C:\Users\VB\AppData\Roaming\Mozilla\Firefox\Profiles\kn2wudp7.default-1347442212704\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
Folder Deleted : C:\Program Files (x86)\Mozilla Firefox\Extensions\afurladvisor@anchorfree.com
File Deleted : C:\END
File Deleted : C:\Users\Abhisheak\AppData\Roaming\Mozilla\Firefox\Profiles\72eeipsc.default-1379242431529\searchplugins\search.xml

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\smartbar
Key Deleted : HKLM\Software\PIP
Key Deleted : [x64] HKLM\SOFTWARE\systweak

***** [ Browsers ] *****

-\\ Internet Explorer v10.0.9200.16537


-\\ Mozilla Firefox v24.0 (en-US)

[ File : C:\Users\Abhisheak\AppData\Roaming\Mozilla\Firefox\Profiles\72eeipsc.default-1379242431529\prefs.js ]

Line Deleted : user_pref("extensions.hide_caption.plus.look.tab_marginTop_delta", 0);
Line Deleted : user_pref("extensions.hide_caption.plus.look.tab_marginTop_delta_nomax", 0);

[ File : C:\Users\VB\AppData\Roaming\Mozilla\Firefox\Profiles\kn2wudp7.default-1347442212704\prefs.js ]


[ File : C:\Users\Ajay\AppData\Roaming\Mozilla\Firefox\Profiles\qeh0kyrr.default\prefs.js ]


-\\ Google Chrome v

[ File : C:\Users\Abhisheak\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [3738 octets] - [18/10/2013 13:24:58]
AdwCleaner[S0].txt - [3639 octets] - [18/10/2013 13:28:13]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3699 octets] ##########
 

 

 

 

  • Copy and paste the contents of JRT.txt in your next reply.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.7 (10.15.2013:3)
OS: Windows 7 Ultimate x64
Ran by Abhisheak on Fri 10/18/2013 at 13:32:56.06
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services

Failed to stop: [Service] hshld
Successfully stopped: [Service] hsstrayservice
Successfully deleted: [Service] hsstrayservice
Successfully stopped: [Service] hsswd
Successfully deleted: [Service] hsswd



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\anchorfree
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\hotspotshield
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\hotspotshield
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskNotify_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\AskNotify_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskNotify_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\AskNotify_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{16AEE7B0-C577-4C3D-9F96-82637138EAA9}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\hotspot shield"
Successfully deleted: [Folder] "C:\Users\Abhisheak\AppData\Roaming\hotspot shield"
Successfully deleted: [Folder] "C:\Program Files (x86)\coupons"
Successfully deleted: [Folder] "C:\Program Files (x86)\hotspot shield"



~~~ FireFox

Emptied folder: C:\Users\Abhisheak\AppData\Roaming\mozilla\firefox\profiles\72eeipsc.default-1379242431529\minidumps [13 files]



~~~ Chrome

Successfully deleted: [Folder] C:\Users\Abhisheak\appdata\local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Fri 10/18/2013 at 13:37:22.98
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 



#5 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,895 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:05:52 PM

Posted 18 October 2013 - 04:16 AM

Did that resolve the problem?
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#6 buyer120

buyer120
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:22 AM

Posted 18 October 2013 - 05:25 AM

Hi,
yes it resolved the problem.

 

 

Thanks



#7 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,895 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:05:52 PM

Posted 18 October 2013 - 05:58 AM

You're welcome.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users