Momoxxio

Hi has anyone come across something called momoxxio. on firefox every time i move my mouse to the right to scroll down it starts to connect to this and i’ve read on yahoo answers about subscriptions and phone bills, how can i get rid of what looks like a vicious stalker type bug or virus, no idea how i got ‘piggybacked’ onto it
Am running an avast scan at the moment so far nothing has come up.

Running in google chrome at moment so far no sign of it

Thanks for any answers!

Looks like it might be an add-on in firefox if that’s the only browser that is affected.

Check this page to see how to remove add-ons.
http://support.mozilla.org/en-US/kb/disable-or-remove-add-ons

Also try a Malwarebytes scan to see if anything malicious is found.
http://www.malwarebytes.org/

Hi hawick

According to WOT web rep Momoxxio is envolved in phishing and scamming: http://www.mywot.com/en/scorecard/momoxxio.com?utm_source=addon&utm_content=popup-donuts
Victims like you should do this quizz here: http://www.quizplz.com/fraud.htm

polonus

Thanks guys, the link ends up with an i-phone5 advert. nothing on the avast scan still running the malwarebytes (thanks for that one).
I tried add-ons via tools, but unless it has ‘attached itself’ to something else like java adobe etc there’s no obvious sign of it in there.

Don’t think am out of the woods yet, but still using chrome. pretty sure it’s as you suggest polonus nasty

If anyone has other suggestions would still be appreciated.

still running the malwarebytes
quick scan is enough....

also run AdwCleaner…and click the delete button…a special tool for browser/toolbar crap http://forum.avast.com/index.php?topic=53253.0
Post the log here…

if still problems a removal expert will help you…

hi again, you guys are superb, this is my log, is it likely the trojan was the problem? Thanks again. Have switched on auto updates.

Registry Data Items Detected: 3
HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) → Bad: (1) Good: (0) → Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) → Bad: (1) Good: (0) → Quarantined and repaired successfully.
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) → Bad: (1) Good: (0) → Quarantined and repaired successfully.

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
C:\WINDOWS\Temp\Keymaker.exe (Trojan.Downloader) → Quarantined and deleted successfully.
C:\WINDOWS\Temp\everest.exe (Trojan.Agent) → Quarantined and deleted successfully.