Odd Message Boxes in Firefox 7.0.1

Hey all,

I’ve been getting weird message boxes popping up in Firefox 7.0.1. I’ll be browsing normal websites (Facebook, email, school website)and Firefox will freeze. After unfreezing, a message box will pop up with no text in the box or on the two choices. This has happened about 4-5 times in the past couple days, so I’m running a scan with the free Avast! antivirus. I’m also probably going to run a Malwarebyte’s scan as soon as that finishes. In the mean time, does anyone recognize this as a virus of some sort, or think it could be a virus? Thanks a lot.

-C.D.

You are right to be suspicious. I’ve seen that on infected systems before (strange blank pop-up windows, freezing).

Its nothing conclusive, but certainly enough reason to start double-checking (as you are already doing).

Hi CountDracula,

The way to start is do a full scan with avast of your users file to be found on Computer - So Computer → comp name C: → Users
If the browser was terminated not properly it could lead to such a message…
Else we have to contact essexboy to have a more firm look at things,

polonus

Just to be on the safe side

Download aswMBR.exe ( 1.8mb ) to your desktop.
Double click the aswMBR.exe to run it Click the “Scan” button to start scan

http://i1224.photobucket.com/albums/ee362/Essexboy3/aswMBR%20shots/aswMBRScan.gif

On completion of the scan click save log, save it to your desktop and post in your next reply

http://i1224.photobucket.com/albums/ee362/Essexboy3/aswMBR%20shots/aswMBRsavelog.gif

THEN

Download OTL to your Desktop

[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
[*]Select All Users
[*]Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%*.exe
/md5start
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
C:\Windows\assembly\tmp\U*.* /s
CREATERESTOREPOINT

[*]Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
[*]Attach both logs

Thanks for the help so far. And for what it’s worth, I’m running Windows 7. Resuming my regular Avast scan.

-C.D.

Nothing really jumps out at me there so lets use a dedicated firefox tool. Your MBR is still reporting Vista

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTL O3 - HKU\S-1-5-21-391789883-3755849557-3817460217-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.

:Files
ipconfig /flushdns /c

:Commands
[purity]
[resethosts]
[emptytemp]
[EMPTYFLASH]
[CREATERESTOREPOINT]
[Reboot]


[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Is it only firefox ?

Please download GooredFix from one of the locations below and save it to your Desktop

Download Mirror #1
Download Mirror #2

[*]Ensure all Firefox windows are closed.
[*]To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
[*]When prompted to run the scan, click Yes.
[*]GooredFix will check for infections, and then a log will appear.

Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).

Any reason my MBR would report Vista? This computer was purchased directly from Dell with Windows 7 on it. Is it safe to use the scans you linked on a Windows 7 machine? (System properties show Windows 7 as my OS.) Thanks.

-C.D.

Yes it is not a problem I was just curious - is this an upgrade from Vista to 7 ?

Ta, essexboy, for the extra check here. Think it is a browser profile issue then?
Or what is your nearest guess?

polonus

If it was an upgrade from Vista to Windows 7, I wouldn’t be aware of it. Dell advertised it as a machine with Windows 7 on it. It seems to affect only Firefox though. Opera seemed to hang slightly, but never had the pop-up box issue.

Did a boot-time scan and eliminated a few suspicious files.

  1. Had about 4-5 instances of Java:CVE:2010-0842-B[EXPL]
  2. Had two instances of Java:Agent-DC[TRJ]

Following is the log for GooredFix.

GooredFix by jpshortstuff (03.07.10.1) Log created at 23:32 on 27/10/2011 (Andrew) Firefox version 7.0.1 (en-US)

========== GooredScan ==========

(none)

========== GooredLog ==========

C:\Program Files (x86)\Mozilla Firefox\extensions
{972ce4c6-7e08-4474-a285-3208198ce6fd} [05:39 03/02/2011]
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [00:49 10/05/2011]

C:\Users\Andrew\Application Data\Mozilla\Firefox\Profiles\tila8aaz.default\extensions
(none)

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
wrc@avast.com”=“C:\Program Files\Alwil Software\Avast5\WebRep\FF” [23:08 29/04/2011]

-=E.O.F=-

I’ll run these new diagnostics though. Could be something floating around the boot-time scan didn’t catch. Thanks.

-C.D.

I wonder whether Dell just upgraded a Vista machine and then sold it as Windows 7

OTL also cleared the Java cache which is probably where it was coming from. Has it ceased now or is it still happening

The issue hasn’t happened since I did my boot scan. I suspect I got rid of the virus causing the problems.

Dell doing that wouldn’t surprise me. Thanks so much for helping me out guys.

-C.D.

The odd message boxes started showing up again after a few days. An Avast scan didn’t show anything. Is there anything else I can do?

-C.D.

Could you clear your Java cache again to see if that clears it

Cleared my Java Cache. Also, I noticed after some experimentation that as long as I don’t have Facebook open, the message box wouldn’t pop up. Once the box started popping up though, it would come back with increasing frequency. (From once an hour to about once every two minutes.)

-C.D.

Definitely facebook related then. But, it does not appear to add an extension - do you have no script installed ?

I do not have No Script installed. I’m assuming installing it would be a good idea.

-C.D.

Yep I do not use FF myself so I am not sure how you customise it But, here it is http://noscript.net/

exact same problem here! firefox 7.0.1, avast free 6.0.1289, virus definitions 111103-0. happens when in facebook too and I do not have noScript installed too. A two-buttoned messagebox appears, with no text in it, i close it from the x button and it keeps coming up after some time. It does not have a standard trigger function I do that brings it up.

Install Noscript and see if that works