Weird Firefox behaviour makes me think I have a virus

A couple of months ago I was using my computer from my administrator account and a program asked for permission to do something and I granted it permission and immediately had the intuitive feeling that I’d done the wrong thing. When I went back to using my standard account clicking on my Firefox toolbar icon said that the program this shortcut was connected to was missing. It was as if Firefox was uninstalled (I tried various ways of launching it) but it was still listed in my programs in the control panel. I started using Chrome from my standard account. It also did this with a program called Trillian, which is a messaging program which combines all the various messaging formats into one program.

When I used my administrator account again (which I was trying to avoid since something seemed to be wrong) Firefox worked but it was full of advertising. That is, there were ad’s in the browser itself. I ran an Avast scan which didn’t find anything, then I ran an Avast boot time scan which still didn’t find anything. I tried uninstalling and reinstalling Firefox, which didn’t work. I’ve left it uninstalled at present. I’ve kept Avast up to date and my OS up to date (which is Windows 7) and tried another boot time scan recently which found nothing.

I haven’t been acting on getting it fixed urgently as I was planning on getting a Mac Mini anyway (which I have now bought). All’s I’ve really done is avoid doing any internet banking since this occurred. Even though I’m going Mac it would be good to get this sorted, what-ever it is might transfer when I transfer my files to the Mac and live on, even if it can’t affect the Mac. I’ve now downloaded and run Malwarebytes Anti-Malware, OTL and aswMBR and have attached their logs.

hey and welcome to the forum. thanks for attaching the needed logs. I’m gonna notify a expert on your case.

your Malwarebytes log say “NO ACTION TAKEN”
update malwarebytes, run new quick scan…make sure evrything detected is marked for removal and click REMOVE SELECTED button

attach new log

Be careful, some viruses now are for windows,mac.and linux together. Also you should have a antivirus cause there is some java malware for macs out and also it can prevent you from phishing websites.

Hi Snoopyjoe,
First follow Pondus advice for removing detected objects via Malwarebytes.

Then …


Zoek’s Fix


Please download zoek.zip or zoek.rar by smeenk (
http://www.mcshield.net/personal/magna86/Images/Zoek_icon.png
) from here or here and save it to your Desktop.
Unpack the archive…

[*]Close any open browsers
[*] Temporarily disable your AntiVirus program. (If necessary)
If you are unsure how to do this please read this or this Instruction.

[*]Double click on zoek.exe to run the tool .
Please wait while the tool does not start…

[*]Copy the text present inside the code box below and paste it into the large window in the zoek tool:

Uninstall-List;
EmptyFoldersCheck;Delete
EmptyCLSID;
FFDefaults;
CHRDefaults;
AutoClean;

[*] Click on
http://www.mcshield.net/personal/magna86/Images/Run%20Script%20by%20zoek.png
button.
Please wait until a logreport will open (this can be after reboot)

[*]Save notepad to your Desktop and attach here zoek-results.log
Note: It will also create a log in the C:\ directory named “zoek-results.log


Re-check …


Re-run OTL, just hit the QuickScan button and post here fresh OTL.txt logreprot.

A big thank you to all those people who have been replying and helping me.

Malwarebytes update button is greyed out, I presume that’s because it is up to date? I didn’t realise I hadn’t selected the malware it found in the first scan when I clicked ‘remove.’ Ran Malwarebytes again, Zoek and OTL again and have attached the logs.

Malwarebytes update button is greyed out
you are running that malwarebytes with limited rights (not admin rights).

couple weeks ago when i tried run malwarebytes without admin rights i could not acces its settings or update database, update button was gray.

Hi Snoopyjoe,

Zoek has been clean up a lots of junk …

  1. Delete the current copy of zoek and download new, fresh copy of zoek…exe.

  2. Re-run new zoek as you did before…

[*]Copy the text present inside the code box below and paste it into the large window in the zoek tool:

C:\Program Files (x86)\CE\CovenantEyes.exe;i
IEDefaults;
news@news.net.xpi;FF
C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA};F
C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1};F
C:\USERS\MASTER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\XYCJKG6Z.DEFAULT\EXTENSIONS\TOOLBAR@ASK.COM;F
cmbbgcooaabknohabmoaikiakkoignai;CHR
{BA3E58F7-60C6-485E-A775-0C1FD9C0E55E};C
C:\Program Files\News.net;FS
EmptyAllTemp;
AutoClean;

[*] Click on
http://www.mcshield.net/personal/magna86/Images/Run%20Script%20by%20zoek.png
button.
Please wait until a logreport will open (this can be after reboot)

[*]Save notepad to your Desktop and attach here zoek-results.log
Note: It will also create a log in the C:\ directory named “zoek-results.log

OK I downloaded a fresh copy of Zoek.exe from http://home.kpn.nl/stefsmeenk/zoek.exe, ran it with the script from magna86 and attached the results, and I ran Malwarebytes from my administrator account, updated it and ran a quick scan and attached the results.

Snoopyjoe, looks good. Tell me, how the things are now?

Everything’s back to normal. I’m writing this from Firefox and Trillian is back as well. Thanks again to everyone that has helped.

Cool. 8)
The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
[i]
http://www.mcshield.net/personal/magna86/Images/checkmark.png
Remove disinfection tools

http://www.mcshield.net/personal/magna86/Images/checkmark.png
Create registry backup

http://www.mcshield.net/personal/magna86/Images/checkmark.png
Purge System Restore [/i]
Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:[b]DelFix.txt[/b])

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.