Recommended Posts

My start page (specified in Tools>options to blank) just started opening to a game page (juego.com). It ONLY happens on a FF restart. It is NOT a redirect when doing searches in google, ixquick, etc.

I DON'T have google or mozilla as my home page - just blank. That's still what shows in options. I'm wondering if it's a trojan or a rogue installed extension?

Looking at the extensions, I don't see any odd - even opening more recent ones up - AFAICT. But, using another instance of FF, using a diff profile - doesn't open the game page - just to a blank page.

Before I get into a full blown malware erradication effort, I wondered if anyone has seen this?

I ran MBAM - full scan - nothing. Ran KIS 2012 full scan, w/ deepest settings - nothing.

Ran DDS - don't see anything unusal, but I'm no expert.

Maybe someone's seen a more simple explanation for this, but if not, I'll have to start running more malware scanners / cleaners.

I could just del the prob profile, but that doesn't mean the "infection" hasn't spread to other parts.

Thanks.

Looks like a hosts file has been altered. Check your hosts file and see.

Or get hijackthis software and this program will tell you and fix it.

Someone else will come by here to give you alternative tips or software if any is better than hijackthis.

Thanks.

Redvamp128 - I have no toolbars & none show up in HJT. What's odd is I have cache set to clear everytime FF shuts down. So, considering after seeing the rogue startup page, I restarted FF couple times - but still same page. Then after an update to some addon installed - would have to check date for which one - my startup page is back to blank. May be pure coincidence.

I'm positive the 1st time I started up FF & the odd page appeared, I closed FF normally & that would've cleared the cache. But seems to have taken closing / restarting it a few times before going back to blank start page??? Any idea why?

Shozilla - Already ran HJT. showed the host file. I checked - there's nothing odd in the host file. Just the 127.0.0.1

Still, I'd like to know how it happened & given that I've already run some scanners, if there's much chance an infection of some sort will "reappear." Of course, if it was a truly malicious infection (if that start page was only prob), it wouldn't have given itself away so obviously.

You could if you know the page-- just turn that site into the restricted site list.. then set it to your home page-- see what happens...

The other option I would see is -- check to see if the syncronize option is enabled... and disable it... -- alternatively you could uninstall-- firefox....then search the %temp% and delete the mozilla folder...

then reinstal and start from scratch--

Also--

Does IE go to the same site??? that way you can tell if it is just a FF problem or not-- or an infection--

in URL type: about:config and press Enter.

click on I'll be careful, i promise!

Now in the search, start typing the name of the site that opens (like write juego in search)

now if you see any entries matching the site name, right click on them and delete (if available)

restart and check!!!

The last 2 posts show having an earlier time than my last??? Anyway, obviously from my comments, it was related (at least) to only some (definitely not ALL) of my FF profiles, so starting IE you'd expect the problem wouldn't exist. It didn't.

No, didn't see anything in about:config - that's one of 1st places I looked.

Somehow, it must have been a page stored in MEMORY cache that was doing this, because disk cache is cleared each time FF is closed.

I think I rebooted at some point & maybe that's when the prob stopped. I did scans w/ several apps before going back online & never found anything. Since then, it hasn't returned.

I'm not exactly sure how w/ today's browsers, a malicious / advertising page in disk or memory cache can hijack your home page at startup, but not make any apparent changes in your browser settings or even add a registry change? Is it simply a script that keeps running over & over everytime the browser is restarted, until the script is removed? (Appears this case, it may have been stored in memory, but not sure).

I somehow got the hijacked start up home page to go away, but not sure how. Clearing cache (main & little startup), shutting down box to clear RAM - bunch of stuff.

Mysteriously went away, then about 1 - 2 wks later came back.

This time just created new profile - didn't copy over any extensions at 1st. That was OK, so then copied the Extensions folder & other "usual" files to transfer to new profile, but not prefs.js. So far, the home page is OK. This was much faster than all the hunting & scanning I did before, unless I'd found something sitting in prefs.js file. I still never found anything, anywhere that hinted at the w-w-w dot blank dot com, which apparently then served up ad sites or others. It was well hidden.

This topic is now closed to further replies.
  • Posts

    • But the reality is it will work for people's needs, and they don't care about the technology that makes it. Clearly not everyone's needs, but that low end space where personal laptops were only used to type emails, watch content and browse websites, but they didn't want to do that on a small screen device. Heck, writing that out I can now see the connection and reason it'll do so well. Apple is about experience. If the experience is bad, they don't release it. Low end Windows laptop manufacturers up until this point have not taken that into consideration ever before, so slow laggy usage with brittle slimey plastic shells were common. I hope that the low end space at least creates better physical products that last a bit longer, and if Microsoft get their act together, they could also have a solid OS on such low end hardware that would actually make the experience work for what the hardware was intended for. The fact that the CPU is a "cellphone", sorry mobile phone processor is irrelevant. It's about the experience, and so far, that sounds quite solid.
    • Hello, Bonjour is Apple's implementation of a multicast-DNS service, which allows devices running Apple's software and/or hardware to find each other on your local network.  I believe the Windows version was last updated around 2010. If you do not need it, you can stop and disable the Bonjour service in the Services Control Manager (filename: SERVICES.MSC).  Once you have done that, the operating system will no longer attempt to load the service. Regards, Aryeh Goretsky  
    • This AMD RX 9070 16GB GPU that performs close to Nvidia 5070 is under $600 by Sayan Sen With the memory shortage that's prevalent nowadays, discounts are super-hard to get. As such we post good deals whenever they pop up. Recently, we covered a few great discounts on SSDs wherein you can get a 4TB TeamGroup NVMe PCIe Gen4 drive for just $400 thanks to a special coupon. If you want a faster product but don't need all that capacity, you can also opt for Samsung's 990 PRO 2TB that is on sale for its lowest price in over three months. Let's say though that you are on the hunt for a 1440p gaming card. In that case AMD's RX 9070 non-XT can help, and with its 16GB VRAM, you can also run AI models locally without worrying about bottlenecking (check out our recent 9070 GRE reviews for gaming and productivity to get an idea). The PowerColor Reaper variant of the RX 9070 is currently on sale for just $580 which is a very good price in the current state of affairs (purchase link under the specs table down below). The Reaper cooler on this 9070 uses a triple‑fan design with ring‑blade fans, paired with premium dual ball bearings to extend lifespan and reduce friction. "Intelligent" fan control allows the fans to remain idle at lower temperatures, only spinning up when the GPU is under load. A nickel‑plated copper base makes direct contact with both the GPU and memory modules, helping to spread heat evenly. PowerColor also applies Honeywell PTM7950 phase‑change thermal interface material (TIM), which fills microscopic gaps between the die and heatsink for more efficient thermal transfer. The fan shroud is shorter in height as the firm has made it such that it can be used in certain SFF (small form factor) cases. The technical specifications of the Reaper RX 9070 are given in the table below: Specification Value Stream Processors 3584 Units Video Memory 16GB GDDR6 Memory Speed 20.0 Gbps Memory Interface 256-bit Engine Clock Game Clock: up to 2070 MHz Boost Clock: up to 2520 MHz Bus Standard PCI Express 5.0 x16 Display Connectors 1 x HDMI 2.1b, 3 x DisplayPort 2.1a Maximum Resolution DisplayPort: 7680 × 4320 HDMI: 7680 × 4320 Board Dimensions 289mm × 111mm × 41mm 304mm × 127mm × 42mm (with bracket) Slot 2 Minimum System Power Requirement 600W Power Connectors Two 8-pin PCI Express Get the PowerColor Reaper RX 9070 at the links below (you get only a 90-day warranty on Woot): PowerColor Reaper Radeon RX 9070 16GB Graphics Card (RX9070 16G-A): $579.99 (Sold and Shipped by Amazon US) (Was: $700) PowerColor Reaper Radeon RX 9070 16GB Graphics Card (RX9070 16G-A): $559.99 (Sold and Shipped by Woot US) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • Are they marketed as an entry into astronomy or astrophotography? I do astrophotography. With big rigs, lots of computers, cables and headaches. I love it. And by learning this ridiculously complex hobby, I’ve learned about the objects I’m shooting. Astronomy followed from photography.
    • Microsoft confirms Recycle Bin bug across all versions of Windows by Usama Jawad A couple of days ago, we reported that the latest Patch Tuesday update has seemingly resulted in a lot of issues for many users, including OneDrive and Dropbox access problems, BitLocker recovery lockouts, and BSODs. Although Microsoft is yet to acknowledge these bugs, it has confirmed another, relatively smaller issue across all supported versions of Windows. In an update on its Windows Release Health Dashboard, Microsoft has confirmed that after installing June's Patch Tuesday update (KB5094126), you'll experience unexpected behavior when leveraging Recycle Bin. Basically, when you attempt to delete an item from the Recycle Bin, the confirm dialog will show you the internal file name of that content rather than the actual name. For example, the file may be named abc.png, but the confirm dialog will ask if you're sure that you want to permanently delete $Rxxxxx.png from the Recycle Bin. This is pretty much it for the scope of the bug itself; it just displays the wrong name in the confirm dialog. The correct name will be shown in the list view of the Recycle Bin and if you restore the file, it will return with the correct name as well. This issue affects pretty much all supported versions of Windows client and server, including: Client: Windows 11, version 26H1; Windows 11, version 25H2; Windows 11, version 24H2; Windows 11, version 23H2; Windows 10, version 22H2; Windows 10 Enterprise LTSC 2021; Windows 10 Enterprise LTSC 2019; Windows 10 Enterprise LTSB 2016 Server: Windows Server 2025; Windows Server 2022; Windows Server 2019; Windows Server 2016; Windows Server 2012 R2; Windows Server 2012 As things currently stand, Microsoft is working on a concrete solution that will be released in a "future" Windows update. It remains to be seen if the firm will wait till the next Patch Tuesday or roll out an out-of-band (OOB) fix. The good news is that commercial customers can deploy a workaround right now, but they will have to reach out to Microsoft Support for Business for additional details.
  • Recent Achievements

    • Week One Done
      Jordan Smith earned a badge
      Week One Done
    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      579
    2. 2
      +Edouard
      184
    3. 3
      PsYcHoKiLLa
      75
    4. 4
      Michael Scrip
      72
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!