Recommended Posts

Hey guys,

I downloaded some file from internet and executed it... (big mistake)

Now i am facing an annoying problem. When ever i open a .HTML file from my computer, the Firefox opens some sites itself (cam sites, ebook sites etc.) I scanned with Malwarebytes it didnt helped.

Another thing is that, this only happens with FireFox. I reset it, re-installed it, deleted my profile it didnt helped.

.HTML files open well in chrome and Internet Explorer.

I am using Windows 8, FireFox Nightly.

Please Help

Thank you.

Link to comment
https://www.neowin.net/forum/topic/1136422-some-virus-in-firefox-please-help/
Share on other sites

Try defaulting firefox.

http://support.mozilla.org/en-US/kb/reset-firefox-easily-fix-most-problems

(Scroll down to see instructions towards bottom of the page).

okay heres another thing i just found..

for example, if the file name is "This is My Page.html" and if i open it in firefox, 4 tabs will open and it will look for This, is, my, page as sites in each tab...

I checked hosts file, nothing there. how to check DNS/ DHCP setting?

thanks

do a windows key + R then type firefox /p and create a new profile and use that and see if your issues go away. If they do then just export your favorites and go back to firefox / p and nuke your old profile.

""This is My Page.html" and if i open it in firefox, 4 tabs will open and it will look for This, is, my, page as sites in each tab..."

So if your page was called one.html what happens

It opens up a second tab searching for site called one?

That doesn't sound like any sort of virus or malware - sounds like some sort of addon or something. Can you post a screen shot of this??

So when I open a html file in firefox it looks like this, only the 1 tab and address of the file I opened.. What does what your saying happen look like - post a screenshot!

post-14624-0-46787000-1360850256.png

If you downloaded a file and executed it, the problem is probably not with firefox, the problem is likely you have a virus

empty all temp folders, disable msconfig startup items, check registry run entries, reset IE, Run scans with > Spybot, Avast Boot time scan, malwarebytes, Hijack This

Also check the hosts file doesn't have a load of redirect entries

So i opened a file "Funny 3 Words.htm" and this is i got :

in tab 1: file:///D:/Zzz/Funny

tab 2: http://www.****.com/Funny

tab 3: http://3/

tab 4:http://words.htm/

it starts searching for the each words of the file name and then sometimes redirects.

some times one tab redirects to some specific site ebook site or cam site.

I ran scan with comodo 2013, bitdefender 2013, malwarebytes and they found nothing. I cleaned registry, checked startup, hosts files, all seem good.

Unfortunately i have no restore points. And this happens with only FireFox. There are NO addons installed and no extra plugins

There is a guide here for battling a redirect virus

http://malwaretips.c...redirect-virus/

You might want to scan for rootkits too if normal AVs / malware scanners can't find anything

I think Kaspersky has a rescue boot disk capable of finding rootkits

What was the file you downloaded and ran ?

Have you checked simple things like programs and features to see if there is some adware / spyware crap installed ?

Why would a virus do such a thing - makes NO sense.. Opening up sites that it wants, sure - opening sites to ads, ok..

But if you open a file and opens tabs with each word?? I highly doubt its redirecting anything, more like just seaching for the word or opening the domain what word matches up too. Sounds more like a bug with the file opening process to me.

So are you just clicking on these html files, or are you in firefox doing open file?

Why would a virus do such a thing - makes NO sense.. Opening up sites that it wants, sure - opening sites to ads, ok..

But if you open a file and opens tabs with each word?? I highly doubt its redirecting anything, more like just seaching for the word or opening the domain what word matches up too. Sounds more like a bug with the file opening process to me.

So are you just clicking on these html files, or are you in firefox doing open file?

I'm just going from OPs post saying: "When ever i open a .HTML file from my computer, the Firefox opens some sites itself (cam sites, ebook sites etc.)"

okay, i followed everything on this page: http://malwaretips.com/blogs/remove-browser-redirect-virus/

but no luck

Also, this only happens when i open .html outside of browser. If i open any html file from file menu of browser then it opens normally. If i double click on any .html file than it opens in an unusual way redirecting and searching for file name words..

okay, i followed everything on this page: http://malwaretips.c...redirect-virus/

but no luck

Also, this only happens when i open .html outside of browser. If i open any html file from file menu of browser then it opens normally. If i double click on any .html file than it opens in an unusual way redirecting and searching for file name words..

Have you gone to the HTML files properties via right click and made sure Firefox is set as the default program to open them ?

Does the same thing happen if you select IE as your default browser or right-click on the .html file and select IE? At least I would point to an OS issue vs. a Firefox one.

What OS are you running? Did you already post that? XP, Vista, 7, 8? Some other windows - linux?

If only happens when you click on it or use open with in explorer, then sure it could be something wrong in the way the file is passed to firefox.. I like the idea of the test of using different browser to open the file the same way. I assume you have done this already since you stated it doesn't happen with other browsers. So are you using open with, or just doubleclicking and its using firefox as default to open html files. What if you change the association of html files to different browser so that if you double click them its opened in IE or Chrome, Opera, etc. What happens then?

If we know what OS your using it will help us pinpoint where the issue might be.

curious what your HKEY_CLASSES_ROOT\FirefoxHTML\shell\open\command

is?

For example mine is

"C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "%1"

Do you happen to have maybe %2 %3 or something added to yours? Im going to edit mine to see if I can duplicate your issue. This is from a XP box btw.

okay, I tried making chrome and IE my default browsers, everything works normal in IE and Chrome. I changed associations and tried on both, chrome and IE, everything works normal.

then again associated or not, theres problem with firefox.

I am using Windows 8

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Apple and Tesla trade secrets reportedly exposed following a Tata Electronics cyberattack by Hamid Ganji Image via Depositphotos.com Tata Electronics has confirmed that it detected a cybersecurity incident in some of its systems. The Indian company is a manufacturing partner of both Apple and Tesla, and the incident may have exposed some trade secrets belonging to the two American companies. The World Leaks ransomware group is said to be behind the attack, and it has reportedly posted up to 200,000 files on the dark web, including component designs and specification documents related to Apple and Tesla products. Tata Electronics told Reuters that its response protocols were deployed immediately and that the “incident has had no impact on our operations across businesses, which remain unaffected.” The ransomware group reportedly sent a ransom demand to Tata Electronics, while Apple has launched an investigation into the incident. World Leaks claims it stole more than 200,000 files totaling over 630GB from Tata Electronics. Some database files on the ransomware group’s website are titled "com.apple.factorydata," which could refer to Apple’s iPhone production operations in India. Moreover, some documents reportedly contain material specifications and quality inspection standards for iPhone circuit board components. However, Apple is not the only affected company. A folder found in the World Leaks database is titled "NV36 Chargeport Controller - North America," which may refer to Tesla Model Y components. Additionally, other files in the database reportedly contain drawings related to Tesla’s Project Highland, the internal codename for the EV maker’s updated Model 3 sedan. To support the authenticity of the stolen files, World Leaks has published documents containing footers that read: "This document contains proprietary and confidential information of Apple Inc." and "information contained herein is deemed confidential, proprietary, and a trade secret of Tesla Inc." Cybersecurity researcher Rajshekhar Rajaharia told Reuters that the database also contains emails, event logs spanning several years, and passport copies of employees, including foreign nationals. Both Tesla and Apple have declined to comment on the scale of the incident.
    • Last time I used Pascal was in college about 40 yrs ago, programmed an inventory database for my exam.
    • If they don't sell enough of the 1st gen then there won't be a 2nd gen
    • Epic fail, should've added an eSata port on the back, also if the memory/NVME are soldered then they're hardly gonna sell any, first thing most people do with their Steamdeck is, or used to be, replacing the NVME with a 2TB one. At that price they should, possibly for the first time, offer an installments option, say 24 months, they may sell a lot if they do. I'm sure they would have no shortage of credit companies willing to partner.
  • Recent Achievements

    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
    • Rookie
      dorf went up a rank
      Rookie
    • First Post
      mike_rumble earned a badge
      First Post
    • Dedicated
      tuben earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      487
    2. 2
      +Edouard
      204
    3. 3
      PsYcHoKiLLa
      94
    4. 4
      Michael Scrip
      91
    5. 5
      neufuse
      71
  • Tell a friend

    Love Neowin? Tell a friend!