Recommended Posts

My start page (specified in Tools>options to blank) just started opening to a game page (juego.com). It ONLY happens on a FF restart. It is NOT a redirect when doing searches in google, ixquick, etc.

I DON'T have google or mozilla as my home page - just blank. That's still what shows in options. I'm wondering if it's a trojan or a rogue installed extension?

Looking at the extensions, I don't see any odd - even opening more recent ones up - AFAICT. But, using another instance of FF, using a diff profile - doesn't open the game page - just to a blank page.

Before I get into a full blown malware erradication effort, I wondered if anyone has seen this?

I ran MBAM - full scan - nothing. Ran KIS 2012 full scan, w/ deepest settings - nothing.

Ran DDS - don't see anything unusal, but I'm no expert.

Maybe someone's seen a more simple explanation for this, but if not, I'll have to start running more malware scanners / cleaners.

I could just del the prob profile, but that doesn't mean the "infection" hasn't spread to other parts.

Thanks.

Looks like a hosts file has been altered. Check your hosts file and see.

Or get hijackthis software and this program will tell you and fix it.

Someone else will come by here to give you alternative tips or software if any is better than hijackthis.

Thanks.

Redvamp128 - I have no toolbars & none show up in HJT. What's odd is I have cache set to clear everytime FF shuts down. So, considering after seeing the rogue startup page, I restarted FF couple times - but still same page. Then after an update to some addon installed - would have to check date for which one - my startup page is back to blank. May be pure coincidence.

I'm positive the 1st time I started up FF & the odd page appeared, I closed FF normally & that would've cleared the cache. But seems to have taken closing / restarting it a few times before going back to blank start page??? Any idea why?

Shozilla - Already ran HJT. showed the host file. I checked - there's nothing odd in the host file. Just the 127.0.0.1

Still, I'd like to know how it happened & given that I've already run some scanners, if there's much chance an infection of some sort will "reappear." Of course, if it was a truly malicious infection (if that start page was only prob), it wouldn't have given itself away so obviously.

You could if you know the page-- just turn that site into the restricted site list.. then set it to your home page-- see what happens...

The other option I would see is -- check to see if the syncronize option is enabled... and disable it... -- alternatively you could uninstall-- firefox....then search the %temp% and delete the mozilla folder...

then reinstal and start from scratch--

Also--

Does IE go to the same site??? that way you can tell if it is just a FF problem or not-- or an infection--

in URL type: about:config and press Enter.

click on I'll be careful, i promise!

Now in the search, start typing the name of the site that opens (like write juego in search)

now if you see any entries matching the site name, right click on them and delete (if available)

restart and check!!!

The last 2 posts show having an earlier time than my last??? Anyway, obviously from my comments, it was related (at least) to only some (definitely not ALL) of my FF profiles, so starting IE you'd expect the problem wouldn't exist. It didn't.

No, didn't see anything in about:config - that's one of 1st places I looked.

Somehow, it must have been a page stored in MEMORY cache that was doing this, because disk cache is cleared each time FF is closed.

I think I rebooted at some point & maybe that's when the prob stopped. I did scans w/ several apps before going back online & never found anything. Since then, it hasn't returned.

I'm not exactly sure how w/ today's browsers, a malicious / advertising page in disk or memory cache can hijack your home page at startup, but not make any apparent changes in your browser settings or even add a registry change? Is it simply a script that keeps running over & over everytime the browser is restarted, until the script is removed? (Appears this case, it may have been stored in memory, but not sure).

I somehow got the hijacked start up home page to go away, but not sure how. Clearing cache (main & little startup), shutting down box to clear RAM - bunch of stuff.

Mysteriously went away, then about 1 - 2 wks later came back.

This time just created new profile - didn't copy over any extensions at 1st. That was OK, so then copied the Extensions folder & other "usual" files to transfer to new profile, but not prefs.js. So far, the home page is OK. This was much faster than all the hunting & scanning I did before, unless I'd found something sitting in prefs.js file. I still never found anything, anywhere that hinted at the w-w-w dot blank dot com, which apparently then served up ad sites or others. It was well hidden.

This topic is now closed to further replies.
  • Posts

    • Get 1-year and $60 of Sam's Club value for just $15 with Auto-renew by Steven Parker Become a Sam's Club Member Now! Shop Premium-Quality Products and Enjoy Incredible Perks, and Savings. Today's highlighted deal comes via our Gift Cards section of the Neowin Deals store, where for only a limited time, you can save 75% off a Sam's Club 1 Year Membership with Auto-Renew. Sam’s Club is a membership warehouse club, a limited-item business model that offers members quality products at an exceptional value unmatched by traditional retail. From groceries and kitchen supplies to electronics and furniture, Sam's Club has great deals on the items you want! By redeeming and signing up as a member, you'll be paying just $20 for a 1 year Sam's Club membership (normally $50.) You'll receive a complimentary household card for more savings from already low-priced items. Sign up now and save money on all your food and decor. Find great deals on groceries, kitchen supplies, electronic, furniture & more Get discounts on hotels, rental car, live events, attractions, movies, & more Save up to 60% on hotel accommodations around the world Get a complimentary household card for more savings from already low-priced items Although it was published quite some time ago, Sam's Club members can enjoy discounts like this. Important Details For a physical membership card after online membership registration, present your phone number or email along with a valid ID at Sam’s Club Membership Services in any US Sam's Club location to have your membership card printed. This membership offer is only available to new Sam's Club members in the USA. It is not valid for membership renewals, for those with a current membership, or those who were Sam’s Club members less than 6 months prior to the current date. To check your renewal date, please check your billing statement or your online account, or chat with an associate. Promotion code is non-transferable Offer valid for new Sam’s Club members only; not valid for membership renewals, for those with a current membership, or those who were Sam’s Club members less than 6 months prior to the current date. Auto Renew: By accepting this offer, you authorize annual recurring charges to any card on file for your Sam's Club membership fee(s) plus any applicable taxes at then-current rate every year until you cancel. Current rates, which may change, are $50 for Club level and $110 for Plus level. Visit SamsClub.com or a club or call 1-888-746-7726 for full terms or to cancel auto-renewal. Valid at over 597 U.S. Sam’s Club locations. Find a location near you. Redemption deadline: redeem your code within 30 days of purchase Access options: desktop & mobile Membership MUST be activated within 30 days Membership expires 1 YEAR from the date the Sam's Club membership is activated Limit 1 per person, may buy 1 additional as gift This Sam's Club 1 Year Membership normally costs $60, but can now be yours for just $15, for a limited time, that's a saving of $45 (70%) off! For specifications, and terms, please click the link below. Get 1-year of Sam's Club with Auto-renew for just $15 (was $60) This deal is only available to U.S. residents. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • Microsoft, why can't I just turn off Copilot on my MS account (in order to stop OneDrive from wanting to summarize everything, ahem) in a way that doesn't break OneNote instead?
    • If we can't agree on a baseline of reality then there is no point in talking. Its a waste of time.
  • Recent Achievements

    • Collaborator
      ryansurfer98 went up a rank
      Collaborator
    • Week One Done
      Eurosoft10 earned a badge
      Week One Done
    • One Month Later
      Eurosoft10 earned a badge
      One Month Later
    • One Year In
      Skeet Campbell earned a badge
      One Year In
    • One Month Later
      Sharbel earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      589
    2. 2
      +Edouard
      190
    3. 3
      PsYcHoKiLLa
      80
    4. 4
      Michael Scrip
      77
    5. 5
      Steven P.
      73
  • Tell a friend

    Love Neowin? Tell a friend!