Closed Bug 629750 Opened 9 years ago Closed 9 years ago

A hijacker keeps directing me to above URL

Categories

(Firefox :: General, defect, critical)

3.6 Branch
x86
Windows XP
defect
Not set
critical

Tracking

()

RESOLVED INCOMPLETE

People

(Reporter: bippeeii, Unassigned)

References

(Blocks 1 open bug, )

Details

User-Agent:       Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13 (.NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.04506.648; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.13) Gecko/20101203 Firefox/3.6.13 (.NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.04506.648; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)

Browser hijack sends me to http://premium_.s3.amazonaws.com/index.html?AWSAccessKeyId=AKIAIKDZBVZT6ABSN6MA&Expires=1296243901&Signature=de0qFPwu4mLkJhXy6N6BQo8ZGSs%3D

First time out it actually showed up on weather.com   If you click on it, worm starts tunneling into computer.  Worm removed by Malwarebytes, but does not get the hijaccker.  Tried uninstaling Mozilla but left preferences & passwords.  After relaod hijacker still there.

Reproducible: Sometimes

Steps to Reproduce:
1. Open browser
2.  Sign in to aol 
3.  start a search
Actual Results:  
click on a search for Gilgamesh using Yahoo, redirected to URL above
My trouble shooting info.

  Application Basics

        Name
        Firefox

        Version
        3.6.13

        Profile Directory

          Open Containing Folder

        Installed Plugins

          about:plugins

        Build Configuration

          about:buildconfig

  Extensions

        Name

        Version

        Enabled

        ID

        Flashblock
        1.5.14.2
        true
        {3d7eb24f-2740-49df-8937-200b1cc08f8a}

        HP Smart Web Printing
        4.60
        false
        smartwebprinting@hp.com

        Hyperwords
        6.5.4
        true
        {9A752782-D706-479b-98F8-3F66BF921692}

        Java Console
        6.0.12
        true
        {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}

        Java Console
        6.0.13
        true
        {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

        Java Quick Starter
        1.0
        true
        jqs@sun.com

        LinkedIn Companion for Firefox
        3.3.1
        true
        {e2337727-f9c9-411b-929e-287584341d1a}

        Microsoft .NET Framework Assistant
        1.2.1
        true
        {20a82645-c095-46ed-80e3-08825760534b}

        Microsoft Choice Guard
        1.2
        false
        ChoiceGuard@Microsoft

        PDF Download
        3.0.0.1
        true
        {37E4D8EA-8BDA-4831-8EA1-89053939A250}

        Move Media Player
        7
        true
        moveplayer@movenetworks.com

        XULRunner
        1.9.1
        true
        {A6821A6A-0587-40DA-BB03-0AF0404F5C8B}

  Modified Preferences

      Name

      Value

        accessibility.blockautorefresh
        true

        accessibility.typeaheadfind.casesensitive
        1

        accessibility.typeaheadfind.flashBar
        0

        browser.history_expire_days
        2

        browser.history_expire_days.mirror
        2

        browser.history_expire_days_min
        1

        browser.places.importBookmarksHTML
        false

        browser.places.importDefaults
        false

        browser.places.leftPaneFolderId
        -1

        browser.places.migratePostDataAnnotations
        false

        browser.places.smartBookmarksVersion
        2

        browser.places.updateRecentTagsUri
        false

        browser.startup.homepage
        http://www.aol.com/

        browser.startup.homepage_override.mstone
        rv:1.9.2.13

        browser.zoom.full
        false

        dom.disable_open_during_load
        false

        extensions.lastAppVersion
        3.6.13

        font.name.serif.x-western
        Univers

        font.size.variable.x-western
        14

        general.useragent.extra.microsoftdotnet
        (.NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.04506.648; .NET CLR 3.0.4506.2152; .NET CLR …

        keyword.URL
        http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=135963&p=

        network.cookie.lifetimePolicy
        2

        network.cookie.prefsMigrated
        true

        network.protocol-handler.warn-external.dnupdate
        false

        places.last_vacuum
        1294677779

        print.print_printer
        Adobe PDF

        print.printer_Adobe_PDF.print_bgcolor
        false

        print.printer_Adobe_PDF.print_bgimages
        false

        print.printer_Adobe_PDF.print_command

        print.printer_Adobe_PDF.print_downloadfonts
        false

        print.printer_Adobe_PDF.print_edge_bottom
        0

        print.printer_Adobe_PDF.print_edge_left
        0

        print.printer_Adobe_PDF.print_edge_right
        0

        print.printer_Adobe_PDF.print_edge_top
        0

        print.printer_Adobe_PDF.print_evenpages
        true

        print.printer_Adobe_PDF.print_footercenter

        print.printer_Adobe_PDF.print_footerleft
        &PT

        print.printer_Adobe_PDF.print_footerright
        &D

        print.printer_Adobe_PDF.print_headercenter

        print.printer_Adobe_PDF.print_headerleft
        &T

        print.printer_Adobe_PDF.print_headerright
        &U

        print.printer_Adobe_PDF.print_in_color
        true

        print.printer_Adobe_PDF.print_margin_bottom
        0.5

        print.printer_Adobe_PDF.print_margin_left
        0.5

        print.printer_Adobe_PDF.print_margin_right
        0.5

        print.printer_Adobe_PDF.print_margin_top
        0.5

        print.printer_Adobe_PDF.print_oddpages
        true

        print.printer_Adobe_PDF.print_orientation
        0

        print.printer_Adobe_PDF.print_pagedelay
        500

        print.printer_Adobe_PDF.print_paper_data
        1

        print.printer_Adobe_PDF.print_paper_height
        11.00

        print.printer_Adobe_PDF.print_paper_size
        0

        print.printer_Adobe_PDF.print_paper_size_type
        0

        print.printer_Adobe_PDF.print_paper_size_unit
        0

        print.printer_Adobe_PDF.print_paper_width
        8.50

        print.printer_Adobe_PDF.print_reversed
        false

        print.printer_Adobe_PDF.print_scaling
        1.00

        print.printer_Adobe_PDF.print_shrink_to_fit
        true

        print.printer_Adobe_PDF.print_to_file
        false

        print.printer_Adobe_PDF.print_unwriteable_margin_bottom
        0

        print.printer_Adobe_PDF.print_unwriteable_margin_left
        0

        print.printer_Adobe_PDF.print_unwriteable_margin_right
        0

        print.printer_Adobe_PDF.print_unwriteable_margin_top
        0

        print.printer_HP_LaserJet_5.print_bgcolor
        false

        print.printer_HP_LaserJet_5.print_bgimages
        false

        print.printer_HP_LaserJet_5.print_command

        print.printer_HP_LaserJet_5.print_downloadfonts
        false

        print.printer_HP_LaserJet_5.print_edge_bottom
        0

        print.printer_HP_LaserJet_5.print_edge_left
        0

        print.printer_HP_LaserJet_5.print_edge_right
        0

        print.printer_HP_LaserJet_5.print_edge_top
        0

        print.printer_HP_LaserJet_5.print_evenpages
        true

        print.printer_HP_LaserJet_5.print_footercenter

        print.printer_HP_LaserJet_5.print_footerleft
        &PT

        print.printer_HP_LaserJet_5.print_footerright
        &D

        print.printer_HP_LaserJet_5.print_headercenter

        print.printer_HP_LaserJet_5.print_headerleft
        &T

        print.printer_HP_LaserJet_5.print_headerright
        &U

        print.printer_HP_LaserJet_5.print_in_color
        true

        print.printer_HP_LaserJet_5.print_margin_bottom
        0.5

        print.printer_HP_LaserJet_5.print_margin_left
        0.5

        print.printer_HP_LaserJet_5.print_margin_right
        0.5

        print.printer_HP_LaserJet_5.print_margin_top
        0.5

        print.printer_HP_LaserJet_5.print_oddpages
        true

        print.printer_HP_LaserJet_5.print_orientation
        0

        print.printer_HP_LaserJet_5.print_pagedelay
        500

        print.printer_HP_LaserJet_5.print_paper_data
        1

        print.printer_HP_LaserJet_5.print_paper_height
        11.00

        print.printer_HP_LaserJet_5.print_paper_size
        0

        print.printer_HP_LaserJet_5.print_paper_size_type
        0

        print.printer_HP_LaserJet_5.print_paper_size_unit
        0

        print.printer_HP_LaserJet_5.print_paper_width
        8.50

        print.printer_HP_LaserJet_5.print_reversed
        false

        print.printer_HP_LaserJet_5.print_scaling
        1.00

        print.printer_HP_LaserJet_5.print_shrink_to_fit
        true

        print.printer_HP_LaserJet_5.print_to_file
        false

        print.printer_HP_LaserJet_5.print_unwriteable_margin_bottom
        0

        print.printer_HP_LaserJet_5.print_unwriteable_margin_left
        0

        print.printer_HP_LaserJet_5.print_unwriteable_margin_right
        0

        print.printer_HP_LaserJet_5.print_unwriteable_margin_top
        0

        print.printer_HP_Officejet_J6400_series.print_bgcolor
        false

        print.printer_HP_Officejet_J6400_series.print_bgimages
        false

        print.printer_HP_Officejet_J6400_series.print_command

        print.printer_HP_Officejet_J6400_series.print_downloadfonts
        false

        print.printer_HP_Officejet_J6400_series.print_edge_bottom
        0

        print.printer_HP_Officejet_J6400_series.print_edge_left
        0

        print.printer_HP_Officejet_J6400_series.print_edge_right
        0

        print.printer_HP_Officejet_J6400_series.print_edge_top
        0

        print.printer_HP_Officejet_J6400_series.print_evenpages
        true

        print.printer_HP_Officejet_J6400_series.print_footercenter

        print.printer_HP_Officejet_J6400_series.print_footerleft
        &PT

        print.printer_HP_Officejet_J6400_series.print_footerright
        &D

        print.printer_HP_Officejet_J6400_series.print_headercenter

        print.printer_HP_Officejet_J6400_series.print_headerleft
        &T

        print.printer_HP_Officejet_J6400_series.print_headerright
        &U

        print.printer_HP_Officejet_J6400_series.print_in_color
        true

        print.printer_HP_Officejet_J6400_series.print_margin_bottom
        0.5

        print.printer_HP_Officejet_J6400_series.print_margin_left
        0.5

        print.printer_HP_Officejet_J6400_series.print_margin_right
        0.5

        print.printer_HP_Officejet_J6400_series.print_margin_top
        0.5

        print.printer_HP_Officejet_J6400_series.print_oddpages
        true

        print.printer_HP_Officejet_J6400_series.print_orientation
        0

        print.printer_HP_Officejet_J6400_series.print_pagedelay
        500

        print.printer_HP_Officejet_J6400_series.print_paper_data
        1

        print.printer_HP_Officejet_J6400_series.print_paper_height
        11.00

        print.printer_HP_Officejet_J6400_series.print_paper_size_type
        0

        print.printer_HP_Officejet_J6400_series.print_paper_size_unit
        0

        print.printer_HP_Officejet_J6400_series.print_paper_width
        8.50

        print.printer_HP_Officejet_J6400_series.print_reversed
        false

        print.printer_HP_Officejet_J6400_series.print_scaling
        1.00

        print.printer_HP_Officejet_J6400_series.print_shrink_to_fit
        true

        print.printer_HP_Officejet_J6400_series.print_to_file
        false

        print.printer_HP_Officejet_J6400_series.print_unwriteable_margin_bottom
        0

        print.printer_HP_Officejet_J6400_series.print_unwriteable_margin_left
        0

        print.printer_HP_Officejet_J6400_series.print_unwriteable_margin_right
        0

        print.printer_HP_Officejet_J6400_series.print_unwriteable_margin_top
        0

        print.printer_Lexmark_2500_Series.print_bgcolor
        false

        print.printer_Lexmark_2500_Series.print_bgimages
        false

        print.printer_Lexmark_2500_Series.print_command

        print.printer_Lexmark_2500_Series.print_downloadfonts
        false

        print.printer_Lexmark_2500_Series.print_edge_bottom
        0

        print.printer_Lexmark_2500_Series.print_edge_left
        0

        print.printer_Lexmark_2500_Series.print_edge_right
        0

        print.printer_Lexmark_2500_Series.print_edge_top
        0

        print.printer_Lexmark_2500_Series.print_evenpages
        true

        print.printer_Lexmark_2500_Series.print_footercenter

        print.printer_Lexmark_2500_Series.print_footerleft
        &PT

        print.printer_Lexmark_2500_Series.print_footerright
        &D

        print.printer_Lexmark_2500_Series.print_headercenter

        print.printer_Lexmark_2500_Series.print_headerleft
        &T

        print.printer_Lexmark_2500_Series.print_headerright
        &U

        print.printer_Lexmark_2500_Series.print_in_color
        true

        print.printer_Lexmark_2500_Series.print_margin_bottom
        0.5

        print.printer_Lexmark_2500_Series.print_margin_left
        0.5

        print.printer_Lexmark_2500_Series.print_margin_right
        0.5

        print.printer_Lexmark_2500_Series.print_margin_top
        0.5

        print.printer_Lexmark_2500_Series.print_oddpages
        true

        print.printer_Lexmark_2500_Series.print_orientation
        0

        print.printer_Lexmark_2500_Series.print_pagedelay
        500

        print.printer_Lexmark_2500_Series.print_paper_data
        1

        print.printer_Lexmark_2500_Series.print_paper_height
        11.00

        print.printer_Lexmark_2500_Series.print_paper_size_type
        0

        print.printer_Lexmark_2500_Series.print_paper_size_unit
        0

        print.printer_Lexmark_2500_Series.print_paper_width
        8.50

        print.printer_Lexmark_2500_Series.print_reversed
        false

        print.printer_Lexmark_2500_Series.print_scaling
        1.00

        print.printer_Lexmark_2500_Series.print_shrink_to_fit
        true

        print.printer_Lexmark_2500_Series.print_to_file
        false

        print.printer_Lexmark_2500_Series.print_unwriteable_margin_bottom
        0

        print.printer_Lexmark_2500_Series.print_unwriteable_margin_left
        0

        print.printer_Lexmark_2500_Series.print_unwriteable_margin_right
        0

        print.printer_Lexmark_2500_Series.print_unwriteable_margin_top
        0

        print.printer_Lexmark_X1100_Series.print_bgcolor
        false

        print.printer_Lexmark_X1100_Series.print_bgimages
        false

        print.printer_Lexmark_X1100_Series.print_command

        print.printer_Lexmark_X1100_Series.print_downloadfonts
        false

        print.printer_Lexmark_X1100_Series.print_edge_bottom
        0

        print.printer_Lexmark_X1100_Series.print_edge_left
        0

        print.printer_Lexmark_X1100_Series.print_edge_right
        0

        print.printer_Lexmark_X1100_Series.print_edge_top
        0

        print.printer_Lexmark_X1100_Series.print_evenpages
        true

        print.printer_Lexmark_X1100_Series.print_footercenter

        print.printer_Lexmark_X1100_Series.print_footerleft
        &PT

        print.printer_Lexmark_X1100_Series.print_footerright
        &D

        print.printer_Lexmark_X1100_Series.print_headercenter

        print.printer_Lexmark_X1100_Series.print_headerleft
        &T

        print.printer_Lexmark_X1100_Series.print_headerright
        &U

        print.printer_Lexmark_X1100_Series.print_in_color
        true

        print.printer_Lexmark_X1100_Series.print_margin_bottom
        0.5

        print.printer_Lexmark_X1100_Series.print_margin_left
        0.5

        print.printer_Lexmark_X1100_Series.print_margin_right
        0.5

        print.printer_Lexmark_X1100_Series.print_margin_top
        0.5

        print.printer_Lexmark_X1100_Series.print_oddpages
        true

        print.printer_Lexmark_X1100_Series.print_orientation
        0

        print.printer_Lexmark_X1100_Series.print_pagedelay
        500

        print.printer_Lexmark_X1100_Series.print_paper_data
        1

        print.printer_Lexmark_X1100_Series.print_paper_height
        11.00

        print.printer_Lexmark_X1100_Series.print_paper_size_type
        0

        print.printer_Lexmark_X1100_Series.print_paper_size_unit
        0

        print.printer_Lexmark_X1100_Series.print_paper_width
        8.50

        print.printer_Lexmark_X1100_Series.print_reversed
        false

        print.printer_Lexmark_X1100_Series.print_scaling
        1.00

        print.printer_Lexmark_X1100_Series.print_shrink_to_fit
        true

        print.printer_Lexmark_X1100_Series.print_to_file
        false

        print.printer_Lexmark_X1100_Series.print_unwriteable_margin_bottom
        0

        print.printer_Lexmark_X1100_Series.print_unwriteable_margin_left
        0

        print.printer_Lexmark_X1100_Series.print_unwriteable_margin_right
        0

        print.printer_Lexmark_X1100_Series.print_unwriteable_margin_top
        0

        print.printer_Microsoft_XPS_Document_Writer.print_bgcolor
        false

        print.printer_Microsoft_XPS_Document_Writer.print_bgimages
        false

        print.printer_Microsoft_XPS_Document_Writer.print_command

        print.printer_Microsoft_XPS_Document_Writer.print_downloadfonts
        false

        print.printer_Microsoft_XPS_Document_Writer.print_edge_bottom
        0

        print.printer_Microsoft_XPS_Document_Writer.print_edge_left
        0

        print.printer_Microsoft_XPS_Document_Writer.print_edge_right
        0

        print.printer_Microsoft_XPS_Document_Writer.print_edge_top
        0

        print.printer_Microsoft_XPS_Document_Writer.print_evenpages
        true

        print.printer_Microsoft_XPS_Document_Writer.print_footercenter

        print.printer_Microsoft_XPS_Document_Writer.print_footerleft
        &PT

        print.printer_Microsoft_XPS_Document_Writer.print_footerright
        &D

        print.printer_Microsoft_XPS_Document_Writer.print_headercenter

        print.printer_Microsoft_XPS_Document_Writer.print_headerleft
        &T

        print.printer_Microsoft_XPS_Document_Writer.print_headerright
        &U

        print.printer_Microsoft_XPS_Document_Writer.print_in_color
        true

        print.printer_Microsoft_XPS_Document_Writer.print_margin_bottom
        0.5

        print.printer_Microsoft_XPS_Document_Writer.print_margin_left
        0.5

        print.printer_Microsoft_XPS_Document_Writer.print_margin_right
        0.5

        print.printer_Microsoft_XPS_Document_Writer.print_margin_top
        0.5

        print.printer_Microsoft_XPS_Document_Writer.print_oddpages
        true

        print.printer_Microsoft_XPS_Document_Writer.print_orientation
        0

        print.printer_Microsoft_XPS_Document_Writer.print_pagedelay
        500

        print.printer_Microsoft_XPS_Document_Writer.print_paper_data
        1

        print.printer_Microsoft_XPS_Document_Writer.print_paper_height
        11.00

        print.printer_Microsoft_XPS_Document_Writer.print_paper_size_type
        0

        print.printer_Microsoft_XPS_Document_Writer.print_paper_size_unit
        0

        print.printer_Microsoft_XPS_Document_Writer.print_paper_width
        8.50

        print.printer_Microsoft_XPS_Document_Writer.print_reversed
        false

        print.printer_Microsoft_XPS_Document_Writer.print_scaling
        1.00

        print.printer_Microsoft_XPS_Document_Writer.print_shrink_to_fit
        true

        print.printer_Microsoft_XPS_Document_Writer.print_to_file
        false

        print.printer_Microsoft_XPS_Document_Writer.print_unwriteable_margin_bottom
        0

        print.printer_Microsoft_XPS_Document_Writer.print_unwriteable_margin_left
        0

        print.printer_Microsoft_XPS_Document_Writer.print_unwriteable_margin_right
        0

        print.printer_Microsoft_XPS_Document_Writer.print_unwriteable_margin_top
        0

        privacy.clearOnShutdown.downloads
        false

        privacy.clearOnShutdown.offlineApps
        true

        privacy.cpd.siteSettings
        true

        privacy.item.cookies
        true

        privacy.item.downloads
        false

        privacy.item.offlineApps
        true

        privacy.sanitize.migrateFx3Prefs
        true

        privacy.sanitize.promptOnSanitize
        false

        privacy.sanitize.sanitizeOnShutdown
        true

        privacy.sanitize.timeSpan
        0

        security.OCSP.disable_button.managecrl
        false

        security.default_personal_cert
        Select Automatically

        security.disable_button.openCertManager
        false

        security.disable_button.openDeviceManager
        false

        security.enable_ssl2
        true

        security.warn_entering_weak
        false

        security.warn_leaving_secure
        true

        security.warn_viewing_mixed
        false
Hijacker prevents leaving Mozilla.  only way to terminate program is to use task manager.  If you click on hijackeer it stats worm spreading.  My IT guy found it will eventually disable internet by changing LAN settings.  Fortunately Malware gets all of it except the cookie(?) that keeps opening the URL identified.
Group: core-security
the XULRunner 1.9.1 addon is malware -- nuke that sucker! Never heard of Hyperwords, but if you know you added it yourself it's probably OK.

Please see http://support.mozilla.com/ for help on removing the bad addon. Usually that addon is added by other software installed on your machine so you may need to figure out where it's respawning from.

Also try http://www.mozilla.com/plugincheck/ to see if your plugins are out of date -- a common route of infection.
The URL in the bug is "AccessDenied" now, so no way to diagnose what it was.
Version: unspecified → 3.6 Branch
Status: UNCONFIRMED → RESOLVED
Closed: 9 years ago
Resolution: --- → INCOMPLETE
You need to log in before you can comment on or make changes to this bug.