Updated Firefox, got a nasty extension

User Help for Mozilla Firefox
Anon.
Guest

Re: Updated Firefox, got a nasty extension

Post by Anon. »

I've got a goored problem as well. Even after a scan with spybot, the problem persists. It only happens with some google searches, however. My Application data has two folders with long letter/number strings; one contains something java related, while the other has something to do with google chrome (I'd imagine. The only things contained in that folder have things titled chrome). Anybody have some advice?
GeorgeFive
Posts: 159
Joined: May 1st, 2004, 6:44 am

Re: Updated Firefox, got a nasty extension

Post by GeorgeFive »

Did you try the step-by-step guide I posted?
Katana_1970
Posts: 3
Joined: June 3rd, 2007, 8:25 am

Re: Updated Firefox, got a nasty extension

Post by Katana_1970 »

@ Anon
Please could you register at Security Cadets, we need some copies of these files so we can target them.
Guest
Guest

Re: Updated Firefox, got a nasty extension

Post by Guest »

Anon. wrote:I've got a goored problem as well. Even after a scan with spybot, the problem persists. It only happens with some google searches, however. My Application data has two folders with long letter/number strings; one contains something java related, while the other has something to do with google chrome (I'd imagine. The only things contained in that folder have things titled chrome). Anybody have some advice?


I had the chrome folder, too. I decided that it was suspicious of it to be in Firefox so I deleted the registry and folder. It did not help anything.

This is so frustrating. ](*,)

Here's a HijackThis report. Maybe it'll provide some hints.

Code: Select all

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:03:06 AM, on 12/9/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\mobile PhoneTools\WatchDog.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Vaio\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Apoint\Apvfb.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Wolfram Research\Mathematica\6.0\SystemFiles\FrontEnd\Binaries\Windows\Mathematica.exe
C:\Program Files\Wolfram Research\Mathematica\6.0\MathKernel.exe
C:\Program Files\Wolfram Research\Mathematica\6.0\SystemFiles\Java\Windows\bin\javaw.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\mobile PhoneTools\WatchDog.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Vaio\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {2931566C-B8A6-46C5-BF4D-E6AB9251E953} (Nexon Package Manager Control) - http://s.nx.com/activex/public_new/nxpm.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: CA Personal Firewall ASEM - Unknown owner - C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

--
End of file - 12643 bytes


I know I have a lot of useless crap bloating my system, but none of it seems malicious.
User avatar
Alice
Posts: 2628
Joined: April 23rd, 2003, 11:47 am

Re: Updated Firefox, got a nasty extension

Post by Alice »

---> C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
Guest,
I don't know about the rest of it (a Security-related forum specializing in malware removal could tell you more) but your Java JRE version 1.5.0_07 is seriously outdated and vulnerable to security exploits. You should uninstall Java Runtime Environment (JRE) 1.5.0_07 (and any other installed JRE versions) and get the latest secure version, currently JRE 5.0 Update 17 or JRE 6 Update 11. Here is the most recent Secunia advisory: http://secunia.com/advisories/32991/

(I recently removed JRE 6u7 and installed JRE 6u11 because of this advisory)
Alice Wyman
GeorgeFive
Posts: 159
Joined: May 1st, 2004, 6:44 am

Re: Updated Firefox, got a nasty extension

Post by GeorgeFive »

"Chrome" is a part of Firefox, no need to delete.

Mozilla/Firefox/Profiles/[rand]/chrome = Layout stuff.

Also, each extension you download adds a file called chrome.manifest as well as a folder called chrome.
Guest
Guest

Re: Updated Firefox, got a nasty extension

Post by Guest »

Alice wrote:---> C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
Guest,
I don't know about the rest of it (a Security-related forum specializing in malware removal could tell you more) but your Java JRE version 1.5.0_07 is seriously outdated and vulnerable to security exploits. You should uninstall Java Runtime Environment (JRE) 1.5.0_07 (and any other installed JRE versions) and get the latest secure version, currently JRE 5.0 Update 17 or JRE 6 Update 11. Here is the most recent Secunia advisory: http://secunia.com/advisories/32991/

(I recently removed JRE 6u7 and installed JRE 6u11 because of this advisory)


I updated to 6u11. I had forgotten that JRE was trying to update before but for some reason couldn't. I had to remove the old one manually. Anyways, the problem seems to be gone.

Thanks.
mandywr
Guest

Re: Updated Firefox, got a nasty extension

Post by mandywr »

I too updated. to the new Firefox and I noticed a box popped up and it said that a new add-on had been installed. I thought it was something to do with the firefox updating. I had not asked for any new add-on, and I didn't actually see anything new Then I saw, from PCAdvisor,Mozilla Firefox users are being targeted by a new Trojan that steals online banking passwords. The malware, which is being spread by drive-by downloads or by duping users into downloading it, is stored in the Firefox add-on folder and is registered as 'Greasemonkey', which are scripts that add extra functionality to Firefox. It starts working as soon as the browser is opened.

How can I discover whether I have this. I am using XP home with all recent updates and AD-aware, and Avast antivirus and Comodo Firewall, and did a full scan 2 weeks ago.
GeorgeFive
Posts: 159
Joined: May 1st, 2004, 6:44 am

Re: Updated Firefox, got a nasty extension

Post by GeorgeFive »

GeorgeFive wrote:Did you try the step-by-step guide I posted?
carle
Guest

Re: Updated Firefox, got a nasty extension

Post by carle »

GeorgeFive: I've tried your steps multiple times. The goored stays in the system. Is it possible that this crap consists of two parts? The chrome xul stuff for hijacking the Google search result and another dll that re-installs the nasty stuff if deleted.


Either way, I've downloaded too many tools today and none have helped.
GeorgeFive
Posts: 159
Joined: May 1st, 2004, 6:44 am

Re: Updated Firefox, got a nasty extension

Post by GeorgeFive »

If you tried my steps (delete the specified folder / registry key and then run Malwarebytes), you should have it removed from your system. You do need to make sure that all instances of Firefox are closed before doing this (check your Task Manager), and you may need to restart afterward (I didn't, some have had to). Make sure you're running Malwarebytes - as of the time I had it, Spybot and AdAware did NOT pick this up. They may have updated since then, but I know for a fact that Malwarebytes will take care of the particular version that I had.

If you've done all of the above and you still have it, you either have something different or an updated version of the same thing. In either case, I apologize, but I'm not sure where to go from there.
FreewheelinFrank
Guest

Re: Updated Firefox, got a nasty extension

Post by FreewheelinFrank »

mandywr wrote:I too updated. to the new Firefox and I noticed a box popped up and it said that a new add-on had been installed. I thought it was something to do with the firefox updating. I had not asked for any new add-on, and I didn't actually see anything new Then I saw, from PCAdvisor,Mozilla Firefox users are being targeted by a new Trojan that steals online banking passwords. The malware, which is being spread by drive-by downloads or by duping users into downloading it, is stored in the Firefox add-on folder and is registered as 'Greasemonkey', which are scripts that add extra functionality to Firefox. It starts working as soon as the browser is opened.

How can I discover whether I have this. I am using XP home with all recent updates and AD-aware, and Avast antivirus and Comodo Firewall, and did a full scan 2 weeks ago.


I also noticed the new add-on notification yesterday, but I think it was just a previously installed add-on which had become disabled after and update of Firefox being re-enabled as an update became available.

This notification alone doesn't mean that anything bad has happened, I think.
GeorgeFive
Posts: 159
Joined: May 1st, 2004, 6:44 am

Re: Updated Firefox, got a nasty extension

Post by GeorgeFive »

If you want to see if you have the exact thing that I had, go to google.com and search for anything. Right click the first result and click "Copy", then "Paste" it into Notepad. You do not have this if it says:

http://www.the-site-you-expected.com

However, you have a problem if it's something like:

http //123.goored.com/url=http://www.some-other-site.com
ElvisCostello
Posts: 5
Joined: December 11th, 2008, 11:50 am

Re: Updated Firefox, got a nasty extension

Post by ElvisCostello »

I'v been goored also. I uninstalled the 3.0.4 version, used Avast to scan for rootkits prior to booting XP and then installed version 3.1b2. I searched google, clicked on the first link and discovered that goored is still present!
ElvisCostello
Posts: 5
Joined: December 11th, 2008, 11:50 am

Re: Updated Firefox, got a nasty extension

Post by ElvisCostello »

I deleted the registry entry [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions] for
C:\Documents and Settings\USERNAME\Local Settings\Application Data\{31D494-E8F8-48AF-9833-B9C683ADCE}
and this fxed the problem.
NOTE: the key is different than what others have reported.

Restarted Firefox and tested google - no problems.
Locked