We’d like to remind Forumites to please avoid political debate on the Forum.
This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
Firefox malware

thelawnet
Posts: 2,584 Forumite


in Techie Stuff
Just got malware from https://www.ihateryanair.org 'privacy.exe' using Firefox.
I loaded the site again using fiddler HTTP trace and found a hit to http://gsdfgsg.coom.in/showthread.php?t=64271947 which is 404 for me now, but I suspect they might cache my IP and only send the malware once.
Not sure what the source of that is as there was no call to it in plain text but there are some obfuscated 'polldaddy' and 'addtoany.com' javascripts also an .swf at poll.fm.
Any ideas what attack vector these malware use to infect through Firefox? The privacy.exe downloaded to C:\Users\%username%\AppData\Roaming which is a low-privilege area, but still annoying.
PS. When I reloaded the ihateryanair.org site again the gsdfgsg.coom.in hit was gone.... Just shows how fast this stuff moves.
I loaded the site again using fiddler HTTP trace and found a hit to http://gsdfgsg.coom.in/showthread.php?t=64271947 which is 404 for me now, but I suspect they might cache my IP and only send the malware once.
Not sure what the source of that is as there was no call to it in plain text but there are some obfuscated 'polldaddy' and 'addtoany.com' javascripts also an .swf at poll.fm.
Any ideas what attack vector these malware use to infect through Firefox? The privacy.exe downloaded to C:\Users\%username%\AppData\Roaming which is a low-privilege area, but still annoying.
PS. When I reloaded the ihateryanair.org site again the gsdfgsg.coom.in hit was gone.... Just shows how fast this stuff moves.
0
Comments
-
just out of interest, what anti -virus/-malware software do/did u have installed ?BLOODBATH IN THE EVENING THEN? :shocked: OR PERHAPS THE AFTERNOON? OR THE MORNING? OH, FORGET THIS MALARKEY!
THE KILLERS :cool:
THE PUNISHER :dance: MATURE CHEDDAR ADDICT:cool:0 -
Your malware was probably served from an advert on the site, the site probably did not host it.
Booby trapped adverts are quite often there one minute, gone the next as adverts are sent randomly. If you want to be even safer, run your web browser in a sandbox. eg sandboxie, that way if anything arrives it cannot get into your system, you just empty the sandbox and all is gone, even if it did run you would not have a problem.0 -
How did you recover?
I too visited this site today around 1pm and got hit.
The result is that all my folders and files are marked as hidden. My start menu consists of nothing. and half my icons on my desktop are gone.
I've shutdown and restarted in safe mode.
And currently left the PC as such overnight to decide what to do.0 -
marsbar989 wrote: »The result is that all my folders and files are marked as hidden. My start menu consists of nothing. and half my icons on my desktop are gone.
Unhide.exe - A introduction as to what this program does
Removal instructions for Privacy Protection
Remove Privacy Protection (Uninstall Guide)0 -
marsbar989 wrote: »How did you recover?
I too visited this site today around 1pm and got hit.
Timestamp is 1:02pmThe result is that all my folders and files are marked as hidden. My start menu consists of nothing. and half my icons on my desktop are gone.
I've shutdown and restarted in safe mode.
And currently left the PC as such overnight to decide what to do.
I just right clicked on the taskbar, showed task manager, looked for a dodgy looking process and there was privacy.exe. I think it tried to shut down my task manager but I just fired it up again and killed it again.
It didn't exactly make itself inconspicuous.
It downloaded to C:\Users\%username%\AppData\Roaming so I just deleted it from there.
Info here: http://remove-malwares.blogspot.com/2011/11/privacyexe-virus-process-of-privacy.html
I'm not quite clear as to the attack vector they use to infect Firefox, I thought it was supposed to be safer than IE.0 -
free4440273 wrote: »just out of interest, what anti -virus/-malware software do/did u have installed ?Error! - Keyboard not attached. Press any key to continue.0
-
Avast Free a/v blocks it but I suppose by now they all do.0
-
download malware proggy and it reported wmprwise.exe installed.
Removed this and as in safe mode backup some files.
Seems some files are bad - in the sense that I cannot copy them. Access is denied even as adminstrator on pc.
unhide all of \programs and \my docs.
but \programs still appears as if they are hidden. I can see the contents of the directories though,.0 -
marsbar989 wrote: »download malware proggy and it reported wmprwise.exe installed.
http://www.threatexpert.com/report.aspx?md5=f6d1cc95f023b9d788eaa4cd8737561d
Do an online scan to confirm whether or not you are infected with Ramnit. Don't rely on your installed AV as it may be infected itself.
http://www.eset.co.uk/Antivirus-Utilities/Online-Scanner0
This discussion has been closed.
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 351.8K Banking & Borrowing
- 253.4K Reduce Debt & Boost Income
- 454K Spending & Discounts
- 244.7K Work, Benefits & Business
- 600.2K Mortgages, Homes & Bills
- 177.3K Life & Family
- 258.4K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.2K Discuss & Feedback
- 37.6K Read-Only Boards