Somehow the GetSavin 5.0 got into the 'about:config' menu - the place where one makes Firefox tweaks. I am only one in house who knows the about_config
Sorry. The below seems like someone is trying to hack FF's add-ons. I was frustrated to have to go through hoops to try to reach someone at Mozilla with what's essentially a 911 call.
FF on Win7 Pro crashed and asked to restore pages. An add-on I had not solicited was prompting me to install. It calls itself "GetSavin 5.0". Other relevant info: getsavin@jetpack . Sorry, there was more on the add-on screen but I wanted to get this off my computer ASAP. Again, I did not initiate this add-on!
GetSavin' or any permutation of this is not in the Mozilla add-on directory.
The scary thing was that the damn thing was on the threshold of the Mozilla about:config command line. I'm the only one in my family who even knows what this is.
Additional System Details
Installed Plug-ins
- Adobe PDF Plug-In For Firefox and Netscape 11.0.02
- Shockwave Flash 11.5 r502
- NPRuntime Script Plug-in Library for Java(TM) Deploy
- Nexon Game Controller
- Pando Web Plugin
- Citrix Receiver Plugin (Win32)
- The plug-in allows you to open and edit files using Microsoft Office applications
- Office Authorization plug-in for NPAPI browsers
Application
- Firefox 19.0
- User Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:19.0) Gecko/20100101 Firefox/19.0
- Support URL: http://support.mozilla.org/1/firefox/19.0/WINNT/en-US/
Extensions
- Adblock Plus 2.2.3
- Adblock Plus Pop-up Addon 0.6
- Cookies Manager+ 1.5.1.1
- Ghostery 2.8.4
- Norton Toolbar 2013.3.0.26
- NoScript 2.6.5.7
- Troubleshooter 1.0a
- Norton Vulnerability Protection 11.1.1.5 - 3 (Inactive)
- Skype Click to Call 6.6.0.11664 (Inactive)
Javascript
- incrementalGCEnabled: True
Graphics
- adapterDescription: AMD Radeon HD 7660D
- adapterDescription2:
- adapterDeviceID: 0x9901
- adapterDeviceID2:
- adapterDrivers: aticfx64 aticfx64 aticfx64 aticfx32 aticfx32 aticfx32 atiumd64 atidxx64 atidxx64 atiumdag atidxx32 atidxx32 atiumdva atiumd6a atitmm64
- adapterDrivers2:
- adapterRAM: 512
- adapterRAM2:
- adapterVendorID: 0x1002
- adapterVendorID2:
- direct2DEnabled: True
- directWriteEnabled: True
- directWriteVersion: 6.2.9200.16492
- driverDate: 9-27-2012
- driverDate2:
- driverVersion: 9.2.0.0
- driverVersion2:
- info: {u'AzureContentBackend': u'direct2d', u'AzureCanvasBackend': u'direct2d', u'AzureFallbackCanvasBackend': u'cairo'}
- isGPU2Active: False
- numAcceleratedWindows: 2
- numTotalWindows: 2
- webglRenderer: Google Inc. -- ANGLE (AMD Radeon HD 7660D)
- windowLayerManagerType: Direct3D 10
Modified Preferences
- accessibility.typeaheadfind.flashBar: 0
- browser.cache.disk.capacity: 358400
- browser.cache.disk.smart_size.first_run: False
- browser.cache.disk.smart_size.use_old_max: False
- browser.cache.disk.smart_size_cached_value: 358400
- browser.places.smartBookmarksVersion: 4
- browser.search.useDBForOrder: True
- browser.startup.homepage: http://www.wikipedia.org/
- browser.startup.homepage_override.buildID: 20130215130331
- browser.startup.homepage_override.mstone: 19.0
- dom.mozApps.used: True
- extensions.lastAppVersion: 19.0
- gfx.direct3d.prefer_10_1: True
- network.cookie.prefsMigrated: True
- places.database.lastMaintenance: 1361806350
- places.history.expiration.transient_current_max_pages: 104858
- plugin.disable_full_page_plugin_for_types: application/pdf
- privacy.clearOnShutdown.cookies: False
- privacy.clearOnShutdown.downloads: False
- privacy.clearOnShutdown.formdata: False
- privacy.clearOnShutdown.history: False
- privacy.donottrackheader.enabled: True
- privacy.sanitize.migrateFx3Prefs: True
- privacy.sanitize.promptOnSanitize: False
- privacy.sanitize.sanitizeOnShutdown: True
- security.warn_viewing_mixed.show_once: False
Misc
- User JS: No
- Accessibility: No
GSO_frustrated wrote:
An add-on I had not solicited was prompting me to install.
As long as you declined the installation, your Firefox setup should be fine. Questionable bundled software like the one you mentioned is why Firefox prompts you to confirm installation.
Install, update, then run a scan with Malwarebytes' Anti-malware.
If you suspect your system is still infected afterwards, ask for help on the following forum.
GSO_frustrated wrote:
The scary thing was that the damn thing was on the threshold of the Mozilla about:config command line.
about:config is where Firefox and add-on preferences are stored. A preference making mention of an add-on is not unusual in itself. If you found something troubling, you'll have to detail what that is.
