X
Tap here to go to the mobile version of the site.
Your Firefox is out of date and may contain a security risk! Upgrade Firefox

Support Forum

when i do a search, the following url appears: http://click.livesearchnow.com/ads-clicktrack/click/jump1.do?sid=29464E06029225B179EE10C948543927FE4837C96521DA9

Posted

regardless of what i search for, that url appears and usually leads me to a strange page. Note that it does not happen with Chrome or IE - only w/Firefox.

Chosen solution

Looks like you got infected with either malicious plugin, trojan or bad proxy. First you should try to Reset Firefox preferences to troubleshoot and fix problems , and if this does not help, scan with anti-malware programs, like hitman Pro or malwarebytes.

Read this answer in context 0

Additional System Details

Installed Plug-ins

  • Shockwave Flash 11.6 r602
  • Plug-in for Workspace utilities
  • Google Talk Plugin Video Accelerator version:0.1.44.24
  • Version 3.15.2.12038
  • Google Update
  • Adobe PDF Plug-In For Firefox and Netscape "9.5.4"
  • Plug-in for Workspace Webmail
  • Advanced SystemCare 6 Safari Plugin DLL
  • Advanced SystemCare 6 Opera Plugin DLL
  • Garmin Communicator Plug-In 4.0.4.0
  • Adobe PDF Plug-In For Firefox and Netscape 11.0.0
  • The QuickTime Plugin allows you to view a wide variety of multimedia content in Web pages. For more information, visit the QuickTime Web site.
  • 5.1.10411.0
  • Picasa plugin
  • 1,2,1,2044
  • GEPlugin
  • ActiveTouch General Plugin Container Version 105
  • iTunes Detector Plug-in
  • Motive Plugin for Mozilla Browsers
  • 5.0.0.0
  • Virtual Earth 3D 3.00080829001 plugin for Mozilla
  • Windows Presentation Foundation (WPF) plug-in for Mozilla browsers
  • 1.7.0069.3
  • DNL Reader
  • Google Gadget Plugin 5.7.712.19360
  • np-mswmp
  • RealJukebox Netscape Plugin
  • RealPlayer(tm) LiveConnect-Enabled Plug-In
  • 6.0.12.1739
  • Yahoo! activeX Plug-in Bridge
  • Office Plugin for Netscape Navigator
  • Macromedia Shockwave for Director Netscape plug-in, version 10.1

Application

  • Firefox 19.0.2
  • User Agent: Mozilla/5.0 (Windows NT 5.1; rv:19.0) Gecko/20100101 Firefox/19.0
  • Support URL: http://support.mozilla.org/1/firefox/19.0.2/WINNT/en-US/

Extensions

  • Adblock Plus 2.2.3 ({d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d})
  • Advanced SystemCare Surfing Protection 1.0 (ascsurfingprotection@iobit.com)
  • BabelFish 1.96 ({ca0849e8-2c76-42ae-9abe-34e14d337acf})
  • BetterPrivacy 1.68 ({d40f5e7b-d2cf-4856-b441-cc613eeffbe3})
  • CSHelper 1.0 ({d91a2be6-3b56-4dfb-97f5-5e48fe3ed473})
  • DownloadHelper 4.9.14 ({b9db16a4-6edc-47ec-a1f4-b86292ed211d})
  • eBay Toolbar 1.3.2.0041 ({249df6a2-e336-47d1-b6c3-ec711ad140ca})
  • FoxClocks 3.1.26 ({d37dc5d0-431d-44e5-8c91-49419370caa1})
  • Garmin Communicator 4.0.4 ({195A3098-0BD5-4e90-AE22-BA1C540AFD1E})
  • Ghostery 2.9.2 (firefox@ghostery.com)
  • Java Console 6.0.37 ({CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA})
  • Readability 2.4 (readability@readability.com)
  • Readability 2.4 ({6005d9b1-d115-485a-a92a-3f6453ca3fe2})
  • ReminderFox 2.0.2 ({ada4b710-8346-4b82-8199-5de2b400a6ae})
  • RSS Icon In Awesombar 1.4 (rssicon@jasnapaka.com)
  • Show my Password 2.0 ({cd617372-6743-4ee4-bac4-fbf60f35719e})
  • StockFox 1.3.2 ({d39a0050-191f-11df-8a39-0800200c9a66})
  • Troubleshooter 1.0a (troubleshooter@mozilla.org)
  • WiseStamp 3.11.21 (wisestamp@wisestamp.com)
  • Download Youtube Videos + 12.9.6 (video.downloader.plugin@ffpimp.com) (Inactive)
  • FoxTab 1.4.9 ({ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}) (Inactive)
  • Freeze.com NetAssistant 3.6.5 ({1266764D-FC4F-4FA7-B63B-884D53B1680F}) (Inactive)
  • Google Gears 0.5.36.0 ({000a9d1c-beef-4f90-9363-039d445309b8}) (Inactive)
  • Google Web Accelerator 1.0.93.116 (web-accelerator@google.com) (Inactive)
  • KeyScrambler 2.7.0.0 (keyscrambler@qfx.software.corporation) (Inactive)
  • Microsoft .NET Framework Assistant 1.2.1 ({20a82645-c095-46ed-80e3-08825760534b}) (Inactive)
  • NoScript 2.6.5.8 ({73a6fe31-595d-460b-a920-fcc0f8843232}) (Inactive)
  • Reader 4.3 ({20068ab2-1901-4140-9f3c-81207d4dacc4}) (Inactive)
  • Screengrab 0.96.3 ({02450954-cdd9-410f-b1da-db804e18c671}) (Inactive)
  • SecurePassword Generator 0.5.4 ({EB8ABF49-0290-410f-BDF2-2F13A38112AB}) (Inactive)
  • Skype Click to Call 6.6.0.11664 ({82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}) (Inactive)
  • TinEye Reverse Image Search 1.1 (tineye@ideeinc.com) (Inactive)
  • TrafficLight 0.2.4 (trafficlight@bitdefender.com) (Inactive)
  • WBE Paste 1.3 (wbepaste@starfield) (Inactive)
  • Workspace Email Zoom 1.4 (zoomext@starfield) (Inactive)
  • Xmarks 4.1.3 (foxmarks@kei.com) (Inactive)

Javascript

  • incrementalGCEnabled: True

Graphics

  • adapterDescription: NVIDIA GeForce 6800 XT
  • adapterDescription2:
  • adapterDeviceID: 0x00c3
  • adapterDeviceID2:
  • adapterDrivers: nv4_disp
  • adapterDrivers2:
  • adapterRAM: Unknown
  • adapterRAM2:
  • adapterVendorID: 0x10de
  • adapterVendorID2:
  • direct2DEnabled: False
  • direct2DEnabledMessage: [u'']
  • directWriteEnabled: False
  • directWriteVersion: 0.0.0.0
  • driverDate: 10-10-2005
  • driverDate2:
  • driverVersion: 8.1.8.5
  • driverVersion2:
  • info: {u'AzureContentBackend': u'none', u'AzureCanvasBackend': u'cairo', u'AzureFallbackCanvasBackend': u'none'}
  • isGPU2Active: False
  • numAcceleratedWindows: 0
  • numAcceleratedWindowsMessage: [u'blockedDriver']
  • numTotalWindows: 1
  • webglRenderer: Google Inc. -- ANGLE (NVIDIA GeForce 6800 XT )
  • windowLayerManagerType: Basic

Modified Preferences

  • accessibility.blockautorefresh: True
  • accessibility.typeaheadfind: True
  • accessibility.typeaheadfind.flashBar: 0
  • browser.cache.disk.capacity: 358400
  • browser.cache.disk.smart_size.first_run: False
  • browser.cache.disk.smart_size.use_old_max: False
  • browser.cache.disk.smart_size_cached_value: 358400
  • browser.cache.memory.capacity: 65536
  • browser.display.show_image_placeholders: True
  • browser.places.smartBookmarksVersion: 4
  • browser.privatebrowsing.dont_prompt_on_enter: True
  • browser.search.suggest.enabled: False
  • browser.search.useDBForOrder: True
  • browser.startup.homepage: http://www.google.com/news
  • browser.startup.homepage_override.buildID: 20130307023931
  • browser.startup.homepage_override.mstone: 19.0.2
  • browser.urlbar.autocomplete.enabled: True
  • browser.urlbar.autofill: True
  • dom.mozApps.used: True
  • extensions.lastAppVersion: 19.0.2
  • gfx.blacklist.layers.direct3d9: 3
  • network.cookie.prefsMigrated: True
  • network.http.max-connections: 48
  • network.http.max-connections-per-server: 16
  • network.http.max-persistent-connections-per-proxy: 16
  • network.http.max-persistent-connections-per-server: 8
  • network.http.pipelining: True
  • network.http.pipelining.firstrequest: True
  • network.http.pipelining.maxrequests: 8
  • network.http.proxy.pipelining: True
  • network.http.request.max-start-delay: 0
  • places.database.lastMaintenance: 1363266544
  • places.history.expiration.transient_current_max_pages: 53637
  • plugin.disable_full_page_plugin_for_types: application/pdf
  • plugin.expose_full_path: True
  • privacy.cpd.offlineApps: True
  • privacy.cpd.sessions: False
  • privacy.cpd.siteSettings: True
  • privacy.donottrackheader.enabled: True
  • privacy.sanitize.migrateFx3Prefs: True
  • privacy.sanitize.timeSpan: 0
  • security.warn_viewing_mixed: False

Misc

  • User JS: Yes
  • Accessibility: No
TheOldFox 110 solutions 619 answers

Helpful Reply

The site "livesearchnow<dot>com" is a known link for a "redirect virus". Read the following article. You can download, install, update and run the free versions of the malware removal applications listed toward the end of the article or you can request help from one of the forums specializing in malware removal, also listed near the end of the article.

Modified by TheOldFox

Giedrius_M 18 solutions 157 answers

Chosen Solution

Looks like you got infected with either malicious plugin, trojan or bad proxy. First you should try to Reset Firefox preferences to troubleshoot and fix problems , and if this does not help, scan with anti-malware programs, like hitman Pro or malwarebytes.

Question owner

Thanks. Ran Malware Bites in safe mode- took care care the problem.

Appreciate the help.

Group2