X
Tap here to go to the mobile version of the site.
Your Firefox is out of date and may contain a security risk! Upgrade Firefox

Support Forum

How to eliminate a Hijack attempt when opening fireFox in windows

Posted

when opening Firefox (or any browser), I get an hijack alert. Instead of home page I get "https://search.perk.com/perk/mystart" I apply action to block hijack but firefox opens to it anyway. The firefox home page is correct. The properties for firefox don't show anything related to "search.perk". Scan on hard drive doesn't reveal any program / script for perk.

any ideal on how to remove "search.perk"?

Additional System Details

Installed Plug-ins

  • Shockwave Flash 11.7 r700
  • Google Talk Plugin Video Accelerator version:0.1.44.24
  • Version 3.18.1.12731
  • npsitesafety
  • Google Update
  • GEPlugin
  • Adobe PDF Plug-In For Firefox and Netscape "9.5.4"
  • 5.1.20125.0
  • Next Generation Java Plug-in 10.7.2 for Mozilla browsers
  • NPRuntime Script Plug-in Library for Java(TM) Deploy
  • RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In
  • RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In
  • RealDownloader Plugin
  • NPWLPG
  • Garmin Communicator Plug-In 4.0.1.0
  • DivX Plus Web Player version 2.2.0.52
  • DivX VOD Helper Plug-in
  • Adobe Shockwave for Director Netscape plug-in, version 11.5.9.615
  • The Hulu Desktop Plugin allows Hulu.com to integrate with the Hulu Desktop application.
  • Zeon PDF Plugin For Mozilla
  • CANON iMAGE GATEWAY Album Plugin Utility Module
  • The plug-in allows you to open and edit files using Microsoft Office applications
  • Office Authorization plug-in for NPAPI browsers

Application

  • Firefox 20.0.1
  • User Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:20.0) Gecko/20100101 Firefox/20.0
  • Support URL: http://support.mozilla.org/1/firefox/20.0.1/WINNT/en-US/

Extensions

  • Adblock Plus 2.2.3 ({d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d})
  • AVG Security Toolbar 14.2.0.1 (avg@toolbar)
  • BrowserProtect 1.1.3 (browserprotect@browserprotect.com)
  • DivX Plus Web Player HTML5 <video> 2.1.2.145 ({23fcfd51-4958-4f00-80a3-ae97e717ed8b})
  • Easy YouTube Video Downloader 6.8 ({c0c9a2c7-2e5c-4447-bc53-97718bc91e1b})
  • Fast Free Converter 3.0 (extension@FastFreeConverter.com)
  • Flash Video Downloader - Youtube Downloader 3.8.7 (artur.dubovoy@gmail.com)
  • Social Privacy 1.0 (sp@sp.com)
  • Troubleshooter 1.1a (troubleshooter@mozilla.org)
  • Unfriend Watcher 1.0 (uc@uc.com)
  • Universal Downloader 21.0.1 ({9051303c-7e41-4311-a783-d6fe5ef2832d})
  • incredibar.com 1.5.0 (ffxtlbr@incredibar.com) (Inactive)
  • PDF Converter 7.0 1.0 (nuance@pdf7) (Inactive)
  • Video Downloader professional 1.97.8 (ffext_basicvideoext@startpage24) (Inactive)
  • Web Assistant 2.0.0.440 ({336D0C35-8A85-403a-B9D2-65C292C39087}) (Inactive)
  • Yolobar 10.15.2.523 ({fdbf1b4b-f082-4b4b-ade9-9ca595c69898}) (Inactive)

Javascript

  • incrementalGCEnabled: True

Graphics

  • adapterDescription: ATI Mobility Radeon HD 5850
  • adapterDescription2:
  • adapterDeviceID: 0x68a1
  • adapterDeviceID2:
  • adapterDrivers: aticfx64 aticfx64 aticfx64 aticfx32 aticfx32 aticfx32 atiumd64 atidxx64 atidxx64 atiumdag atidxx32 atidxx32 atiumdva atiumd6a atitmm64
  • adapterDrivers2:
  • adapterRAM: 1024
  • adapterRAM2:
  • adapterVendorID: 0x1002
  • adapterVendorID2:
  • direct2DEnabled: False
  • direct2DEnabledMessage: [u'']
  • directWriteEnabled: False
  • directWriteVersion: 6.2.9200.16492
  • driverDate: 3-31-2011
  • driverDate2:
  • driverVersion: 8.820.5.1000
  • driverVersion2:
  • info: {u'AzureCanvasBackend': u'cairo', u'AzureFallbackCanvasBackend': u'none', u'AzureContentBackend': u'none'}
  • isGPU2Active: False
  • numAcceleratedWindows: 0
  • numAcceleratedWindowsMessage: [u'']
  • numTotalWindows: 1
  • webglRenderer: Google Inc. -- ANGLE (ATI Mobility Radeon HD 5850 )
  • windowLayerManagerType: Basic

Modified Preferences

  • browser.cache.disk.capacity: 358400
  • browser.cache.disk.smart_size.first_run: False
  • browser.cache.disk.smart_size.use_old_max: False
  • browser.cache.disk.smart_size_cached_value: 358400
  • browser.places.smartBookmarksVersion: 4
  • browser.search.useDBForOrder: True
  • browser.sessionstore.max_tabs_undo: 40
  • browser.startup.homepage: about:home|https://mybay.baycollege.edu/ics|http://www.google.com/ig|http://www.mycatholic.com/
  • browser.startup.homepage_override.buildID: 20130409194949
  • browser.startup.homepage_override.mstone: 20.0.1
  • browser.tabs.warnOnClose: False
  • dom.mozApps.used: True
  • dom.w3c_touch_events.expose: False
  • extensions.lastAppVersion: 20.0.1
  • font.internaluseonly.changed: True
  • gfx.direct2d.disabled: True
  • layers.acceleration.disabled: True
  • network.cookie.prefsMigrated: True
  • places.database.lastMaintenance: 1366668126
  • places.history.expiration.transient_current_max_pages: 104858
  • places.history.expiration.transient_optimal_database_size: 167772160
  • plugin.disable_full_page_plugin_for_types: application/pdf
  • privacy.donottrackheader.enabled: True
  • privacy.sanitize.migrateFx3Prefs: True
  • security.warn_viewing_mixed: False

Misc

  • User JS: Yes
  • Accessibility: No
the-edmeister
  • Top 10 Contributor
  • Moderator
3197 solutions 24404 answers

Chosen Solution

See this support thread - https://support.mozilla.org/en-US/questions/941632

Giedrius_M 18 solutions 157 answers

This is toolbar/search hijacker based on Blekko search. It is used for browser redirects, as they get commission for each person using their services. You have to uninstall all unknown addons/toolbars (I recommend from control panel as well) Then enter about:config and :

  1. Type “Keyword.url” in the search box. Right click it & reset it.
  2. Type “browser.search.defaultengine” in the search box. Right click it & reset it.
  3. Type “browser.search.selectedengine” in the search box. Right click it & reset it.
  4. Search for ‘browser.newtab.url’. Right-click and reset. This will make sure that the search page won’t launch on each new tab.

Question owner

The only way I could resolve it was by "Reset" Firefox.

I checked IE Registry and did find the particular hijack url info which I removed. Search of programs revealed nothing. Didn't know what to look for within Firefox Appdata directory. Suspect problem was in there.

The problem originated with upgrading extension FVD Suite from their site. CNet site was clean.