PDA

View Full Version : Manual Removal Guide for FFHijacker.ttam



Friday
2009-11-18, 17:14
The following instructions have been created to help you to get rid of "FFHijacker.ttam" manually.
Use this guide at your own risk; software should usually be better suited to remove malware, since it is able to look deeper.

If this guide was helpful to you, please consider donating towards this site (http://www.safer-networking.org/index.php?page=donate).

Threat Details:

Categories:
hijacker

Description:
Infects Mozilla Firefox and redirects Google searches.
Removal Instructions:

Files:

Please use Windows Explorer or another file manager of your choice to locate and delete these files.

The file at "<$APPDATA>\{22E139E9-7FE7-4020-BB3C-9EDC27B4201B}\chrome\content\overlay.xul".
The file at "<$APPDATA>\{BD208831-1E1E-48C6-A736-DCB948D587E1}\chrome\content\overlay.xul".
The file at "<$APPDATA>\{EFD62117-D14D-4B5A-A38F-66F2BC3BF448}\chrome\content\overlay.xul".
The file at "<$APPDATA>\{F6AC1051-CCCA-4725-ADD7-B104FAFEC2CA}\chrome\content\overlay.xul".
The file at "<$COMMONAPPDATA>\{22E139E9-7FE7-4020-BB3C-9EDC27B4201B}\chrome\content\overlay.xul".
The file at "<$COMMONAPPDATA>\{BD208831-1E1E-48C6-A736-DCB948D587E1}\chrome\content\overlay.xul".
The file at "<$COMMONAPPDATA>\{EFD62117-D14D-4B5A-A38F-66F2BC3BF448}\chrome\content\overlay.xul".
The file at "<$COMMONAPPDATA>\{F6AC1051-CCCA-4725-ADD7-B104FAFEC2CA}\chrome\content\overlay.xul".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{22E139E9-7FE7-4020-BB3C-9EDC27B4201B}\cache\cacheData.rdf".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{22E139E9-7FE7-4020-BB3C-9EDC27B4201B}\cache\default\feed".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{22E139E9-7FE7-4020-BB3C-9EDC27B4201B}\chrome.manifest".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{22E139E9-7FE7-4020-BB3C-9EDC27B4201B}\chrome\queryservice.jar".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{22E139E9-7FE7-4020-BB3C-9EDC27B4201B}\defaults\preferences\prefs.js".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{22E139E9-7FE7-4020-BB3C-9EDC27B4201B}\install.rdf".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{22E139E9-7FE7-4020-BB3C-9EDC27B4201B}\logs\ytoolbar.thu.log".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{BD208831-1E1E-48C6-A736-DCB948D587E1}\cache\cacheData.rdf".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{BD208831-1E1E-48C6-A736-DCB948D587E1}\cache\default\feed".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{BD208831-1E1E-48C6-A736-DCB948D587E1}\chrome.manifest".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{BD208831-1E1E-48C6-A736-DCB948D587E1}\chrome\queryservice.jar".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{BD208831-1E1E-48C6-A736-DCB948D587E1}\defaults\preferences\prefs.js".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{BD208831-1E1E-48C6-A736-DCB948D587E1}\install.rdf".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{BD208831-1E1E-48C6-A736-DCB948D587E1}\logs\ytoolbar.thu.log".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{EFD62117-D14D-4B5A-A38F-66F2BC3BF448}\cache\cacheData.rdf".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{EFD62117-D14D-4B5A-A38F-66F2BC3BF448}\cache\default\feed".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{EFD62117-D14D-4B5A-A38F-66F2BC3BF448}\chrome.manifest".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{EFD62117-D14D-4B5A-A38F-66F2BC3BF448}\chrome\queryservice.jar".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{EFD62117-D14D-4B5A-A38F-66F2BC3BF448}\defaults\preferences\prefs.js".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{EFD62117-D14D-4B5A-A38F-66F2BC3BF448}\install.rdf".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{EFD62117-D14D-4B5A-A38F-66F2BC3BF448}\logs\ytoolbar.thu.log".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{F6AC1051-CCCA-4725-ADD7-B104FAFEC2CA}\cache\cacheData.rdf".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{F6AC1051-CCCA-4725-ADD7-B104FAFEC2CA}\cache\default\feed".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{F6AC1051-CCCA-4725-ADD7-B104FAFEC2CA}\chrome.manifest".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{F6AC1051-CCCA-4725-ADD7-B104FAFEC2CA}\chrome\queryservice.jar".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{F6AC1051-CCCA-4725-ADD7-B104FAFEC2CA}\defaults\preferences\prefs.js".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{F6AC1051-CCCA-4725-ADD7-B104FAFEC2CA}\install.rdf".
The file at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{F6AC1051-CCCA-4725-ADD7-B104FAFEC2CA}\logs\ytoolbar.thu.log".
Make sure you set your file manager to display hidden and system files. If FFHijacker.ttam uses rootkit technologies, use our RootAlyzer (http://forums.spybot.info/downloads.php?id=8) or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).
You will have to use a global search for files without a name specified. Be extra careful, because just the name might not be enough to identify files!

Folders:

Please use Windows Explorer or another file manager of your choice to locate and delete these folders.

The directory at "<$APPDATA>\{22E139E9-7FE7-4020-BB3C-9EDC27B4201B}".
The directory at "<$APPDATA>\{BD208831-1E1E-48C6-A736-DCB948D587E1}".
The directory at "<$APPDATA>\{EFD62117-D14D-4B5A-A38F-66F2BC3BF448}".
The directory at "<$APPDATA>\{F6AC1051-CCCA-4725-ADD7-B104FAFEC2CA}".
The directory at "<$COMMONAPPDATA>\{22E139E9-7FE7-4020-BB3C-9EDC27B4201B}".
The directory at "<$COMMONAPPDATA>\{BD208831-1E1E-48C6-A736-DCB948D587E1}".
The directory at "<$COMMONAPPDATA>\{EFD62117-D14D-4B5A-A38F-66F2BC3BF448}".
The directory at "<$COMMONAPPDATA>\{F6AC1051-CCCA-4725-ADD7-B104FAFEC2CA}".
The directory at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{22E139E9-7FE7-4020-BB3C-9EDC27B4201B}\chrome".
The directory at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{22E139E9-7FE7-4020-BB3C-9EDC27B4201B}\defaults\preferences".
The directory at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{22E139E9-7FE7-4020-BB3C-9EDC27B4201B}\defaults".
The directory at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{22E139E9-7FE7-4020-BB3C-9EDC27B4201B}".
The directory at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{BD208831-1E1E-48C6-A736-DCB948D587E1}\chrome".
The directory at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{BD208831-1E1E-48C6-A736-DCB948D587E1}\defaults\preferences".
The directory at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{BD208831-1E1E-48C6-A736-DCB948D587E1}\defaults".
The directory at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{BD208831-1E1E-48C6-A736-DCB948D587E1}".
The directory at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{EFD62117-D14D-4B5A-A38F-66F2BC3BF448}\chrome".
The directory at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{EFD62117-D14D-4B5A-A38F-66F2BC3BF448}\defaults\preferences".
The directory at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{EFD62117-D14D-4B5A-A38F-66F2BC3BF448}\defaults".
The directory at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{EFD62117-D14D-4B5A-A38F-66F2BC3BF448}".
The directory at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{F6AC1051-CCCA-4725-ADD7-B104FAFEC2CA}\chrome".
The directory at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{F6AC1051-CCCA-4725-ADD7-B104FAFEC2CA}\defaults\preferences".
The directory at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{F6AC1051-CCCA-4725-ADD7-B104FAFEC2CA}\defaults".
The directory at "<$PROGRAMFILES>\Mozilla Firefox\extensions\{F6AC1051-CCCA-4725-ADD7-B104FAFEC2CA}".
Make sure you set your file manager to display hidden and system files. If FFHijacker.ttam uses rootkit technologies, use our RootAlyzer (http://forums.spybot.info/downloads.php?id=8) or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).
You will have to use a global search for files without a name specified. Be extra careful, because just the name might not be enough to identify folders!

Registry:

You can use regedit.exe (included in Windows) to locate and delete these registry entries.

Delete the registry value "{22E139E9-7FE7-4020-BB3C-9EDC27B4201B}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions\".
Delete the registry value "{BD208831-1E1E-48C6-A736-DCB948D587E1}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions\".
Delete the registry value "{EFD62117-D14D-4B5A-A38F-66F2BC3BF448}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions\".
Delete the registry value "{F6AC1051-CCCA-4725-ADD7-B104FAFEC2CA}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions\".
If FFHijacker.ttam uses rootkit technologies, use our RegAlyzer (http://www.safer-networking.org/index.php?page=regalyzer), RootAlyzer (http://forums.spybot.info/downloads.php?id=8) or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).

Final Words:

If neither Spybot-S&D nor self help did resolve the issue or you would prefer one on one help,
Please read these instructions (http://forums.spybot.info/showthread.php?t=288) before requesting assistance,
Then start your own thread in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22) where a volunteer analyst will advise you as soon as available.