Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

firefox files flagged by malwarebytes as a problem

  • 3 replies
  • 1 has this problem
  • 16 views
  • Last reply by cor-el

more options

Lately Malwarebytes is flagging firefox files for quarantine. I get messages like these daily now when I never saw any in the past many years of using Firefox and Malwarebytes.

PUP.Optional.DefaultSearch, C:\USERS\LNERE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BH0PRP7I.DEFAULT-RELEASE\PREFS.JS, No Action By User, 330, 932426, 1.0.39845, , ame, , 298C1EFCC1B7E44E4B7FEF6B0A790457, E4B41F7AB9BEE2D2A4FC8EB93718CC35F6F70DBCF08B84F65ED2E5C4A56A7BEB

PUP.Optional.DefaultSearch, C:\USERS\LNERE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BH0PRP7I.DEFAULT-RELEASE\PREFS.JS, No Action By User, 330, 932427, 1.0.39845, , ame, , 298C1EFCC1B7E44E4B7FEF6B0A790457, E4B41F7AB9BEE2D2A4FC8EB93718CC35F6F70DBCF08B84F65ED2E5C4A56A7BEB

Lately Malwarebytes is flagging firefox files for quarantine. I get messages like these daily now when I never saw any in the past many years of using Firefox and Malwarebytes. PUP.Optional.DefaultSearch, C:\USERS\LNERE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BH0PRP7I.DEFAULT-RELEASE\PREFS.JS, No Action By User, 330, 932426, 1.0.39845, , ame, , 298C1EFCC1B7E44E4B7FEF6B0A790457, E4B41F7AB9BEE2D2A4FC8EB93718CC35F6F70DBCF08B84F65ED2E5C4A56A7BEB PUP.Optional.DefaultSearch, C:\USERS\LNERE\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\BH0PRP7I.DEFAULT-RELEASE\PREFS.JS, No Action By User, 330, 932427, 1.0.39845, , ame, , 298C1EFCC1B7E44E4B7FEF6B0A790457, E4B41F7AB9BEE2D2A4FC8EB93718CC35F6F70DBCF08B84F65ED2E5C4A56A7BEB

All Replies (3)

more options

The PREFS.JS file contains user options and settings.

Something in the file is causing the problem. Do the error messages say anything else?


Use these links to create a new profile. Use this new profile as is. Is the problem still there?

https://support.mozilla.org/en-US/kb/how-run-firefox-when-profile-missing-inaccessible

http://kb.mozillazine.org/Profile_folder_-_Firefox#Navigating_to_the_profile_folder

https://support.mozilla.org/en-US/kb/profile-manager-create-and-remove-firefox-profiles

https://support.mozilla.org/en-US/kb/back-and-restore-information-firefox-profiles


Type about:profiles<enter> in the address bar.

more options

what you see above is exactly what MBAM reports which I am able to save to a TXT file. This is what I received on Saturday:

Malware.AI.3173362979, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{AAFA1E73-4842-4BEC-BC46-48C62E1C5C9C}, No Action By User, 1000000, 0, , , , , , Malware.AI.3173362979, HKLM\SOFTWARE\CLASSES\NCTAudioInformation2.AudioInformation2, No Action By User, 1000000, 0, , , , , , Malware.AI.3173362979, HKLM\SOFTWARE\CLASSES\NCTAudioInformation2.AudioInformation2.2, No Action By User, 1000000, 0, , , , , , Malware.AI.3173362979, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{AAFA1E73-4842-4BEC-BC46-48C62E1C5C9C}, No Action By User, 1000000, 0, , , , , , Malware.AI.3173362979, HKLM\SOFTWARE\CLASSES\TYPELIB\{5C63D23E-0132-43CA-9FE3-908E0FD3A4C0}, No Action By User, 1000000, 0, , , , , , Malware.AI.3173362979, HKLM\SOFTWARE\CLASSES\INTERFACE\{F31A1156-1CC0-4130-9FCB-B69116480C93}, No Action By User, 1000000, 0, , , , , , Malware.AI.3173362979, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{F31A1156-1CC0-4130-9FCB-B69116480C93}, No Action By User, 1000000, 0, , , , , , Malware.AI.3173362979, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F31A1156-1CC0-4130-9FCB-B69116480C93}, No Action By User, 1000000, 0, , , , , , Malware.AI.3173362979, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{5C63D23E-0132-43CA-9FE3-908E0FD3A4C0}, No Action By User, 1000000, 0, , , , , , Malware.AI.3173362979, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{5C63D23E-0132-43CA-9FE3-908E0FD3A4C0}, No Action By User, 1000000, 0, , , , , , Malware.AI.3173362979, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{AAFA1E73-4842-4BEC-BC46-48C62E1C5C9C}\InprocServer32, No Action By User, 1000000, 0, , , , , , Malware.AI.3173362979, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{AAFA1E73-4842-4BEC-BC46-48C62E1C5C9C}\InprocServer32, No Action By User, 1000000, 0, , , , , ,

more options

You will have to contact Malwarebytes for support if you have a question about their software. Like posted above, prefs.js only contains custom settings and shouldn't be a threat (i.e. it is a data file and not an active file).

Note that usually best is to exclude the Firefox profile folder from scanning by security software as this only gives issues and can lead to data loss or data corruption.