FV Firefox with private browsing

Hi everyone, I’m new to this forum and I’m quite a paranoid with internet security.

I have Win7 Enterprise x64 SP1 with:
CIS v.7.0.3.17799.4142;
Eset Nod AV v.7.0302.28 w/ updated signatures
MBAM v.1.70.0.1100 w/ updated database
Firefox 33.1 w/ AdBlock Plus 2.6.6 - AdBlock Plus Popup Addon 0.9.2 - Blur (formerly DoNotTrackMe) 4.5.1334 - NoScript 2.6.9.5

After checking a strange url (from a friend’s mail) on virustotal.com with 0/61 threats outcome, I closed my current FF session.
I’ve right-clicked the FF icon and selected “Run in Comodo Sandbox” and then I switch to private browsing.
I pasted the above-mentioned link in the address bar and I got redirected to a different site. I didn’t get any popup from ESET, CIS or MBAM so I felt safe. That confidence ended quick as soon as I checked the new url on virustotal.com because this time I got 4/61 threats outcome.
I rebooted the system and in safe mode I made a full scan with ESET, MBAM, Hitman Pro and ADWCleaner without any threat message or whatever problem.
I’m paranoid and my main fear is focused on hidden exploit. I’m used to login in each portal, every time I connect to internet but not always.
There are places I logged in checking the “remember me” options and that kind of data is stored in the FF’s profile folder.

That’s the time of my question: is it possible for a malicius site to copy or simply read the files in the Firefox’s profile folder while I’m surfing with fully virtualized Firefox (also in private browsing) without any CIS, ESET, MBAM alerts or popup messages? Is there a way to know if someone access my files when I’m sandboxed? With all the FF addons I’ve installed I should be safe or not?

Sorry for the long chat, I’m italian so forgive me if I made mistakes.
Thanks in advance.

Hi,

Could you please post the website address, and then we could test it on our local machine to check what problem happened.

Thank you very much

Hi,

Operations in sandbox are fully virtualized, so they cannot affect your system out of sandbox. They are isolated by sandbox. So don’t worry.

Thank you very much.

My bad. The friend’s mail has been trashed and when I closed FF the first time, after checking the link on Virustotal, all the browsing history was erased so I can’t give you the last part of the strange domain. I’m sure that the link I clicked was like “DaGmbh.COM is for sale | HugeDomains… sequence of letters (dot) another letters row” and when I hit enter it switched up and I’ve ended up with motherprofitwork.com.

EDIT: with the onlinelinkscan.com’s scan history, I found the original link ----> DaGmbh.COM is for sale | HugeDomains

Virustotal.com say this:

Domain Name: MOTHERPROFITWORK.COM
Registrar: TRUNKOZ TECHNOLOGIES PVT LTD. D/B/A OWNREGISTRAR.COM
Whois Server: whois.ownregistrar.com
Referral URL: http://www.ownregistrar.com
Name Server: NS1.MICROHELIXDNS.COM
Name Server: NS2.MICROHELIXDNS.COM
Name Server: NS3.MICROHELIXDNS.COM
Name Server: NS4.MICROHELIXDNS.COM
Status: clientTransferProhibited
Updated Date: 10-oct-2014
Creation Date: 10-oct-2014
Expiration Date: 10-oct-2015

Domain Name: motherprofitwork.com
Registry Domain ID:
Registrar WHOIS Server: Whois.ownregistrar.com
Registrar URL: www.ownregistrar.com
Registrar : Trunkoz Technologies Pvt Ltd. d/b/a OwnRegistrar.com
Registrar IANA ID: 1250
Registrar URL: www.ownregistrar.com
Registrar Abuse Contact Email: abuse[at]ownregistrar.com
Registrar Abuse Contact Phone : +91-22-6142 6058

Creation Date: 10-Oct-2014
Expiration Date: 10-Oct-2015

Registrant Contact Details:
Nathalie Perrault
Nathalie Perrault
19 rue des Chaligny
Nice
6300
FR
Tel No. +33.0426755088

Administrative Contact Details:
Nathalie Perrault
Nathalie Perrault
19 rue des Chaligny
Nice
6300
FR
Tel No. 33.0426755088
Email Address: miggs[at]motherprofitwork.com

Technical Contact Details:
Nathalie Perrault
Nathalie Perrault
19 rue des Chaligny
Nice
6300
FR
Tel No. +33.0426755088
Email Address: miggs[at]motherprofitwork.com

Billing Contact Details:
Nathalie Perrault
Nathalie Perrault
19 rue des Chaligny
6300
Nice
FR
Tel No. +33.0426755088
Email Address: miggs[at]motherprofitwork.com

Name Servers:
ns1.microhelixdns.com
ns2.microhelixdns.com
ns3.microhelixdns.com
ns4.microhelixdns.com

DNSSEC:Unsigned

I’m used to be super-careful with spam links but I’ve trusted a friend’s mail so I hope this won’t happen to anyone else. (at least with DaGmbh.COM is for sale | HugeDomains… domains).