ATTENTION: You are viewing a page formatted for mobile devices; to view the full web page, click HERE.

Main Area and Open Discussion > General Software Discussion

Are the new Firefox versions coming with adware built in?

(1/4) > >>

superboyac:
I noticed recently that I've been getting these "coupondropdown" ads every once in a while, like so:


Before I try to blast with all the tools, I was wondering if this was built into the new firefox versions?  Because I normally never get any ads or anything, and the only changes lately have been the firefox updates.  I see them in wikipedia occasionally as well.

TaoPhoenix:
It's not clear. Before I power-bombed it with About:Config, at one point when I had the command wrong, making new tabs dropped me onto some Spanish page. It's like some weird defaults crept in there and were only hidden for so long by more powerful default behavior.

Summary: So I don't really think those ads are in FF proper, I watch Slashdot daily and that's the kind of thing they wouldn't stand for without an article. I'm more likely to believe ever sneakier BHO (Browser Helper Objects) and other stuff sneaking in there because you didn't scroll down to unclick a box when you installed something, but then you don't see it for a while because some other setting is over-riding it, until some random version of FF (see my other rant) breaks something and then the hidden ad pops up.

superboyac:
Thanks TP, I'll investigate.  Speaking of which, now you're doing it to me also?!  Cmon man, I thought we were friends!  ;D

TaoPhoenix:
Thanks TP, I'll investigate.  Speaking of which, now you're doing it to me also?!  Cmon man, I thought we were friends!  ;D
-superboyac (December 12, 2012, 10:44 PM)
--- End quote ---

Doing what to you?! There's a gender problem in that pic! That would mean not only was I kidnapped to Mexico but that I didn't even notice the results of the operation!  :o

Edit: No really, that's not basic FF, that screams malware glued itself into your browser instance. You might have a good hour of detective work ahead of you! :(

Curt:
1) http://coupondropdown.com/uninstall.php
2) http://www.onlinesafety411.com/remove-coupondropdown-com-coupondropdown-adware-browser-hijacker-malware

DIY CouponDropdown removal resources
http://www.onlinesafety411.com/remove-coupondropdown-com-coupondropdown-adware-browser-hijacker-malware

*If you are an experienced computer user, you may locate and delete the CouponDropdown files and registry entries below. The manual removal process for CouponDropdown is best performed while in Safe Mode.

CouponDropdown Files

    %LocalAppData%\CouponDropDown\
    %LocalAppData%\CouponDropDown\Chrome\
    %LocalAppData%\CouponDropDown\Chrome\CouponDropDown.crx
    %ProgramFilesX86%\CouponDropDown\
    %ProgramFilesX86%\CouponDropDown\CouponDropDown.dll
    %ProgramFilesX86%\CouponDropDown\CouponDropDown.exe
    %ProgramFilesX86%\CouponDropDown\CouponDropDown.ico
    %ProgramFilesX86%\CouponDropDown\CouponDropDown.ini
    %ProgramFilesX86%\CouponDropDown\CouponDropDownGui.exe
    %ProgramFilesX86%\CouponDropDown\CouponDropDownInstaller.log
    %ProgramFilesX86%\CouponDropDown\Uninstall.exe

CouponDropdown Registry Entries

    HKEY_CURRENT_USER\Software\AppDataLow\Software\CouponDropDown\
    HKEY_CURRENT_USER\Software\AppDataLow\Software\Crossrider
    HKEY_CURRENT_USER\Software\Cr_Installer
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0004352.BHO
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0004352.FBApi
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0004352.Sandbox
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550055435552}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660066436652}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{77777777-7777-7777-7777-770077437752}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440044434452}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11111111-1111-1111-1111-110011431152}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{22222222-2222-2222-2222-220022432252}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{33333333-3333-3333-3333-330033433352}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{55555555-5555-5555-5555-550055435552}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660066436652}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{77777777-7777-7777-7777-770077437752}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440044434452}
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{11111111-1111-1111-1111-110011431152}
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{22222222-2222-2222-2222-220022432252}
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{33333333-3333-3333-3333-330033433352}
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{55555555-5555-5555-5555-550055435552}
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{66666666-6666-6666-6666-660066436652}
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Interface\{77777777-7777-7777-7777-770077437752}
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\TypeLib\{44444444-4444-4444-4444-440044434452}
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\New Windows\Allow\*.crossrider.com
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011431152}
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\CouponDropDown
    HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110011431152}

-onlinesafety411
--- End quote ---

Navigation

[0] Message Index

[#] Next page

Go to full version