all of a sudden when i click any button or link a new window opens with an ad
I have used Firefox for about 7 years. No issues... I recently installed Ghostery add on.
The only way to describe it is: I go to a page.. Click a link (or close to it) or enter or any other button/link that would take me to what I expect..
BUT instead it opens a new tab to an advertisement site (quibids, P&G, many other random ads) - a few of them I blacklisted with BLOCKSITE (installed after the problem started happening) but several I can't because I would actually use them when I need to (ex: Vistaprint.com)
When I go back to the original site and click the same link and click it again it works as intended. This happens across all sites that I am on... It is like there is a hidden link within the one I am clicking on. I have pop ups blocked in my browser but this gets around it somehow.
Since GHOSTERY installed, some sites do not work correctly. If I click on a picture, or something that I want to expand it is as if I am doing nothing at all because it won't complete the action, the functionality is broken.
I have white listed a couple sites but this is random and if I whitelist everything I come across then it opens me back to what I am trying to avoid..
EXAMPLES:
went on Heat.com, clicked the button to go to the White Hot Gear instead it opened a new tab brandonline.com
was on LinkedIn and hit the comment button on a thread, then it opened a new tab vistaprint.com
was on publix.com, hit the order refills button, then it opened a new tab premium-promos.net
did a google search clicked on the link I wanted, it opened a new tab premiumgiftrewards.net
EACH time I go back to the original site and click the same button/link/etc it takes me where expected.
Thanks in advance for your help!
Tất cả các câu trả lời (7)
hello, this sounds like a problem possibly caused by adware on your pc. please go to firefox > addons > extensions & remove any suspicious entries (toolbars, things that you have not installed intentionally, don't know what purpose they serve, etc). also go to the windows control panel / programs and remove all toolbars or potentially unwanted software from there and run a full scan of your system with the security software that you have in place and different other tools like the free version of malwarebytes & adwcleaner.
Remove a toolbar that has taken over your Firefox search or home page Troubleshoot Firefox issues caused by malware
I only have: Blocksite Ghostery Norton Toolbar Norton Vulnerability Firefox troubleshooter
Ran AWCleaner and got this:
- AdwCleaner v2.300 - Logfile created 05/14/2013 at 10:54:43
- Updated 28/04/2013 by Xplode
- Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
- User : Sales - LISAERICKSON
- Boot Mode : Normal
- Running from : C:\Users\Sales\Downloads\AdwCleaner.exe
- Option [Search]
- [Services] *****
- [Files / Folders] *****
File Found : C:\END File Found : C:\user.js File Found : C:\Users\Sales\AppData\Roaming\Mozilla\Firefox\Profiles\htsogrrd.default\searchplugins\safesearch.xml Folder Found : C:\Program Files (x86)\Ask.com Folder Found : C:\Program Files (x86)\Conduit Folder Found : C:\ProgramData\Ask Folder Found : C:\ProgramData\AVG Security Toolbar Folder Found : C:\ProgramData\Babylon Folder Found : C:\ProgramData\Partner Folder Found : C:\Users\Sales\AppData\Local\Babylon Folder Found : C:\Users\Sales\AppData\Local\Conduit Folder Found : C:\Users\Sales\AppData\LocalLow\AskToolbar Folder Found : C:\Users\Sales\AppData\LocalLow\AVG Security Toolbar Folder Found : C:\Users\Sales\AppData\LocalLow\Conduit Folder Found : C:\Users\Sales\AppData\LocalLow\PriceGong Folder Found : C:\Users\Sales\AppData\Roaming\Babylon
- [Registry] *****
Key Found : HKCU\Software\APN Key Found : HKCU\Software\AppDataLow\Software\AVG Security Toolbar Key Found : HKCU\Software\AppDataLow\Software\Conduit Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Key Found : HKCU\Software\AppDataLow\Software\PriceGong Key Found : HKCU\Software\AppDataLow\Software\SmartBar Key Found : HKCU\Software\AVG Security Toolbar Key Found : HKCU\Software\Conduit Key Found : HKCU\Software\ilivid Key Found : HKCU\Software\InstallCore Key Found : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Key Found : HKLM\Software\APN Key Found : HKLM\Software\AskToolbar Key Found : HKLM\Software\AVG Security Toolbar Key Found : HKLM\Software\Babylon Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Found : HKLM\SOFTWARE\Classes\AppID\PropertySync.EXE Key Found : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe Key Found : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr Key Found : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1 Key Found : HKLM\SOFTWARE\Classes\Prod.cap Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3298573 Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Found : HKLM\Software\Conduit Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Key Found : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\aaaaojmikegpiepcfdkkjaplodkpfmlo Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Found : HKLM\SOFTWARE\Classes\Interface\{2263BE11-ACB7-49D9-8313-6B1D5CC42FAA} Key Found : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991} Key Found : HKLM\SOFTWARE\Classes\Interface\{97FC5555-8BDC-40EA-8DE2-B1E46B9EA629} Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Found : HKLM\SOFTWARE\Software Value Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [ApnUpdater]
- [Internet Browsers] *****
-\\ Internet Explorer v10.0.9200.16537
[OK] Registry is clean.
-\\ Mozilla Firefox v14.0.1 (en-US)
File : C:\Users\Sales\AppData\Roaming\Mozilla\Firefox\Profiles\htsogrrd.default\prefs.js
Found : user_pref("CT3298573_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\"[...] Found : user_pref("Smartbar.ConduitHomepagesList", ""); Found : user_pref("Smartbar.ConduitSearchEngineList", ""); Found : user_pref("Smartbar.ConduitSearchUrlList", ""); Found : user_pref("Smartbar.SearchFromAddressBarSavedUrl", ""); Found : user_pref("Smartbar.keywordURLSelectedCTID", "CT3298573"); Found : user_pref("browser.search.defaultengine", "Ask.com"); Found : user_pref("browser.search.defaultenginename", "Ask.com"); Found : user_pref("browser.search.defaultthis.engineName", "MixiDJ V37 Customized Web Search"); Found : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3298573&CUI[...] Found : user_pref("browser.search.order.1", "Ask.com"); Found : user_pref("browser.startup.homepage", "hxxps://www.facebook.com/index.php?stype=lo&jlou=Afet3S-nQyNl[...] Found : user_pref("extensions.BabylonToolbar_i.aflt", "babsst"); Found : user_pref("extensions.BabylonToolbar_i.babExt", ""); Found : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=109935"); Found : user_pref("extensions.BabylonToolbar_i.hardId", "7c0e931b00000000000000266c526ccc"); Found : user_pref("extensions.BabylonToolbar_i.id", "7c0e931b00000000000000266c526ccc"); Found : user_pref("extensions.BabylonToolbar_i.instlDay", "15451"); Found : user_pref("extensions.BabylonToolbar_i.instlRef", "sst"); Found : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar"); Found : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon"); Found : user_pref("extensions.BabylonToolbar_i.smplGrp", "none"); Found : user_pref("extensions.BabylonToolbar_i.srcExt", "ss"); Found : user_pref("extensions.BabylonToolbar_i.tlbrId", "tb9"); Found : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17"); Found : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1719:52:03"); Found : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17"); Found : user_pref("extensions.asktb.ff-original-keyword-url", "hxxp://search.conduit.com/ResultsExt.aspx?cti[...] Found : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3298573&SearchSource=2&CU[...] Found : user_pref("smartbar.machineId", "TGDXM3SV7HJOWDIIQ8DPQSD3GE6/6XBNB7EB6JXB2LJL1OQDFWXUOZHGBQZXIS1NL7I[...]
AdwCleaner[R1].txt - [6849 octets] - [14/05/2013 10:54:43]
- EOF - C:\AdwCleaner[R1].txt - [6909 octets] ##########
BTW-I ran a deep scan on malwarebytes last night and got nothing. I then ran deep scan in Norton and nothing...
could you go to firefox > help > troubleshooting information, copy the contents of that page and paste them here into a reply on the forum? maybe this might give us some other clue what is going on...
Application Basics
Name Firefox
Version 20.0.1
User Agent Mozilla/5.0 (Windows NT 6.1; WOW64; rv:20.0) Gecko/20100101 Firefox/20.0
Build Configuration
about:buildconfig
Extensions
Name
Version
Enabled
ID
BlockSite 0.7.1.1 true {dd3d7613-0246-469d-bc65-2a3cc1668adc}
Ghostery 2.9.4 true firefox@ghostery.com
Norton Toolbar 2013.3.5.1 true {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}
Norton Vulnerability Protection 11.3.0.9 - 5 true {BBDA0591-3099-440a-AA10-41764D9DB4DB}
Troubleshooter 1.1a true troubleshooter@mozilla.org
Unfriend Finder 42.220 true firefox@unfriendfinder.com
DownloadTerms 1.0 false jmwgabsbmtxairm@wzcttjml.com
Important Modified Preferences
Name
Value
accessibility.blockautorefresh true
accessibility.typeaheadfind.flashBar 0
browser.cache.disk.capacity 358400
browser.cache.disk.smart_size.first_run false
browser.cache.disk.smart_size.use_old_max false
browser.cache.disk.smart_size_cached_value 358400
browser.places.smartBookmarksVersion 4
browser.search.useDBForOrder true
browser.startup.homepage https://www.facebook.com/index.php?stype=lo&jlou=Afet3S-nQyNlUktQjcB7G9Hpxm0mjqCq3N2jW9j0T8wX05hivAETc1Qyk6BXqRP30SRJUcr
browser.startup.homepage_override.buildID 20130409194949
browser.startup.homepage_override.mstone 20.0.1
dom.mozApps.used true
dom.w3c_touch_events.expose false
extensions.lastAppVersion 20.0.1
font.minimum-size.x-western 14
font.name.monospace.x-western Courier
font.name.serif.x-western Kartika
font.size.fixed.x-western 14
keyword.URL http://search.conduit.com/ResultsExt.aspx?ctid=CT3298573&SearchSource=2&CUI=UN31376034466619377&UM=2&q=
network.cookie.prefsMigrated true
places.database.lastMaintenance 1368306297
places.history.expiration.transient_current_max_pages 103914
plugin.disable_full_page_plugin_for_types application/pdf
privacy.donottrackheader.enabled true
privacy.sanitize.migrateFx3Prefs true
privacy.sanitize.timeSpan 0
user.js Preferences
Your profile folder contains a
user.js file, which includes preferences that were not created by Firefox.
Graphics
Adapter Description Mobile Intel(R) 4 Series Express Chipset Family
Adapter Drivers igdumd64 igd10umd64 igdumdx32 igd10umd32
Adapter RAM Unknown
ClearType Parameters Gamma: 2200 Pixel Structure: RGB ClearType Level: 100 Enhanced Contrast: 400
Device ID 0x2a42
Direct2D Enabled Blocked for your graphics driver version. Try updating your graphics driver to version 8.1500.1000.2202 or newer.
DirectWrite Enabled false (6.2.9200.16492)
Driver Date 2-20-2010
Driver Version 8.15.10.2086
GPU #2 Active false
GPU Accelerated Windows 1/1 Direct3D 9
Vendor ID 0x8086
WebGL Renderer Google Inc. -- ANGLE (Mobile Intel(R) 4 Series Express Chipset Family)
AzureCanvasBackend cairo
AzureContentBackend none
AzureFallbackCanvasBackend none
JavaScript
Incremental GC true
Accessibility
Activated false
Prevent Accessibility 0
Library Versions
Expected minimum version
Version in use
NSPR 4.9.5 4.9.5
NSS 3.14.3.0 Basic ECC 3.14.3.0 Basic ECC
NSSSMIME 3.14.3.0 Basic ECC 3.14.3.0 Basic ECC
NSSSSL 3.14.3.0 Basic ECC 3.14.3.0 Basic ECC
NSSUTIL 3.14.3.0 3.14.3.0
ok, the downloadterms extension is malicious but already disabled so it shouldn't cause this issue directly any more (if you are able to remove it, please do so nevertheless).
the blocksite addon has gotten some negative reviews recently, so you might also want to disable it.
in addition go to firefox > help > troubleshooting information, click on profile folder/show folder and close all firefox windows afterwards. a windows explorer window should open up - in there delete the file named user.js - it is used to overwrite your preferences and shouldn't exist if you haven't created it manually in the first place.
Both Firefox and IE have the same problem. The cursor instead of being a finger when pointing to a link is still an arrow. However I can click anywhere on the page and an ad will pop up. I have eliminated all unwanted bars in Firefox, I ran Malwarebytes until it came out clean. I also have AVG which had detected a few items on it's own. But when I get into Firefox I still have exactly the same problem. Now it will not let me download Browser Safeguard. Usually after one click the pointer returns to normal for a few screens. When I try to click to download Browser Safeguard it keeps bringing up different ads or it tries to get me to upgrade Firefox or some other browser helper program which I know are all BS tactics to get me to load their junk again. PLease help I'm an engineer and pretty good with PCs but this one has me beat at least so far.