Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Hotlean.com redirect from google search page [Solved]


  • This topic is locked This topic is locked

#16
megadez

megadez

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 119 posts
quick scan by malwarebytes came out clean,here it is, I'm also doing full one, kaspersky is in the progress, to be posted

one sure positive thing! is i haven't had hotlean.com redirect since you have worked on the machine, but mozilla crashes and

inconveniences with downloads still persists

Malwarebytes' Anti-Malware 1.34
Database version: 1757
Windows 5.1.2600 Service Pack 3

2/13/2009 8:10:39 AM
mbam-log-2009-02-13 (08-10-39).txt

Scan type: Quick Scan
Objects scanned: 70357
Time elapsed: 45 minute(s), 31 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
  • 0

Advertisements


#17
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

but mozilla crashes and inconveniences with downloads still persists


Hmm...that Firefox did have a corrupt file in there which I had hoped we had fixed when we ran that Combofix script.

Lets have a look at the Kaspersky scan first and then have another look at Firefox after that if necessary. :)
  • 0

#18
megadez

megadez

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 119 posts
Here is Kaspersky report:

I had one hotlean.com redirect during the scan, but maybe it has to do with the fact that my antivirus had to be switched of during the Kaspersky scan.
What do you say?

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Friday, February 13, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, February 13, 2009 13:24:04
Records in database: 1792334
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
H:\

Scan statistics:
Files scanned: 256283
Threat name: 9
Infected objects: 10
Suspicious objects: 0
Duration of the scan: 08:57:19


File name / Threat name / Threats count
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\06200000\4F7CF22C.VBN Infected: Trojan.Win32.Inject.ock 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\0D3C0000\4DBF2209.VBN Infected: Trojan.Win32.Agent.blis 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\0D3C0001\4DBF23D0.VBN Infected: Trojan-Dropper.Win32.Small.cpw 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\0D3C0002\4DBF2489.VBN Infected: Trojan.Win32.Agent2.axc 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\0D3C0003\4DBF248A.VBN Infected: Trojan-Dropper.Win32.Small.cpw 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\0D3C0004\4DBF248D.VBN Infected: Trojan-Downloader.Win32.Agent.bfbm 1
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec Endpoint Protection\Quarantine\0D3C0005\4DBF248F.VBN Infected: Worm.Win32.AutoTDSS.bie 1
C:\Program Files\CrossLoop\VNCHooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b 1
C:\Program Files\CrossLoop\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.h 1
F:\Software\Intel.Visual.Fortran.Compiler.v10.1.014.EM64T-TBE\w_fc_p_10.1.014_intel64.exe Infected: Trojan-Dropper.Win32.Agent.ehc 1

The selected area was scanned.
  • 0

#19
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

I had one hotlean.com redirect during the scan, but maybe it has to do with the fact that my antivirus had to be switched of during the Kaspersky scan.
What do you say?


I think we haven't got to the root of the problem yet.

Couple of questions now: Most of those found be Kaspersky were in you anti-virus quarantine and can't hurt your machine but there were three others.

Two of them relate to RealVNC Ltd and safe but it can also be a threat as outlined by the Kaspersky description in the log. My question is do you recognise them and do you need those files?

The second question relates to a torrent download that Kaspersky has identified as an infection. Do you know about this file F:\Software\Intel.Visual.Fortran.Compiler.v10.1.014.EM64T-TBE\w_fc_p_10.1.014_intel64.exe if not we will delete it at next post?

Now

Please download GooredFix and save it to your Desktop. Double-click Goored.exe to run it. Select 1. Find Goored (no fix) by typing 1 and pressing Enter. A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called Goored.txt). Note: Do not run Option #2 yet.
  • 0

#20
megadez

megadez

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 119 posts
I recognized those 2 entries which were considered to be innocent. I unistalled the program they are part of, I can do without it.

I also recognize F:\Software\Intel.Visual.Fortran.Compiler.v10.1.014.EM64T-TBE\w_fc_p_10.1.014_intel64.exe

and can do without it, it's not installed even. I'm not deleting it my way, waiting for your instruction, don't want to screw anything.

Here is GooredFix

GooredFix v1.91 by jpshortstuff
Log created at 18:18 on 13/02/2009 running Option #1 (Yuriy Horokhivskyy)
Firefox version 3.0.6 (en-US)

=====Suspect Goored Entries=====

=====Dumping Registry Values=====

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.6\extensions]
"Plugins"="C:\Program Files\Mozilla Firefox\plugins"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.6\extensions]
"Components"="C:\Program Files\Mozilla Firefox\components"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"[email protected]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff"

[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\"
  • 0

#21
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :processes
    explorer.exe
    
    :files
    C:\Program Files\CrossLoop
    F:\Software\Intel.Visual.Fortran.Compiler.v10.1.014.EM64T-TBE\w_fc_p_10.1.014_intel64.exe
    
    :commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Next

Download FoxScan to your desktop.
  • Run the FoxScan file.
  • A window will open up and give you an option for what language to use. Press 2 and then Enter, let the program run unhindered.
  • The message Press any key to continue... will appear, do what it says and press any key you want.
  • The program will then open its report in a Notepad file, it will also be saved to your C:\ drive.
  • Post this log on the forum.
So when you return please post
  • OTMoveIt3 log
  • Foxscan report

  • 0

#22
megadez

megadez

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 119 posts
I must say that I unistalled crossloop (program responsible for two "innocent" infections found by Kaspersky) before doing what you said in the previous post, I unistalled using CCleaner.

OTmovit prompted me to reboot, I did that.


========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
File/Folder C:\Program Files\CrossLoop not found.
F:\Software\Intel.Visual.Fortran.Compiler.v10.1.014.EM64T-TBE\w_fc_p_10.1.014_intel64.exe moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\A9R6FAA.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\A9R6FAB.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\A9R6FAC.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\A9R6FAD.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\A9R6FAE.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\A9RCACA.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\alm.log scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\amt.log scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\etilqs_WqGOD5yczbtWl2kXuQDj scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\Perflib_Perfdata_10ac.dat scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\Perflib_Perfdata_e20.dat scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\~DFFCB8.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_420.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Yuriy Horokhivskyy\Local Settings\Application Data\Mozilla\Firefox\Profiles\bjbfibwr.default\Cache\BCF065F2d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Yuriy Horokhivskyy\Local Settings\Application Data\Mozilla\Firefox\Profiles\bjbfibwr.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Yuriy Horokhivskyy\Local Settings\Application Data\Mozilla\Firefox\Profiles\bjbfibwr.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Yuriy Horokhivskyy\Local Settings\Application Data\Mozilla\Firefox\Profiles\bjbfibwr.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Yuriy Horokhivskyy\Local Settings\Application Data\Mozilla\Firefox\Profiles\bjbfibwr.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Yuriy Horokhivskyy\Local Settings\Application Data\Mozilla\Firefox\Profiles\bjbfibwr.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Yuriy Horokhivskyy\Local Settings\Application Data\Mozilla\Firefox\Profiles\bjbfibwr.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Opera cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02132009_185550

Files moved on Reboot...
File C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\A9R6FAA.tmp not found!
File C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\A9R6FAB.tmp not found!
File C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\A9R6FAC.tmp not found!
File C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\A9R6FAD.tmp not found!
File C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\A9R6FAE.tmp not found!
File C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\A9RCACA.tmp not found!
C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\alm.log moved successfully.
C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\amt.log moved successfully.
File C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\etilqs_WqGOD5yczbtWl2kXuQDj not found!
File C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\Perflib_Perfdata_10ac.dat not found!
File C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\Perflib_Perfdata_e20.dat not found!
C:\DOCUME~1\YURIYH~1\LOCALS~1\Temp\~DFFCB8.tmp moved successfully.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\Perflib_Perfdata_420.dat not found!
File C:\Documents and Settings\Yuriy Horokhivskyy\Local Settings\Application Data\Mozilla\Firefox\Profiles\bjbfibwr.default\Cache\BCF065F2d01 not found!
C:\Documents and Settings\Yuriy Horokhivskyy\Local Settings\Application Data\Mozilla\Firefox\Profiles\bjbfibwr.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Yuriy Horokhivskyy\Local Settings\Application Data\Mozilla\Firefox\Profiles\bjbfibwr.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Yuriy Horokhivskyy\Local Settings\Application Data\Mozilla\Firefox\Profiles\bjbfibwr.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Yuriy Horokhivskyy\Local Settings\Application Data\Mozilla\Firefox\Profiles\bjbfibwr.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Yuriy Horokhivskyy\Local Settings\Application Data\Mozilla\Firefox\Profiles\bjbfibwr.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Yuriy Horokhivskyy\Local Settings\Application Data\Mozilla\Firefox\Profiles\bjbfibwr.default\XUL.mfl moved successfully.






FoxScan Version 1.0.5
Written by Loup blanc - Zebulon.fr
Scan started Fri 02/13/2009 at 19:20:18.32


Microsoft Windows XP [Version 5.1.2600]
Service Pack 3

Mozilla Firefox version : 3.0.6 (en-US)
Installation folder : C:\Program Files\Mozilla Firefox

Profil name : default
Profil folder : C:\Documents and Settings\Yuriy Horokhivskyy\Application Data\mozilla\firefox\Profiles\bjbfibwr.default\

------------------------------------------------------


//////////// Add-on \\\\\\\\\\\\\
======= Profil name : default =======

Installation notification for Add-on is enabled

Name : Forecastfox
State : Activated
Folder : C:\Documents and Settings\Yuriy Horokhivskyy\Application Data\Mozilla\Firefox\Profiles\bjbfibwr.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}

Name : Google Toolbar for Firefox
State : Activated
Folder : C:\Documents and Settings\Yuriy Horokhivskyy\Application Data\Mozilla\Firefox\Profiles\bjbfibwr.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}

Name : Java Quick Starter
State : Activated
Folder : C:\Program Files\Java\jre6\lib\deploy\jqs\ff

Name : Microsoft .NET Framework Assistant
State : Activated
Folder : C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension

Name : Tab Mix Plus
State : Activated
Folder : C:\Documents and Settings\Yuriy Horokhivskyy\Application Data\Mozilla\Firefox\Profiles\bjbfibwr.default\extensions\{dc572301-7619-498c-a57d-39143191b318}

Name : Chromifox
State : Activated
Folder : C:\Documents and Settings\Yuriy Horokhivskyy\Application Data\Mozilla\Firefox\Profiles\bjbfibwr.default\extensions\[email protected]

Name : Default
State : Activated
Folder : C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}



------------------------------------------------------



//////////// Search plugins \\\\\\\\\\\\\
======= Profil name : default =======

Search in "prefs.js" :

browser.search.defaultenginename : ""

browser.search.defaulturl : ""

browser.search.selectedEngine : ""

keyword.URL : "about:neterror?e=query&u="


--------- Search engines found ------------
+ Search form configured for the engine


C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml
template="http://www.amazon.co...ernal-search/">


C:\Program Files\Mozilla Firefox\searchplugins\answers.xml
template="http://www.answers.c.../main/ntquery">


C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.xml
template="http://search.creati...ecommons.org/">


C:\Program Files\Mozilla Firefox\searchplugins\eBay.xml
template="http://rover.ebay.co...294-18009-3/4">


C:\Program Files\Mozilla Firefox\searchplugins\google.xml
template="http://www.google.com/search">


C:\Program Files\Mozilla Firefox\searchplugins\wikipedia.xml
template="http://en.wikipedia....pecial:Search">


C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml
template="http://search.yahoo....oo.com/search">


------------------------------------------------------


//////////// DLL found in C:\Program Files\Mozilla Firefox\components \\\\\\\\\\\\\

browserdirprovider.dll
brwsrcmp.dll

------------------------------------------------------

//////////// Plugins set in registry \\\\\\\\\\\\\


[HKEY_LOCAL_MACHINE\software\mozillaplugins\@adobe.com/FlashPlayer]
"Description"="Adobe® Flash® Player 10"
"Vendor"="Adobe Systems Incorporated"
"Path"="C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll"

[HKEY_LOCAL_MACHINE\software\mozillaplugins\@google.com/npPicasa3,version=3.0.0]
"Description"="Picasa3 plugin"
"Vendor"="Google, Inc."
"Path"="C:\Program Files\Google\Picasa3\npPicasa3.dll"

[HKEY_LOCAL_MACHINE\software\mozillaplugins\@microsoft.com/WPF,version=3.5]
"Description"="Windows Presentation Foundation plug-in for Mozilla browsers"
"Vendor"="Microsoft Corp."
"Path"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll"

[HKEY_CURRENT_USER\software\mozillaplugins\@talk.google.com/GoogleTalkPlugin]
"Description"="Google Talk Plugin"
"Vendor"="Google"
"Path"="C:\Documents and Settings\Yuriy Horokhivskyy\Application Data\Mozilla\plugins\npgoogletalk.dll"

[HKEY_CURRENT_USER\software\mozillaplugins\@tools.google.com/Google Update;version=7]
"Description"="Google Update"
"Vendor"="Google"
"Path"="C:\Documents and Settings\Yuriy Horokhivskyy\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll"

------------------------------------------------------

//////////// Additional search for infections Goored, YoogSearch... \\\\\\\\\\\\\


[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" ==== Goored infection possible ====
Contents of folder :
C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\chrome
C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\chrome.manifest
C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\defaults
C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\install.rdf
C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\chrome\chrome.jar
C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\defaults\preferences
C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\defaults\preferences\defaults.js




[HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.6\extensions]


------------------ End of report ------------------
  • 0

#23
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Hello megadez,

In Firefox location bar (address bar) type about:config and press Enter to display the list of preferences, as shown below in Firefox 3.

Posted Image

On the left hand side you will see Preference Name

  • scroll down untill you find Keyword.URL
  • If it is not set as default under the heading Status right click and click Reset
Next

Please go to the link below for instructions on how to remove the Microsoft add-on extension that has been put on your Firefox.

This add-on is said to provide click-once support for Firefox and also will report back to whatever web server is asking the latest version of .NET that you're using.

http://polygon89.wor...t-from-firefox/

After that come back and tell me if there has been any change.
  • 0

#24
megadez

megadez

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 119 posts
I did all that. One question. The article you referred me to mentions that the new issue (.NET) is brought about by new windows updates.
Should I now be careful when updating windows?

Now, the problem with downloads in firefox is solved, I can freely choose prespecified folder for downloads or choose where to download files every time,
it works.

Opera is still freaking - I can't download files, only open. Also, in the preference section where you can choose the prespecified folder for downloads, when I click on the button to change that folder nothing happens, I can't do both - change the folder and download to the folder which is currently specified.

I'll now reboot my computer and get back to you with new browsing and downloading reports.

Thanks a lot.
  • 0

#25
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Hello again megadez,

Should I now be careful when updating windows?


No of course not. I think that Microsoft were doing what they thought would help things. Unfortunately sometimes these things don't work the way you think they will.

Microsoft are providing updates that help with the better running of your system and attending to security issues. Very important to keep up to date with these.

Opera is still freaking - I can't download files, only open. Also, in the preference section where you can choose the prespecified folder for downloads, when I click on the button to change that folder nothing happens, I can't do both - change the folder and download to the folder which is currently specified.


I will need to carry out some research on this. I will wait though for your report on computer performance. Meantime a question, have you tried re-installing Opera?

I'll now reboot my computer and get back to you with new browsing and downloading reports.


Okie dokie. Look forward to hearing about how your computer is performing now. :)
  • 0

Advertisements


#26
megadez

megadez

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 119 posts
Ok, I reinstalled Opera, no problems with downloads in Mozilla or Opera whatsoever.

But, occasional hotlean.com redirects and Mozilla crashes are back :)
  • 0

#27
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Hmm...I think that problem went away after we carried out those actions at post # 23.

I wonder whether that setting in Firefox came back after you closed and re-opened it again.

Lets check that out. Try that first instruction at post 23 again and tell me if our suspicions were right.
  • 0

#28
megadez

megadez

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 119 posts
Yes, that setting came back and I reset it again.
  • 0

#29
megadez

megadez

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 119 posts
everytime I restart firefox that setting Keyword.url comes back to user set, not default.
  • 0

#30
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

everytime I restart firefox that setting Keyword.url comes back to user set, not default.


Lets try it again but this time I have added in a change to the Keyword immediately below Keyword.URL.

See if that does the trick.

In Firefox location bar (address bar) type about:config and press Enter to display the list of preferences, as shown below in Firefox 3.

Posted Image

On the left hand side you will see Preference Name

  • scroll down untill you find Keyword.URL
  • If it is not set as default under the heading Status right click and click Reset
  • immediately below Keyword.URL check that Keyword.enabled is set to true under the heading Value. If it is not, double-click on it to set it to true.
Note that some preferences will require a restart for the change to take effect.

Come back and tell me if that has changed anything.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP