Page 1 of 1

[RESOLVED] Foxydeal

Posted: Tue Jun 02, 2015 3:56 pm
by ThumperZ1
On my noscript list, foxydeal is there and won't go away. I have cleaned the registry, searched and antivirused and antimalwared the hell out of my computer, but I can't find it. It's only on the noscirpt list when I click for a website to choose what I want to run. I've tried uninstalling noscript and reinstalling it, plus I've uninstalled and installed the latest RC version. Help!

Re: Foxydeal

Posted: Tue Jun 02, 2015 5:52 pm
by barbaz
ThumperZ1 wrote:antivirused and antimalwared the hell out of my computer,
With what programs/scanners?
ThumperZ1 wrote:It's only on the noscirpt list when I click for a website to choose what I want to run.
I don't know what this means. Can you please explain it more?
(When does foxydeal *not* show up in your NoScript menu?)

Re: Foxydeal

Posted: Tue Jun 02, 2015 6:44 pm
by therube
What happens if you backup your NoScript settings, then do a (NoScript) Reset?

As a test, create a new, clean Profile.
Install only NoScript.
Is foxydeal there?


(I have no knowledge of this this site:)
How to remove FoxyDeal Ads (Virus Removal Guide)

Re: Foxydeal

Posted: Tue Jun 02, 2015 10:44 pm
by ThumperZ1
I d/l that and found nothing. MalwareBytes Pro and Windows Defender. (running windows 10) I backed up NoScript profile and reset it. Didn't help.

Then when I was looking at 'view page source" on a web site and found that my VPN was showing up in the source. I am running the pro version of OkayFreedom. I shut it down and the foxydeals is no longer there.
I don't know how they did that, but it's a good thing I never allowed it to run.

Re: Foxydeal

Posted: Tue Jun 02, 2015 10:46 pm
by barbaz
Yikes. Thanks for telling us that.
ThumperZ1 wrote:I don't know how they did that, but it's a good thing I never allowed it to run.
I don't know exactly but they could probably man-in-the-middle-attack plain HTTP pages and inject it in the client side for HTTPS pages.
And if you're paying for this VPN service then IMO they should not be giving you that kind of crap. Just hope they weren't hacked...