Ads/Script redirecting to Virus site?


Recommended Posts

2nd time this has happened to me now. I use inprivate mode at work so i'm not logged in but i'm on the neowin main page then start getting redirected to other site to land at:

 

post-698-0-85235300-1373561494.png

 

WARNING: Don't be a smarty and go to site below: :punch:

http://usdppvs.myftp.biz/index.php?....................... etc

 

I don't know if it's the same site as last time but it was the same fake Security Essentials thing.

 

It's only happened when not logged in so i'm guessing guests haven't been able to report it.

Link to comment
https://www.neowin.net/forum/topic/1164064-adsscript-redirecting-to-virus-site/
Share on other sites

Yes, I am not the only one that has seen the fake Security Essentials windows a few times now when I come to Neowin.  It seems like a bad advert in the rotation I am guessing and the link is different each time. 

 

Warning to not go to the link below!!

 

"http://thpfbez.myftp.biz/index.php?c=RaENOjEayDF925cOxP3ACC60zajgAjCTlcK0liAaKtvKheVQzm+YhzfWz1MPnw1S6zBdyf5PIpX2zaZzWwL95qmKyoM="

 

 

And this happens while I am logged in.

this is what i usually do if i get infected.

 

Malwarbytes

http://www.malwarebytes.org/

 

if you dont have it, download, install, update and then do a full system scan.

 

then once i have used my antivirus to scan (which takes about 2 days, since i have a huge amount of data and space!) and done a malware scan, i then use one or more of these:

 

(these are all online scanners, so do not require you to remove your existing antivirus software)

 

Trendmacro Housecall

http://housecall.trendmicro.com

 

panda active scan

http://www.pandasecurity.com/activescan/index/

 

Bit Defender

http://www.bitdefender.co.uk/scanner/online/free.html

 

Eset online scanner

http://www.eset.com/us/online-scanner/

 

and check startup items and running processes, if i suspect anything i submit it to this site, you can usually judge weather you need to get rid of the file or not

 

Virus total

https://www.virustotal.com/en/

I'm not infected.... pssht :p - I run clean shop over here. It's happened on work PC and my home machine which was formatted to install Windows 8.1 preview. SO it's as clean as a bell. Dunno though, haven't seen it yet today.

this is what i usually do if i get infected.

 

Malwarbytes

http://www.malwarebytes.org/

 

if you dont have it, download, install, update and then do a full system scan.

 

then once i have used my antivirus to scan (which takes about 2 days, since i have a huge amount of data and space!) and done a malware scan, i then use one or more of these:

 

(these are all online scanners, so do not require you to remove your existing antivirus software)

 

Trendmacro Housecall

http://housecall.trendmicro.com

 

panda active scan

http://www.pandasecurity.com/activescan/index/

 

Bit Defender

http://www.bitdefender.co.uk/scanner/online/free.html

 

Eset online scanner

http://www.eset.com/us/online-scanner/

 

and check startup items and running processes, if i suspect anything i submit it to this site, you can usually judge weather you need to get rid of the file or not

 

Virus total

https://www.virustotal.com/en/

Over kill to the maximum, even if it is better to be safe than sorry!

 

Malwarebytes and SuperAntiSpyware, are all I need. If those 2 programs haven't gotten everything, I'll use Malwarebytes anti rootkit, which I'm not even sure is any different that regular Malwarebytes! Usually, either of those first 2 programs get's those baddies.

 

Not even using an AV now. Have NEVER had one of those bloated programs block/find/remove anything!

Can someone please screenshot the advert that supposedly triggers this? It's quite serious and I need to be able to report it. Does it happen only on main or also in the forums?

Not sure which ad was doing it but it only happened to me on the main page and not the forums.

Couldn't screenshot it because it goes by too fast as I'm generally not paying attention to the ads either (:p) - I just go neowin.net then go to try click the login button and it starts going all over the place.

myftp.biz has been blocked here and at two ad providers that could possibly host such an ad, but it's confusing because we don't even allow popups; the only way we can truly get to the bottom of this is if I know exactly what ads are loaded on the page when the thing pops up.

2nd time this has happened to me now. I use inprivate mode at work so i'm not logged in but i'm on the neowin main page then start getting redirected to other site to land at:

 

attachicon.gifFake Virus.png

 

WARNING: Don't be a smarty and go to site below: :punch:

http://usdppvs.myftp.biz/index.php?....................... etc

 

I don't know if it's the same site as last time but it was the same fake Security Essentials thing.

 

It's only happened when not logged in so i'm guessing guests haven't been able to report it.

 

WOW, if MSE detects it just imagine how bad it really is....

 

Also Sandboxie FTW!

 

A good time to remind anyone who is reading this to keep their 3rd party applications and operating system up to date. It's more than likely what ever site it's redirecting to probably has an exploit kit.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • It's time to say goodbye to Edge and switch back to Firefox. There's no way to disable the ugly rounded corners that appear everywhere. Not even on the page frame. No one uses screens with rounded corners, you idiots.
    • Being on Github makes it more trustable since I can see the code at any point.
    • Gen Atlas is the next game from Shadow of the Colossus creator, this time with giant robots by Pulasthi Ariyasinghe The mind behind widely well-received games like Ico, Shadow of the Colossus, and The Last Guardian, Fumito Ueda, showed up at Summer Game Fest today, and that was to reveal his latest project. Being developed by genDESIGN, Gen Atlas is incoming with what looks to be plenty of mech and robot action. Watch the reveal trailer, which makes not much sense, above. The game will have players waking up on an abandoned planet where deserted facilities and grand designs from the original creators remain. Soon, they will stumble upon a colossal robot, from which players gain access to the power to change the world. "Across an endless expanse of time, the remnants of those forgotten constructs begin to move once more," adds the studio. The gameplay snippets seen in the trailer show the player character climbing giant robots (as expected from the creator), while also controlling these titans somehow as well. This is a fully single-player open-world adventure. “The team and I are grateful to all the fans who’ve been eager to learn more about our game,” says Fumito Ueda, CEO and creative director of genDESIGN. “Their passion and enthusiasm has always motivated and inspired us. We hope to share an experience that inspires moments of quiet wonder and discovery.” Before gaining the name Gen Atlas, Ueda first announced this project back in 2024 with the codename Project Robot. Interestingly, this will be a project being funded and published by Epic Games, which should mean that a Steam release is out of the question. Gen Atlas will be releasing on Epic Games Store, Xbox Series X|S, and PlayStation 5. A release date has not been announced just yet.
    • How backwards can you have it? Yes, Linux was gaining because of Linux handhelds and the push for gaming compatibility, but that's not desktop users, it barely converts anyone who owns a SteamDeck, though it helps for those who wanted to do it, but anyways, the AI+RAM debacle helped Linux because people can't easily upgrade their PCs easily and many hate AI so they'd be incentivized to try Linux.
    • 🤦🏻‍♂️ No, expected because 10 EOL
  • Recent Achievements

    • Mentor
      grik went up a rank
      Mentor
    • Dedicated
      JKR earned a badge
      Dedicated
    • One Year In
      CHUNWEI earned a badge
      One Year In
    • Conversation Starter
      FBSPL earned a badge
      Conversation Starter
    • Week One Done
      I2D earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      472
    2. 2
      PsYcHoKiLLa
      269
    3. 3
      Skyfrog
      78
    4. 4
      Steven P.
      68
    5. 5
      +Edouard
      61
  • Tell a friend

    Love Neowin? Tell a friend!