Ads/Script redirecting to Virus site?


Recommended Posts

2nd time this has happened to me now. I use inprivate mode at work so i'm not logged in but i'm on the neowin main page then start getting redirected to other site to land at:

 

post-698-0-85235300-1373561494.png

 

WARNING: Don't be a smarty and go to site below: :punch:

http://usdppvs.myftp.biz/index.php?....................... etc

 

I don't know if it's the same site as last time but it was the same fake Security Essentials thing.

 

It's only happened when not logged in so i'm guessing guests haven't been able to report it.

Link to comment
https://www.neowin.net/forum/topic/1164064-adsscript-redirecting-to-virus-site/
Share on other sites

Yes, I am not the only one that has seen the fake Security Essentials windows a few times now when I come to Neowin.  It seems like a bad advert in the rotation I am guessing and the link is different each time. 

 

Warning to not go to the link below!!

 

"http://thpfbez.myftp.biz/index.php?c=RaENOjEayDF925cOxP3ACC60zajgAjCTlcK0liAaKtvKheVQzm+YhzfWz1MPnw1S6zBdyf5PIpX2zaZzWwL95qmKyoM="

 

 

And this happens while I am logged in.

this is what i usually do if i get infected.

 

Malwarbytes

http://www.malwarebytes.org/

 

if you dont have it, download, install, update and then do a full system scan.

 

then once i have used my antivirus to scan (which takes about 2 days, since i have a huge amount of data and space!) and done a malware scan, i then use one or more of these:

 

(these are all online scanners, so do not require you to remove your existing antivirus software)

 

Trendmacro Housecall

http://housecall.trendmicro.com

 

panda active scan

http://www.pandasecurity.com/activescan/index/

 

Bit Defender

http://www.bitdefender.co.uk/scanner/online/free.html

 

Eset online scanner

http://www.eset.com/us/online-scanner/

 

and check startup items and running processes, if i suspect anything i submit it to this site, you can usually judge weather you need to get rid of the file or not

 

Virus total

https://www.virustotal.com/en/

I'm not infected.... pssht :p - I run clean shop over here. It's happened on work PC and my home machine which was formatted to install Windows 8.1 preview. SO it's as clean as a bell. Dunno though, haven't seen it yet today.

this is what i usually do if i get infected.

 

Malwarbytes

http://www.malwarebytes.org/

 

if you dont have it, download, install, update and then do a full system scan.

 

then once i have used my antivirus to scan (which takes about 2 days, since i have a huge amount of data and space!) and done a malware scan, i then use one or more of these:

 

(these are all online scanners, so do not require you to remove your existing antivirus software)

 

Trendmacro Housecall

http://housecall.trendmicro.com

 

panda active scan

http://www.pandasecurity.com/activescan/index/

 

Bit Defender

http://www.bitdefender.co.uk/scanner/online/free.html

 

Eset online scanner

http://www.eset.com/us/online-scanner/

 

and check startup items and running processes, if i suspect anything i submit it to this site, you can usually judge weather you need to get rid of the file or not

 

Virus total

https://www.virustotal.com/en/

Over kill to the maximum, even if it is better to be safe than sorry!

 

Malwarebytes and SuperAntiSpyware, are all I need. If those 2 programs haven't gotten everything, I'll use Malwarebytes anti rootkit, which I'm not even sure is any different that regular Malwarebytes! Usually, either of those first 2 programs get's those baddies.

 

Not even using an AV now. Have NEVER had one of those bloated programs block/find/remove anything!

Can someone please screenshot the advert that supposedly triggers this? It's quite serious and I need to be able to report it. Does it happen only on main or also in the forums?

Not sure which ad was doing it but it only happened to me on the main page and not the forums.

Couldn't screenshot it because it goes by too fast as I'm generally not paying attention to the ads either (:p) - I just go neowin.net then go to try click the login button and it starts going all over the place.

myftp.biz has been blocked here and at two ad providers that could possibly host such an ad, but it's confusing because we don't even allow popups; the only way we can truly get to the bottom of this is if I know exactly what ads are loaded on the page when the thing pops up.

2nd time this has happened to me now. I use inprivate mode at work so i'm not logged in but i'm on the neowin main page then start getting redirected to other site to land at:

 

attachicon.gifFake Virus.png

 

WARNING: Don't be a smarty and go to site below: :punch:

http://usdppvs.myftp.biz/index.php?....................... etc

 

I don't know if it's the same site as last time but it was the same fake Security Essentials thing.

 

It's only happened when not logged in so i'm guessing guests haven't been able to report it.

 

WOW, if MSE detects it just imagine how bad it really is....

 

Also Sandboxie FTW!

 

A good time to remind anyone who is reading this to keep their 3rd party applications and operating system up to date. It's more than likely what ever site it's redirecting to probably has an exploit kit.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Adobe Acrobat Reader DC 2026.001.21651 by Razvan Serea Adobe Acrobat Reader DC software is the free, trusted standard for viewing, printing, signing, and annotating PDFs. Its the only PDF viewer that can open and interact with all types of PDF content – including forms and multimedia. It’s connected to Adobe Document Cloud – so you can work with PDFs on computers and mobile devices. Adobe Document Cloud is a revolutionary, modern and efficient way to get work done with documents in the office, at home or on-the-go. At the heart of Document Cloud is the all-new Adobe Acrobat DC, which will take e-signatures mainstream by delivering free e-signing with every individual subscription. Document Cloud includes a set of integrated services that use a consistent online profile and personal document hub. With Adobe Document Cloud, people will be able to create, review, approve, sign and track documents whether on a desktop or mobile device. Businesses will be able to take advantage of Document Cloud for enterprise which provides enterprise-class document services that integrate into systems of record such as CRM, HCM, CLM, and CMS, adding speed, efficiency and transparency to getting business done with documents. Adobe Acrobat Reader DC new feature highlights: Work with PDFs from anywhere with the new, free Acrobat DC mobile app for Android or iOS. Select functionality is also available on Windows Phone. Use the new Fill & Sign tool in your desktop software to complete PDF forms fast with smart autofill. Download the free Adobe Fill & Sign mobile app to add the same option to your iPad or Android tablet device. Save money on ink and toner when printing from your Windows PC. Store and access files in Adobe Document Cloud with 5GB of free storage. Get instant access to recent files across desktop, web, and mobile devices with Mobile Link. Sync your Fill & Sign autofill collection across desktop, web, and iPad devices. Adobe PDF Pack premium features includes: Convert documents and images to PDF files. Use your mobile device camera to take a picture of a paper document or form and convert it to PDF. Turn PDFs into editable Microsoft Word, Excel, PowerPoint, or RTF files. Combine multiple files into a single PDF (web only). Get signatures from others with a complete e-signature service. Send, track, and confirm delivery of documents electronically instead of using fax or overnight services (tracking not available on mobile). Store and access files online with 20GB of storage. Download: Adobe Acrobat Reader DC 64-bit | 719.0 MB (Freeware) Link: Adobe Acrobat Reader DC Home Page | Release Notes | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • The consumer ESU is ending in 4 months. LTSC isn't now, never has been, and never will be for consumer use, it is for OT usage - plant machinery, medical devices, manufacturing equipment etc. LTSC requires a Microsoft EA. You can't legally obtain LTSC to run on your PC at home.
    • Hmm actually looks decently interesting!  
    • Being on GitHub doesn't make something safe. Like any unofficial scripts to do x or y this caters to people with just enough knowledge to be dangerous. If you want to do what this does, and you actually know what you're doing then write your own script (or maybe just add the reg keys yourself) if you don't have the ability to read and understand what a script is doing, and especially don't run it with elevated privileges. Or in this case just use an MSA, sign up the normal route, and stop trying to push water up hill
  • Recent Achievements

    • Week One Done
      JKR earned a badge
      Week One Done
    • Rookie
      moog19 went up a rank
      Rookie
    • Mentor
      grik went up a rank
      Mentor
    • Dedicated
      JKR earned a badge
      Dedicated
    • One Year In
      CHUNWEI earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      488
    2. 2
      PsYcHoKiLLa
      271
    3. 3
      Skyfrog
      75
    4. 4
      Steven P.
      68
    5. 5
      FloatingFatMan
      64
  • Tell a friend

    Love Neowin? Tell a friend!