Adware on Neowin


Recommended Posts

Heh. Darn those Firefox users! *shake fist*

Hmmm, that's a BC-registered numbered corporation, in the same province where I'm in (where I happen to head up the security/abuse desk of a Tier 1 carrier). I hope those clowns aren't with us. :|

Anyone know the IP address where the first download is coming from? If the ad's still up, maybe I'll fire up a vmware win98 session and see if I can capture it.

It seems to me that neowin or its ads are changing my homepage, cuase after a hour browsing around in other forum (after using ccleaner to clean all the interent stuff on my comp,run adaware and spybot) nothing happen. Until just now when my homepage changed.

Before my homepage change i get this pop-up from object.passthison.com/vu083003/object.cgi?homepage1

ANY help

The same IP address range keeps appearing. I would suggest using your firewall to block 209.50.252.0/24:

Non-authoritative answer:

Name: object.passthison.com

Addresses: 209.50.252.113, 209.50.252.114, 209.50.252.116

%whois -a 209.50.252.113

ServInt Corp. SERVINT-CIDR-1 (NET-209-50-224-0-1)

209.50.224.0 - 209.50.255.255

ServInt Internet Services SERVINT-INTR-2 (NET-209-50-252-0-1)

209.50.252.0 - 209.50.252.255

# ARIN WHOIS database, last updated 2004-03-17 19:15

# Enter ? for additional hints on searching ARIN's WHOIS database.

%whois -a servint-intr-2

OrgName: ServInt Internet Services

OrgID: SIS-31

Address: 6861 Elm St.

City: McLean

StateProv: VA

PostalCode: 22101

Country: US

NetRange: 209.50.252.0 - 209.50.252.255

CIDR: 209.50.252.0/24

NetName: SERVINT-INTR-2

NetHandle: NET-209-50-252-0-1

Parent: NET-209-50-224-0-1

NetType: Reassigned

NameServer: NS.SERVINT.COM

NameServer: NS2.SERVINT.COM

Comment:

RegDate: 1998-06-30

Updated: 2001-05-15

TechHandle: NO178-ARIN

TechName: Network Operations

TechPhone: +1-703-847-1421

TechEmail: [email protected]

I can tell you right now, Neowin does not (nor ever has) support any forms of Spyware/Adware/Malware/Asshatware. The blame for this one lies in one of the Advertising companies that Neowin receives it's banners from, Redmak will resolve this issue as soon as possible.

Thanks again for your concern,

Cara

Global Moderator

All of you Firefox users are blocking our Ads I suppose...great to help out the site's funding.  :rolleyes:

I'm using firefox and i'm not blocking anything related to neowin's ads. :)

So "ALL" is not a good way to say it :/

Weak ass trojan can't even infect with my McAfee disabled lol.

Well the "trojan" is hosted on http://www.achtungachtung.com/0021 (this is where all the parts of the "trojan" are located) but I can't tell you much more because I can't get the whole thing downloaded. I have the part that installs the trojan but not the part it downloads after you're infected.

I'm willing to bet though that this trojan aint a trojan but a crappy spyware program. The infecter part(index[1].html is pretty small but makes several references to LaunchJpu.php which in turn references scriptbody.jsp which then references payloadexe.exe(which I can't seem to get). It also mentions C:/WINDOWS/PCHEALTH/HELPCTR/System/panels/Context.htm and has several paths to notepad coded into it but just what it does I can't say because I can't get payloadexe.exe, and on top of that even if I could I probably wouldn't understand it as easy as I would a script like the other files.

I'm working on this but as I don't get these ads myself it's quite hard to pinpoint its origin.

If any of you get this ad again could you please provide me with:

The link of the banner that is showing at that time (so do a mouseover and read your IE status bar) and if you could even provide me with the source code of the page (the neowin page) so I can check the ad code in there.

I was in this thread

https://www.neowin.net/forum/index.php?showtopic=149643

And the ad above was

http://oz.valueclick.com/cycle?host=hs0279...script=1;msizes

"Free! Online Diabetes menu planner Click here to use it now"

Hoped i have help, off to scan my comp, how gay :blush:

Oh can someone look in there registry and go to

Hkey_Current_user\software\microsoft\internet Explorer\main

and look for

search bar

search page

And tell me what is the defualt data suppose to be. So i can change mines :)

i found that mines said smartbotpro which i guess is affiliated with the Passthison crap, after doin research on it.

Currently in my registy (pic below)

post-19-1079623857.jpg

Oh can someone look in there registry and go to

Hkey_Current_user\software\microsoft\internet Explorer\main

and look for

search bar

search page

And tell me what is the defualt data suppose to be. So i can change mines :)

i found that mines said smartbotpro which i guess is affiliated with the Passthison crap, after doin research on it.

Currently in my registy (pic below)

Those registry keys are not a default part of Internet Explorer. They are a part of the "adware" you are describing. I would delete them personally.

after some time again researching about passthison, i have learn that this Hijacking occured becuase of some flaw/hole in IE.

Would it be in my best interest to switch to firefox. Will it rid me of my problem.

Other forum also sent me a popup and reset my homepage. i have tried everything to get rid of it, including going to safe mode with CMD and del index.dat/s. I manage to browse around neowin by pressing hte stop button before the ads load.

Firefox - yay or nay?

I was getting the same crap yesterday. I thought it was just me, but looks like others are complaining now as well. I got rid of it by running HiJackThis and removing the entries for it. I didn't even get one of those installer windows, like in some screenshots. I just got a normal popup that opened and was closed instantly by the google toolbar, and then after that popup I had problems.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I totally disagree. Very little good comes out of governments all around the world manipulating everything they can and usually the people are not the benefactors. What you say about being restricted and expensive sounds almost like the arguments against firearms and why banning them will protect people as if making something illegal somehow will prevent the criminals from having and using them. AI being far less mainstream could simply mean the average person will not benefit, but "big brother" and the corporations will benefit, which is almost for sure NOT a good thing.
    • I do apologize to the author Mr. Sen for my rude comment, questioning his knowledge of the subject. It is I whom lacked knowledge of the subject. Sorry!
    • Hello All Have a MSI Pro B650 VC Wifi Rev 1.0 motherboard Ryzen 7 7700X Radeon 7800XT OC 16GB 32GB Teamgroup DDR 5 5600mhz Samsung 990 Pro 1TB Boot NVMe Samsung 990 Pro 2TB Game NVMe Lian Li Lancool Black ARGB 216 Case Seasonic Focus GX 750 Watt Power supply   Wondering today what is best spot to plug in the following items on system for performance and not bottle neck anything if i can help it Creative Pebble Pro USB C or A Speakers, ((Powered by External USB C to C PD Adapter)  Logitech G513 USB Gaming Keyboard Logitech G502X Wired Gaming Mouse Cyberpower UPS USB Cable for UPS Power Management/System shutdown External drives connected occasionally are as follows---WD My Book 8TB (primary backup drive)   Seagate 8TB in External USB 3.0 Enclosure,  Seagate Portable 1TB USB 3.0 drive,   WD My Passport (Blue) 2TB, and WD My Passport (Red) 2TB,    WD Elements 500GB USB 2.0 External (Oldest one, Christmas 2003)       **Do have a 7 Port Powered  USB Hub as well, but when i use that--that leaves only the USB Flash spot for something to directly connect to system if needed.    Rear USB C 2x2 unused right now as moved the Creative speakers off it to USB A port next to it, with a USB C to A Cable, as figured speakers didn't near audio from USB C port and tie up the high speed port**   Front Ports trying to limit use of, so i don't have Front I/O port go bad again, already had it replaced once by Lian Li support all the way from Taiwan over night ((Do get extra nervous at times on things,  so i might just be extra nervous for nothing lol))
    • "connect with audiences" is the most obvious corporate speak you can think of. I only bought Need for Speed from EA because it was the only racing game with cops in existence and I dig that. Now that they killed off NFS franchise, I have nothing to spend money on. EA is officially dead for me, just like Ubisoft which I've been boycotting for some 20 years now...
  • Recent Achievements

    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      496
    2. 2
      +Edouard
      203
    3. 3
      PsYcHoKiLLa
      127
    4. 4
      Steven P.
      83
    5. 5
      ATLien_0
      80
  • Tell a friend

    Love Neowin? Tell a friend!