Adware on Neowin


Recommended Posts

This is for you guys that got this spyware from that page.

My IE didn't even get infected by it and this was with my anti-virus and spyware guard programs disabled(I was trying to get it infected hoping it was a trojan because I wanted to add it to my collection), so I think my Internet Explorer settings are pretty solid. This post is more of a preventive measure than a fix and will harden internet explorers security but at the same time retaining the functionality that IE has.

First in tools, internet options, advanced uncheck "Enable Install On Demand (Internet Explorer)" and "Enable Install On Demand (Other)" and "Enable Third-Party Browser Extensions (Requires Restart)" and choose apply and ok. Also ensure your internet security setting is at least medium(unless you know what you are doing and have made it custom).

Goto http://www.windowsupdate.com and make sure you have all the latest updates.

Then download Suns Java JRE from http://java.com/en/index.jsp (the link you want to hit is the "get it now" in the top right). Running Suns Java protects you because it has less exploited vulnerabilities than microsofts Java. Lots of spyware use holes in Microsofts java to install thier spyware so switching to Sun's closes a lot of holes.

Then download Spybot Search and Destroy from http://www.safer-networking.org/ run it and make sure to let it download the newest updates. Now goto Spybots immunize function and under "permanent internet explorer immunity" choose immunize, then under "permanently running bad download blocker for internet explorer" select "ask for blocking confermation and choose install.

Now download spyware blaster from http://www.javacoolsoftware.com/spywareblaster.html run it and ensure it's fully updated. Now choose "select all" and then hit "Protect Against Checked Items". Just for reference all the items that are in red are items that Spybots immunize doesn't protect you against that's why you should use both programs.

Both Spybot search and destroy's immunize function and spyware blaster are one time set things, these programs no longer have to be running to keep you from getting infected with the stuff the block against. What they do is disallow any activeX program that's was known to them at the time you immunized from even running. With both Spybot and Spyware Blaster it is important that you check for updates every two weeks or so and re-immunize yourself when new updates are released to stay current. Spybot's other immunize function ("permanently running bad download blocker for internet explorer") installs a BHO that will ask you for permission to block other known bad BHO's from installing. BHO's are really not needed and fairly rare and most people only have the adobe acrobat BHO. You could have set this option to always block but I chose "ask for blocking confirmation" for those people that use something that I do not that uses a BHO.

Now download both DSOstop2 and HTAstop2003 from http://www.nsclean.com/freebies.html and run both of those.

In addition there's another great free utility that you can run but unlike everything above it has to always be open just like an antivirus called spywareguard from javacool. You can download it and run it as well to further increase your security against spyware if you choose. It's available here: http://www.wilderssecurity.net/spywareguard.html

That should beef things up considerably. Having a good antivirus is also helpful because many of them are starting to add spyware to thier definitions, for instance my McAfee 8 caught that spyware trying to install.

I hope this helsp you guys because these settings are pretty solid but at the same time loose enough that you can still have active scripting enabled and activeX. Granted you could disable those as well but at that point you might as well go download an old version of Mosiac browser because it isn't worth using IE with everything disabled.

They(Neowin) don't really run the ads themself, they lease the adspace to ad companies who then run thier own ads.

Now granted since the ad is on neowin's site the responsibility is primarily thiers, but I hope everyone understand they can't just drop thier ad company altogether because that's how Neowin stays up, so I hope everyone sees that they need to know the actual ad doing this so they can have it removed while keeping the other ads in place.

Ok, i have been on the post latly and when i am going to reply or start a new topic as soon as i finish and click Post this site comes up: http://www.proxyconn.com/best.asp . Does anyone know why? It is really bugging me and i'm sure it has other people. You can't even add a post or post, it just keeps coming up everytime you click it.

Help i guess...?

this is ****** up .. the admins/mods should do something about this issue. I just reinstalled Windows XP, got all the updates then got on neowin ( no other sites .. just neowin!!) ..and see what ad-ware 6.0 came up with.

Edited by Emon

^^ hey what browser are you running, looks like avant

I have had the yellow box from the post above also....hhhhhhhhmmmmmmmmmmm

Heres a topic on passthison crap

http://www.lecour.net/richard/archives/001042.html

this suck, hopefully i have rid my computer of smartbotpro and alll that other crap

mAcOdIn

They(Neowin) don't really run the ads themself, they lease the adspace to ad companies who then run thier own ads.

Now granted since the ad is on neowin's site the responsibility is primarily thiers, but I hope everyone understand they can't just drop thier ad company altogether because that's how Neowin stays up, so I hope everyone sees that they need to know the actual ad doing this so they can have it removed while keeping the other ads in place.

this is ****** up .. the admins/mods should do something about this issue. I just reinstalled Windows XP, got all the updates then got on neowin ( no other sites .. just neowin!!) ..and see what ad-ware 6.0 came up with.

Yea man, I was browsing Neowin in school and guess what!

Changed home page and search page

Lots of popups

Installed virus/cookies/trojan (yeah, the AV kicked in)

Change it ASAP! :angry:

Well I got the same crap, and I'm sorry, but I activated my NIS 2004 Banner blocking, and I activated the popup blocker on neowin.... :s

No way I'm gonna infect my computer by coming here...

No offense guys, but there is no point in getting angry about this. We are looking into it. We havent done this intentionaly, its the ad server people. if you dont want to come to neowin, then fine, but dont let it be over some adverts that you can easily block out.

No offense guys, but there is no point in getting angry about this. We are looking into it. We havent done this intentionaly, its the ad server people. if you dont want to come to neowin, then fine, but dont let it be over some adverts that you can easily block out.

I'm not blocking ads because I realize that (at least part of) the way neowin stays afloat and free. Are you saying that it doesn't really matter if we block these or not?

No, but i'm saying if you cant live with it, then its a better alternative than you not coming atall. Of course neowin lives off ad revenue, but at the end of the day, we also live of you guys- the members. You know we haven't done this intentionally, and you know we'll try and provide the best site for you guys as possible. Just give us a chance.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • AMAZON needs to take total accountability for this.
    • Server Summit had a heap of announcements, ADCS changes are baller.
    • Nice, hope they *finally* fixed the issue with the NTFS driver where the system would completely brick during large file copies using the built in driver. It's been broken for years requiring me to use the older, slower, NTFS-3G FUSE driver.
    • Windows 11 KB5094126 BSODing, freezing, forcing BitLocker lockout, breaks OneDrive, and more by Sayan Sen Microsoft released Windows 11 KB5094126 and KB5093998 last week as the latest Patch Tuesday updates. Following that the company also published the accompanying dynamic updates under KB5094149, KB5095971, and KB5094156. While Microsoft has so far not acknowledged any major problems with the release, some users online are running into problems. These range from OneDrive and Dropbox access issues, BitLocker recovery lockouts, to blue screens and BSODs. The most common one seems to be happening with HP systems wherein affected users say they hit 0xc0430001 BSOD (blue screen of death) error code after the KB5094126 update. We wonder if this could be related to the recent bug we covered on HP devices wherein the ongoing Secure Boot certificate updates are leading to similar issues. While we are not certain, users affected by this issue likely need to ensure that the boot.stl file is included on the installation media (such as a USB installer or ISO), if the above-mentioned dynamic updates are deployed. If this file is missing, computers may fail to boot from the installation media and could display the error 0xc0430001. This STL file is used by Secure Boot to verify that the boot files are trusted, so it must match the same Windows version and system architecture. To ensure the file is included, Microsoft recommends using the Update WinPE script, which automatically updates the image and handles the required files. Alternatively, you can manually copy the boot.stl file from the Windows\Boot\EFI folder on a Windows device and place it in the matching folder on your installation media before deploying the updated image. Aside from blue screening some users also note their systems have been freezing following the update. This could be happening to Lenovo PCs specifically. In the case of the OneDrive and Dropbox access issues, a user figured out that there could be a conflict with UAC. He explained: "Okay, so I did some digging, and in our environment KB5094126 breaks OneDrive and Dropbox in Explorer. I went through all our GPOs and found out that the combination of disabling UAC and having my user being a local admin breaks OneDrive in Explorer. ... If I enable UAC again, then it works, even with KB5094126 still installed." Hopefully, Microsoft will look into these issues. Source: Microsoft forum (link1, link2, link3, link4), Reddit (link1, link2, link3, link4)
    • It is when it's a desktop in my house though for a PC that's lightly used and not really important when it is. If it was a laptop, it would be a different story. The real solution is varied and begins starting at post #22 in that thread.
  • Recent Achievements

    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      508
    2. 2
      +Edouard
      198
    3. 3
      PsYcHoKiLLa
      138
    4. 4
      ATLien_0
      90
    5. 5
      Steven P.
      80
  • Tell a friend

    Love Neowin? Tell a friend!