Adware on Neowin


Recommended Posts

This is for you guys that got this spyware from that page.

My IE didn't even get infected by it and this was with my anti-virus and spyware guard programs disabled(I was trying to get it infected hoping it was a trojan because I wanted to add it to my collection), so I think my Internet Explorer settings are pretty solid. This post is more of a preventive measure than a fix and will harden internet explorers security but at the same time retaining the functionality that IE has.

First in tools, internet options, advanced uncheck "Enable Install On Demand (Internet Explorer)" and "Enable Install On Demand (Other)" and "Enable Third-Party Browser Extensions (Requires Restart)" and choose apply and ok. Also ensure your internet security setting is at least medium(unless you know what you are doing and have made it custom).

Goto http://www.windowsupdate.com and make sure you have all the latest updates.

Then download Suns Java JRE from http://java.com/en/index.jsp (the link you want to hit is the "get it now" in the top right). Running Suns Java protects you because it has less exploited vulnerabilities than microsofts Java. Lots of spyware use holes in Microsofts java to install thier spyware so switching to Sun's closes a lot of holes.

Then download Spybot Search and Destroy from http://www.safer-networking.org/ run it and make sure to let it download the newest updates. Now goto Spybots immunize function and under "permanent internet explorer immunity" choose immunize, then under "permanently running bad download blocker for internet explorer" select "ask for blocking confermation and choose install.

Now download spyware blaster from http://www.javacoolsoftware.com/spywareblaster.html run it and ensure it's fully updated. Now choose "select all" and then hit "Protect Against Checked Items". Just for reference all the items that are in red are items that Spybots immunize doesn't protect you against that's why you should use both programs.

Both Spybot search and destroy's immunize function and spyware blaster are one time set things, these programs no longer have to be running to keep you from getting infected with the stuff the block against. What they do is disallow any activeX program that's was known to them at the time you immunized from even running. With both Spybot and Spyware Blaster it is important that you check for updates every two weeks or so and re-immunize yourself when new updates are released to stay current. Spybot's other immunize function ("permanently running bad download blocker for internet explorer") installs a BHO that will ask you for permission to block other known bad BHO's from installing. BHO's are really not needed and fairly rare and most people only have the adobe acrobat BHO. You could have set this option to always block but I chose "ask for blocking confirmation" for those people that use something that I do not that uses a BHO.

Now download both DSOstop2 and HTAstop2003 from http://www.nsclean.com/freebies.html and run both of those.

In addition there's another great free utility that you can run but unlike everything above it has to always be open just like an antivirus called spywareguard from javacool. You can download it and run it as well to further increase your security against spyware if you choose. It's available here: http://www.wilderssecurity.net/spywareguard.html

That should beef things up considerably. Having a good antivirus is also helpful because many of them are starting to add spyware to thier definitions, for instance my McAfee 8 caught that spyware trying to install.

I hope this helsp you guys because these settings are pretty solid but at the same time loose enough that you can still have active scripting enabled and activeX. Granted you could disable those as well but at that point you might as well go download an old version of Mosiac browser because it isn't worth using IE with everything disabled.

They(Neowin) don't really run the ads themself, they lease the adspace to ad companies who then run thier own ads.

Now granted since the ad is on neowin's site the responsibility is primarily thiers, but I hope everyone understand they can't just drop thier ad company altogether because that's how Neowin stays up, so I hope everyone sees that they need to know the actual ad doing this so they can have it removed while keeping the other ads in place.

Ok, i have been on the post latly and when i am going to reply or start a new topic as soon as i finish and click Post this site comes up: http://www.proxyconn.com/best.asp . Does anyone know why? It is really bugging me and i'm sure it has other people. You can't even add a post or post, it just keeps coming up everytime you click it.

Help i guess...?

this is ****** up .. the admins/mods should do something about this issue. I just reinstalled Windows XP, got all the updates then got on neowin ( no other sites .. just neowin!!) ..and see what ad-ware 6.0 came up with.

Edited by Emon

^^ hey what browser are you running, looks like avant

I have had the yellow box from the post above also....hhhhhhhhmmmmmmmmmmm

Heres a topic on passthison crap

http://www.lecour.net/richard/archives/001042.html

this suck, hopefully i have rid my computer of smartbotpro and alll that other crap

mAcOdIn

They(Neowin) don't really run the ads themself, they lease the adspace to ad companies who then run thier own ads.

Now granted since the ad is on neowin's site the responsibility is primarily thiers, but I hope everyone understand they can't just drop thier ad company altogether because that's how Neowin stays up, so I hope everyone sees that they need to know the actual ad doing this so they can have it removed while keeping the other ads in place.

this is ****** up .. the admins/mods should do something about this issue. I just reinstalled Windows XP, got all the updates then got on neowin ( no other sites .. just neowin!!) ..and see what ad-ware 6.0 came up with.

Yea man, I was browsing Neowin in school and guess what!

Changed home page and search page

Lots of popups

Installed virus/cookies/trojan (yeah, the AV kicked in)

Change it ASAP! :angry:

Well I got the same crap, and I'm sorry, but I activated my NIS 2004 Banner blocking, and I activated the popup blocker on neowin.... :s

No way I'm gonna infect my computer by coming here...

No offense guys, but there is no point in getting angry about this. We are looking into it. We havent done this intentionaly, its the ad server people. if you dont want to come to neowin, then fine, but dont let it be over some adverts that you can easily block out.

No offense guys, but there is no point in getting angry about this. We are looking into it. We havent done this intentionaly, its the ad server people. if you dont want to come to neowin, then fine, but dont let it be over some adverts that you can easily block out.

I'm not blocking ads because I realize that (at least part of) the way neowin stays afloat and free. Are you saying that it doesn't really matter if we block these or not?

No, but i'm saying if you cant live with it, then its a better alternative than you not coming atall. Of course neowin lives off ad revenue, but at the end of the day, we also live of you guys- the members. You know we haven't done this intentionally, and you know we'll try and provide the best site for you guys as possible. Just give us a chance.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Hello, It would appear so, according to https://finance.yahoo.com/news/how-to-hide-your-home-on-google-maps-apple-maps-204146687.html. Regards, Aryeh Goretsky      
    • Hello, The Nvidia Founders Edition 3080 video card is approximately six years old, correct? Have you looked into whether replacement fans are available for it? Perhaps replacing those will improve cooling, especially when combined with cleaning the card's heatsink and replacing the thermal interface materials. Regards, Aryeh Goretsky  
    • Hello, While ~104 GB of space may seem generous (at least compared to other e-readers which have 8-32GB), I feel at this price point the device should have a Micro SDXC card slot for expansion, particularly if it allows audio books to be installed and played. I hope to see more reviews of 6" phone-sized e-readers on Neowin in the future. It will be interesting to see how they compare. Regards, Aryeh Goretsky
    • Sandboxie Plus 1.17.8 / Classic 5.72.8 by Razvan Serea Run programs in a sandbox to prevent malware from making permanent changes to your PC. Sandboxie allows you to run your browser, or any other program, so that all changes that result from the usage are kept in a sandbox environment, which can then be deleted later. Sandboxie is a sandbox-based isolation software for 32- and 64-bit Windows NT-based operating systems. It is being developed by David Xanatos since it became open source, before that it was developed by Sophos (which acquired it from Invincea, which acquired it earlier from the original author Ronen Tzur). It creates a sandbox-like isolated operating environment in which applications can be run or installed without permanently modifying the local or mapped drive. An isolated virtual environment allows controlled testing of untrusted programs and web surfing. Sandboxie is available in two flavors Plus and Classic. Both have the same core components, this means they have the same level of security and compatibility. What's different is the user interface the Plus build has a modern Qt based UI which supports all new features that have been added since the project went open source. The Classic build has the old no longer developed MFC based UI, hence it lacks support for modern features, these features can however still be used when manually configured in the Sandboxie.ini. Sandboxie Plus 1.17.8 / Classic 5.72.8 release notes: Added added DisableCustomTitleOpt=[process,][y|n] to allow [#] sandboxie title markers on custom-titlebar windows (Delphi VCL, Qt, Electron) that were previously skipped to prevent DWM repaint CPU loops #5387 Changed updated bundled ImDisk driver to 3.0.2 #5419 Fixed fix Suppress logs for expected non-user SIDs #5422 SbieSvc.exe: SBIE2218/2219 error when run program as administrator #5417 fixed explorer.exe crashes in Application Compartment when Huorong Security is installed #5423 Download: Sandboxie Plus (64-bit) | 23.5 MB (Open Source) Download: Sandboxie Classic (64-bit) | 3.0 MB Links: Sandboxie Website | GitHub | ARM64 | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Hello, Christian Maas' XVI32 is a nice (and very small) hex editor. Speaking of hex editors, many years ago a colleague and I who both worked at Tribal Voice managed to edit a copy of the company's PowWow instant messaging client to make it behave better now that all of its lookup servers and other server-side tech was gone.  The program didn't support NAT (RFC-3022 was introduced in January 2001, the same time Tribal Voice was shuttered), but it still worked okay if you manually set up port-forwarding on your router.  The server at http://powwow.jazy.net/ hosts a copy (usual warnings about downloading and running untrusted code from random internet servers apply). I occasionally use some tools like Funduc Software's Search and Replace and Application Mover when I need to make mass-edits to text-based files or move programs with a hard-coded installation directories, respectively.  When I need to figure out the exact LCD panel inside of a laptop, EnTech Taiwan's Monitor Asset Manager is my go-to tool for that purpose. JD Design's website (now hosted on github.io) has a number of interesting freeware and shareware utilities.  I used to use their TouchPro utility to set the file timestamps on software I was mastering to match its version number (e.g., version 3.00 of a program had all of its files dates set to 3:00AM, and so forth). Karenware has a number of interesting freeware utilities, too. Regards, Aryeh Goretsky  
  • Recent Achievements

    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      509
    2. 2
      +Edouard
      198
    3. 3
      PsYcHoKiLLa
      138
    4. 4
      ATLien_0
      90
    5. 5
      Steven P.
      82
  • Tell a friend

    Love Neowin? Tell a friend!