Adware on Neowin


Recommended Posts

Heh. Darn those Firefox users! *shake fist*

Hmmm, that's a BC-registered numbered corporation, in the same province where I'm in (where I happen to head up the security/abuse desk of a Tier 1 carrier). I hope those clowns aren't with us. :|

Anyone know the IP address where the first download is coming from? If the ad's still up, maybe I'll fire up a vmware win98 session and see if I can capture it.

It seems to me that neowin or its ads are changing my homepage, cuase after a hour browsing around in other forum (after using ccleaner to clean all the interent stuff on my comp,run adaware and spybot) nothing happen. Until just now when my homepage changed.

Before my homepage change i get this pop-up from object.passthison.com/vu083003/object.cgi?homepage1

ANY help

The same IP address range keeps appearing. I would suggest using your firewall to block 209.50.252.0/24:

Non-authoritative answer:

Name: object.passthison.com

Addresses: 209.50.252.113, 209.50.252.114, 209.50.252.116

%whois -a 209.50.252.113

ServInt Corp. SERVINT-CIDR-1 (NET-209-50-224-0-1)

209.50.224.0 - 209.50.255.255

ServInt Internet Services SERVINT-INTR-2 (NET-209-50-252-0-1)

209.50.252.0 - 209.50.252.255

# ARIN WHOIS database, last updated 2004-03-17 19:15

# Enter ? for additional hints on searching ARIN's WHOIS database.

%whois -a servint-intr-2

OrgName: ServInt Internet Services

OrgID: SIS-31

Address: 6861 Elm St.

City: McLean

StateProv: VA

PostalCode: 22101

Country: US

NetRange: 209.50.252.0 - 209.50.252.255

CIDR: 209.50.252.0/24

NetName: SERVINT-INTR-2

NetHandle: NET-209-50-252-0-1

Parent: NET-209-50-224-0-1

NetType: Reassigned

NameServer: NS.SERVINT.COM

NameServer: NS2.SERVINT.COM

Comment:

RegDate: 1998-06-30

Updated: 2001-05-15

TechHandle: NO178-ARIN

TechName: Network Operations

TechPhone: +1-703-847-1421

TechEmail: [email protected]

I can tell you right now, Neowin does not (nor ever has) support any forms of Spyware/Adware/Malware/Asshatware. The blame for this one lies in one of the Advertising companies that Neowin receives it's banners from, Redmak will resolve this issue as soon as possible.

Thanks again for your concern,

Cara

Global Moderator

All of you Firefox users are blocking our Ads I suppose...great to help out the site's funding.  :rolleyes:

I'm using firefox and i'm not blocking anything related to neowin's ads. :)

So "ALL" is not a good way to say it :/

Weak ass trojan can't even infect with my McAfee disabled lol.

Well the "trojan" is hosted on http://www.achtungachtung.com/0021 (this is where all the parts of the "trojan" are located) but I can't tell you much more because I can't get the whole thing downloaded. I have the part that installs the trojan but not the part it downloads after you're infected.

I'm willing to bet though that this trojan aint a trojan but a crappy spyware program. The infecter part(index[1].html is pretty small but makes several references to LaunchJpu.php which in turn references scriptbody.jsp which then references payloadexe.exe(which I can't seem to get). It also mentions C:/WINDOWS/PCHEALTH/HELPCTR/System/panels/Context.htm and has several paths to notepad coded into it but just what it does I can't say because I can't get payloadexe.exe, and on top of that even if I could I probably wouldn't understand it as easy as I would a script like the other files.

I'm working on this but as I don't get these ads myself it's quite hard to pinpoint its origin.

If any of you get this ad again could you please provide me with:

The link of the banner that is showing at that time (so do a mouseover and read your IE status bar) and if you could even provide me with the source code of the page (the neowin page) so I can check the ad code in there.

I was in this thread

https://www.neowin.net/forum/index.php?showtopic=149643

And the ad above was

http://oz.valueclick.com/cycle?host=hs0279...script=1;msizes

"Free! Online Diabetes menu planner Click here to use it now"

Hoped i have help, off to scan my comp, how gay :blush:

Oh can someone look in there registry and go to

Hkey_Current_user\software\microsoft\internet Explorer\main

and look for

search bar

search page

And tell me what is the defualt data suppose to be. So i can change mines :)

i found that mines said smartbotpro which i guess is affiliated with the Passthison crap, after doin research on it.

Currently in my registy (pic below)

post-19-1079623857.jpg

Oh can someone look in there registry and go to

Hkey_Current_user\software\microsoft\internet Explorer\main

and look for

search bar

search page

And tell me what is the defualt data suppose to be. So i can change mines :)

i found that mines said smartbotpro which i guess is affiliated with the Passthison crap, after doin research on it.

Currently in my registy (pic below)

Those registry keys are not a default part of Internet Explorer. They are a part of the "adware" you are describing. I would delete them personally.

after some time again researching about passthison, i have learn that this Hijacking occured becuase of some flaw/hole in IE.

Would it be in my best interest to switch to firefox. Will it rid me of my problem.

Other forum also sent me a popup and reset my homepage. i have tried everything to get rid of it, including going to safe mode with CMD and del index.dat/s. I manage to browse around neowin by pressing hte stop button before the ads load.

Firefox - yay or nay?

I was getting the same crap yesterday. I thought it was just me, but looks like others are complaining now as well. I got rid of it by running HiJackThis and removing the entries for it. I didn't even get one of those installer windows, like in some screenshots. I just got a normal popup that opened and was closed instantly by the google toolbar, and then after that popup I had problems.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Just when I thought EA couldn't go lower. They surpassed my expectations
    • The GEEKOM A8 mini PC is 20% off (lower than Prime Day pricing) plus Huge Storewide Sale by Steven Parker GEEKOM is back with a deal on a variant of its A8 Mini PC powered by AMD's Ryzen 7 8945HS, which came out in 2024 with a TDP of just 45W, with a base clock of 3.8 GHz and a Turbo Boost of 4.9 GHz; although we never reviewed this variant, we did check out the Ryzen 9 version. As a reminder of what you get, below are the specifications for this Mini PC. GEEKOM A8 Dimensions 112.4 mm x 112.4 mm x 37 mm Weight 450g CPU Ryzen 7 8745HS (8 cores, 16 threads, 16MB L3 cache, 3.8 - 4.9 GHz, TDP: 45 W) cTDP: 35-54W (Default 45W) Graphics AMD Radeon™ 780M Graphics 12 RDNA 3 Graphics Cores 2700MHz 768 shading units / stream processors (12 CUs), 48 texture mapping units, and 32 ROPs NPU XDNA architecture (Up to 16 NPU TOPS) Memory 16GB Dual-channel Crucial DDR5-5600MT/s SODIMM (up to 64GB) Storage 1TB NVMe M.2 (PCIe Gen 4.0 x4) Operating System Windows 11 Pro Bluetooth Bluetooth v5.2 Wireless LAN Wi-Fi 6E Kensington Lock No SD Card reader Yes (left side) Adapter 120W, 6.32A, 19V Power Adapter Front I/O Ports 2 x USB 3.2 Gen 2 Type-A 1 x 3.5mm front stereo headset jack Rear I/O Ports 1 x USB 3.2 Gen 2 Type-A 1 x USB 4 Gen 3 Type-C with Power delivery up to 15W (5V 3A) 1 x USB 3.2 Gen 2 Type-C 1 x USB 2.0 Type-A 2 x HDMI 2.0b 1 x 2.5G RJ45 LAN 1 x DC-in Deal Price $519 (buying links below) GEEKOM has two configurations of the A8, with the only difference being the slightly less-powerful Ryzen 7 CPU with half the storage (1TB) and DDR5 memory (16GB). This knocks $350 off the price compared to the $999 Ryzen 9 configuration. In both instances, a Windows 11 Pro license is also pre-loaded. As I said previously, this appears to be an update on the A7 with the only difference being the newer CPU. The packaging has changed quite a bit from the A7. Instead of dark colors, now the box is completely white, and the foam cushion has been replaced by a cardboard mould that the A8 sits in, above a small envelope that contains a thank you card and booklet that has guidance on all of the controls, how to access the A8 to swap out the SSD or memory, and safety information in several European languages. Upon removing the cardboard mould, you can find another cardboard compartment that contains the power lead, HDMI cable, VESA plate, and a bag of screws. What’s In The Box 1 x A8 Mini PC 1 x Power Adapter 1 x HDMI Cable 1 x VESA plate and bag of screws 1 x Envelope with booklet and Thank you card Unlike the A7, the VESA mount option is back with the A8. In short, you have everything you need to get started. All products sold by GEEKOM receive a 3-year free Warranty from the date you receive the product. If needed, you can RMA or return locally relative to your region (the U.S. has a U.S. warehouse, mainland E.U. has a German warehouse). GEEKOM A8 at GEEKOM U.S. for $519 was $649 (20% off) GEEKOM A8 at GEEKOM U.K. for £503 was £629 (20% off) GEEKOM A8 at GEEKOM CA for $735.20 was $919 (20% off) Use coupon code NWGKA820 when checking out. This flash deal expires on July 2. Next up is the highest savings on the A7 Max series of Mini PC in the Spring Sale. The GEEKOM [2026 Edition] A7 MAX with AMD Ryzen 9 7940HS, 16GB DDR5, and 1TB SSD. Operating System: Windows 11 Pro CPU Model: Ryzen 9 7940HS CPU Speed: 5.2 GHz Cache Size: 24 MB Graphics Card Description: Integrated Graphics Coprocessor: AMD Radeon 780M Memory Storage Capacity: 16GB DDR5 SSD: 1 TB We reviewed this Mini PC back in January, and praised it for its modern internals like a dedicated NPU and DDR5 memory; as such, it is more than capable of keeping up with today's offerings of Mini PC on the market. GEEKOM A7 Max at GEEKOM U.S. for $587 (was $699) 16% off GEEKOM A7 Max at GEEKOM U.K. for £551 was £689 (20% off) Use coupon code NWGKA7MAX when checking out. This flash deal expires on July 2. Huge Summer Sale If the above deals don't tickle your fancy, from today, there are deep discounts on a range of other GEEKOM products. From June 15 to June 30, the GEEKOM Official Store will be running its Summer Sale, with discounts starting from 15% off across the entire lineup, up to 50%! This is their biggest promotion of the year so far, offering pricing that is even lower than select Prime Day deals. You can check out the discounts at the dedicated Summer Sale landing pages below. GEEKOM U.S. Summer Sale GEEKOM U.K. Summer Sale What's more, all products from GEEKOM receive a 3-year free Warranty from the date you receive the product. If needed, you can RMA or return locally relative to your region (the U.S. has a U.S. warehouse, mainland E.U. has a German warehouse, the U.K. has a U.K. warehouse, Australia has an AU warehouse). While the Summer Sale ends on June 30, deals on the A8 and A7 Max will remain active until July 2.
  • Recent Achievements

    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      513
    2. 2
      +Edouard
      205
    3. 3
      PsYcHoKiLLa
      136
    4. 4
      ATLien_0
      88
    5. 5
      Steven P.
      85
  • Tell a friend

    Love Neowin? Tell a friend!