Forum Settings
       
Reply To Thread

Malware warning?Follow

#1 Nov 08 2007 at 7:06 AM Rating: Good
I just got what appeared to be a windows malware warning while I was on the main page of an FFXI forum. It made me suspicious because it said "User at IP address blah blah has gained control of your computer and has accessed your credit card information." It also said that I did not have all my Windows Security stuff activated, when I know for a fact that our work PCs are locked up tighter than Fort Knox. (Hell, all cookies are frickin deleted every time we boot up!)

I suspect I rolled over an ad which is masquerading as an offical Windows security warning. I don't mind pop ups, but this particular ad took me away from the Alla page I was on and jumped me over to an entirely different website so that I had to hit the back button. (I'll admit, it gave me the jumps too before I realized that it made NO SENSE.)

If it happens again I'll try to grab a screenshot.
#2 Nov 09 2007 at 3:46 AM Rating: Decent
****
6,424 posts
Solution is very simple: adblock the adserver script. I tried blocking specific sites but they constantly change their names, so the only constant part is the adserver script...

In allakhazam's case, insert "http://*.tribalfusion.com/" as an adblock filter, and it will block all scripts from them. I don't mind ads, but I do mind ads taking over my browser with scams.
#3 Nov 09 2007 at 5:32 AM Rating: Good
Here is another similar one I just got:

http://www.catwho.net/images/fake.jpg

Very annoying.
#4 Nov 09 2007 at 7:01 AM Rating: Excellent
Avatar
******
29,919 posts
I can't get anything like that to load from our ad servers for me. Are you 100% certain your PC is clean?
____________________________
Arch Duke Kaolian Drachensborn, lvl 95 Ranger, Unrest Server
Tech support forum | FAQ (Support) | Mobile Zam: http://m.zam.com (Premium only)
Forum Rules
#5 Nov 09 2007 at 7:17 AM Rating: Good
If it wasn't I'd be in serious trouble with my company XD Every reboot it goes through and deletes all cookies (means I get to log into Alla fresh every day, woo), runs a complete virus check, and scrubs itself down, before I'm even allowed on the network. About the only thing it's due for is a good defrag, and that would have nothing to do with spam-ads.

The only places I surf at work are here, livejournal (paid account, no ads), my linkshell forum's website (private server, no ads), occasionally Killing Ifrit, and Scientific American. I somehow doubt that the Hitachi or HP websites have spyware tool ads on it. This sort of thing only comes up on Allakazham, and as you can see IE7 did a nice job of popping whatever blockup was trying to install itself.

I get some pretty wacky advertisements. Right above my post as I'm typing this, the banner ad didn't even load. It's a white box of nothing. Usually I just ignore them; once in a while I'll even click em if it's something worth looking at. ("You are the 999,999th visitor! Click here for a free Playstation 3" is NOT. That was an old tactic before the .com bubble burst!)
#6 Nov 09 2007 at 7:30 AM Rating: Excellent
That is similar to the Smitfraud.C spyware dropper actually. It pops up a warning message saying you are either infected or your security is set too low to get you to click the link or install their software, which is where the real infection begins. Once you agree to let that stuff install on your PC, it also installs a trojan that allows other software to install on your PC to infect it further.

Run Ad-Aware, Spybot, your AV and check HijackThis for possible issues but do NOT click the links or pages that those pop ups generate.
#7 Nov 09 2007 at 9:34 AM Rating: Good
I know better than to click the links ;)

Virus scan on the work box came up clean. I can't run SpyBot or AdAware as I'm forbidden from installing software at all.
#8 Nov 12 2007 at 9:28 AM Rating: Good
**
335 posts
When I closed a page I was reading on the ffxi forum a tiny box popped up with something about malware. When I closed it it started scanning automatically. I closed that and am heading off to do some scans but just wanted to post my experience.
#9 Nov 12 2007 at 10:28 AM Rating: Excellent
***
2,553 posts
We'll keep looking into this, but so far we've been unable to reproduce the problem. Are you in North America?
____________________________
--Illia
Fumus, draco magus incoluit mare.
Myrx - 70 Holy Priest, Myr - 70 Resto Shaman, Gryd - 70 Prot Warrior
#10 Nov 12 2007 at 3:41 PM Rating: Good
**
335 posts
I am in North america and I do run Firefox.
#11 Nov 13 2007 at 5:50 AM Rating: Good
In north america, forced to run on IE7 against my will due to company policy. :(
#12 Nov 13 2007 at 9:24 AM Rating: Excellent
I've been running the ads for 2 days now and have my security down a little bit to see if I can find this. So far I haven't seen anything but I will keep at it and work with our upper management folks to see if we can figure out what the deal is here for you.
#14 Nov 13 2007 at 8:04 PM Rating: Decent
**
727 posts
I had something similar happen yesterday. I clicked Alla from bookmarks, clicked on the server forums link and an Ad for Malware cleaning popped up. It had Yes and No option buttons. I clicked No and it began downloading. I closed out of everything asap, then ran my virus, and spyware programs. Luckily everything came up clean, so I must have been fast enough. I run Firefox, I have firewalls, and I use pop-up blockers. This was the first time this had happened on the Alla or any site.
#15 Nov 13 2007 at 8:29 PM Rating: Excellent
Do you happen to recall what ad it was?
#16 Nov 13 2007 at 10:36 PM Rating: Decent
*****
12,501 posts
I can support what he is saying.

Back before I got premium again(About 2 months now?), Alla window shut and it came up with a small pop up, like a normal error popup. It said that my system needed a scan, and click here to install some file to check my computer for viruses.

I don't have a screenshot as I thought nothing of it. I run the latest version of Firefox and alla was and is the only window i have open while viewing the forum.
#17 Nov 13 2007 at 10:38 PM Rating: Decent
*****
12,501 posts
Actually, I did save a screenshot.

http://i88.photobucket.com/albums/k162/Antinoob3/allaad.jpg
#18 Nov 14 2007 at 3:09 AM Rating: Decent
****
6,424 posts
Illia wrote:
We'll keep looking into this, but so far we've been unable to reproduce the problem. Are you in North America?


I'm in the Netherlands, and it took me 30 seconds to reproduce the problem.

Firefox 2.0.0.9
1. Turn of Adblock so tribalfusion scripts are no longer blocked.
2. Refresh this page x3 (no premium so ads will load)
3. Third refresh closed the browser and showed a fake popup from doctorfix.com

The ads are localized for their audience, so I wouldn't be surprised if they can prevent the malware from showing on the domains that show the ads, or even to avoid regions that could take legal action against them.

These 'ads' are highly intimidating and are designed to bully people into installing their fake software. Once installed, a fake scan will reveal a load of 'problems' but you have to pay for the registered version to 'clean' your pc. If you don't pay, countless popups will haunt you everytime you try to use the pc. They will go away once you pay... until the version expires...

Every adserver that allows them will go into my banlist, and I would suggest anyone doing the same.

#19 Nov 14 2007 at 3:53 AM Rating: Good
Citizen's Arrest!
******
29,527 posts
Seedling wrote:
I'm in the Netherlands, and it took me 30 seconds to reproduce the problem.


Did you screenshot it? Might help them to determine any issues.
#20 Nov 14 2007 at 5:05 AM Rating: Decent
****
6,424 posts
The One and Only Poldaran wrote:
Seedling wrote:
I'm in the Netherlands, and it took me 30 seconds to reproduce the problem.


Did you screenshot it? Might help them to determine any issues.


I didn't, but there's nothing to learn there. I already explained that without ads (premium or adblock) these ads don't show, while browsing a few forum pages with ads enabled will trigger the scam ads sooner or later.
Reply To Thread

Colors Smileys Quote OriginalQuote Checked Help

 

Recent Visitors: 139 All times are in CST
Anonymous Guests (139)