PDA

View Full Version : ZERO Viruses in the ads or something



Assassin
09-22-2013, 12:57 PM
I just got a pop up by my antivirus when I came here saying it blocked a rootkit endpoint. Just saying.

ZERO
09-22-2013, 01:40 PM
On what page where?

Assassin
09-22-2013, 02:55 PM
Main page when I first got on. The ad on the side was some Google ad that IO7 or something in it (which I find really weird considering the IOS 7 is the latest apple iphone/ipad updates)

ZERO
09-22-2013, 03:21 PM
Ok so it was on the main page. What makes you think it came from that ad and what anti virus are you using?

maynard
09-22-2013, 04:45 PM
my virus detection picked some shit up out of nowhere like an hour ago, didn't think much of it at the time other than it being really odd.... wouldn't be surprised if it's related 2 this as it's the first time in years it's gone off... I don't do anything on this PC but steam game.

DJ_MikeyRevile
09-22-2013, 04:54 PM
well... it looks like zero is using google ad sense to generate those ads. Google ad sense displays ads relevant to you and your Google search history and well... any history related to your google accounts. Also, Google is very strict with that program. People get banned daily and advertisers get kicked out of the program all the time. It is likely something unrelated to the sidebar ads, perhaps a bot post on one of the blogs on the main page.


edit: though it is unrelated.. the recent forum changes render the current ad size to large. They no longer fit within the borders. Perhaps
google_ad_width = 160;
google_ad_height = 600;

to

google_ad_width = 140;
google_ad_height = 600;

also, i saw nothing out of the ordinary with the add code when viewing the page source.

What browse you using? You might have the dreaded google redirect trojan that changes search results affiliated with google. I.e. search results, what shows as ads ect.

Steamer
09-22-2013, 06:18 PM
I use a host file ads block along with a internet database version. No problems here, no ads either.

phil.™
09-22-2013, 08:01 PM
Hahahaha we all know why I got a virus hahaha #iaintevenmad

What
09-22-2013, 08:26 PM
I've never seen any ads on the front page, is this a mobile access thing?

Assassin
09-22-2013, 10:14 PM
No it's on my web browser on my comp. Firefox of course, and I use AVG. Weird that it didn't pick up anything on it's scan, but it did block one. Idk.

ZERO
09-23-2013, 01:16 AM
OK that was the hacker testing the virus. It appears that before I removed the last hacked account it places some iframe code in the style so they could then activate this later on. The code has been cleaned out now so the issue should go away as well. :wtg:

ZERO
09-23-2013, 01:18 AM
Anyone who has used the forums in the last 24 hours is highly recommended to do a virus scan to be safe. If you do not have anti virus you WILL need to get some now, sorry about that.

What
09-23-2013, 01:38 AM
is avg ok for that>?

ZERO
09-23-2013, 01:45 AM
if you were on the website from 2am to 2:11am and never got any messages from your av deflecting shit than your av was not good enough to see the virus. Then again it could be there was not one at all as my av will cut out the connection if it detects a strange iframe based redirect. It could be that they were just redirecting to another defacement page and not a virus at all but there is no way to know for sure.

What
09-23-2013, 01:46 AM
2 am to 2:11 EST yesterday?

And what virus scan do you reccomend then? I did an AVG scan today and nothing poped up on it, but now you're making me think something should have

ZERO
09-23-2013, 01:48 AM
No 2am as in 48min ago

What
09-23-2013, 01:51 AM
well damn, maybe I was, never say any warning or anything, not sure if i was logged in then, but i probably had the forum page open

ZERO
09-23-2013, 01:56 AM
The forum page would have tried to redirect you to another webpage or open popups on your screen. If you did not see any of that you likely missed it.

The time from when it went live to when I killed it was very very short, maybe a few min at most. If you did not refresh or load any pages during that time you missed it completely.

What
09-23-2013, 02:01 AM
i didnt get any pops or redirects, so thats a good thing then?

ZERO
09-23-2013, 02:16 AM
yes that means you did not have any issue.

CYBER
09-23-2013, 02:21 AM
I'm running adblock and adblock plus, and the ads on the right side of the forums are always blocked by the extensions (sorry zero, i have it running 24/7 on all sites, nothing personal:P),

...
would u think that was enough to block the virus from starting to begin with? or should i do a deep scan with avg anyway?

What
09-23-2013, 02:22 AM
yes that means you did not have any issue.

Well thank god, I am not real good with computers and a virus be a pain in my ass to get rid of if AVG wouldn't do it for me

ZERO
09-23-2013, 02:23 AM
it was not in the ads it was a hack that was in the actual header that appears on every page of the website.

XX0wnsXY
09-23-2013, 03:03 AM
any way that this can affect my phone?

ZERO
09-23-2013, 03:05 AM
any way that this can affect my phone?

unlikley

DJ_MikeyRevile
09-23-2013, 04:21 AM
as stated before, it was extremely unlikely that it was being caused by the ads......

What if you are that nervous about a virus get rid of avg and use the following.

http://www.safer-networking.org/

and

http://windows.microsoft.com/en-us/windows/security-essentials-download

both free and take up less cpu combined, then avg.

ZERO
09-23-2013, 04:28 AM
spybot is just for anti spyware and you got to pay for the AV part. BTW has anyone actually used the new free version? I still use 1.6.2.46

DJ_MikeyRevile
09-23-2013, 05:15 AM
spybot is just for anti spyware and you got to pay for the AV part. BTW has anyone actually used the new free version? I still use 1.6.2.46

i know, that is why you double up with MC essentials and set up a weekly scan while you sleep. Id like to think most of us are responsible internet users. Actually, some people with older rigs might notice a performance boost if they stopped using AVG and Avast.

edit: The newest version is awesome, you still need to pay a box price for live protection but you dont need live protection with spybot when using MC essentials.

ZERO
09-23-2013, 05:30 AM
There is no live protection in the older version anyways. I always just used it for the tools, immunization and the weekly manual scan.

Steamer
09-23-2013, 07:17 AM
It was called tea timer. There was also another element of protection from BHO's. These were for root kits, memory injections, and browser objects. These were on some earlier versions way back amr not meant as AV. Mainly highjacking adware.

ZERO
09-23-2013, 07:21 AM
Oh yea there was tea timer but I always disabled it b/c it was annoying as fuck.

Steamer
09-23-2013, 07:31 AM
It indeed was if not highly configured. I also noticed back in the day it cause a bit of lag. The heuristic's were harsh.

brett friggin favre
09-23-2013, 10:44 AM
i hate the newer version with a passion. they changed too much imo.

ZERO
09-23-2013, 11:51 AM
luckily the old one still gets updates :wtg: