View Active ThreadsCreate an account on HarderFasterLogin to HarderFaster Information for Promoters Information for Advertisers Search HarderFaster About HarderFaster Link to this Page
[HarderFaster] - Work Hard, Play Harder!
Home | News | What's On | Annual Poll | Photos | Forums | DJs | Features | Music | Venues | Reviews | Links |

Register your name List of Members Frequently Asked Questions Terms of use Search HarderFaster
HarderFaster Forums >> HarderFaster: announcements, suggestions and feedback >> There is an ad creating pop ups...

 
Author
Pages (4):  1  [2]  3  4   Post New Thread    Post A Reply
Matt
V2.0

Registered: Apr 2002
Posts: 17728 - Threads: 847
Location: Surrey



Poll Winner!
2016
Honourable Mention
Party Animal

Quote:
ceekay wrote on 22-02-2017 03:21 PM

I did a malware scan, deleted 3 files, opened ONLY this site - lo and behold.
Click here to view original image




That page is showing a skyscraper ad on the lower right - HF doesn't run skyscrapers and nothing in that position.

A quick search suggests it's a browser add-on:

https://www.pcrisk.com/removal-guides/10184-counterflix-ads

Report this post to a moderator | IP: Logged

Old Post23-02-2017 09:02 AM
Matt is offline   Click Here to See the Profile for Matt   Click Here to send a Private Message to  Matt   Click Here to Email Matt   Visit the homepage of Matt       Link to this Post   Quote this message in a PM   Reply Quoting Entire Message   Reply Quoting Last Post   
ceekay
venomous fairy

Registered: Feb 2010
Posts: 39935 - Threads: 1064
Location: In a wide open space



Poll Winner!
2016
Winner
Thread
Honourable Mention
Member

NFI - it seems to be fine again today. Shrugs shoulders



"Do you believe in the devil? You know, a supreme evil being dedicated to the temptation, corruption, and destruction of man?"
"I'm not sure that man needs the help." (Calvin & Hobbes)

Report this post to a moderator | IP: Logged

Old Post23-02-2017 09:15 AM
ceekay is offline   Click Here to See the Profile for ceekay   Click Here to send a Private Message to  ceekay       Link to this Post   Quote this message in a PM   Reply Quoting Entire Message   Reply Quoting Last Post   
Matt
V2.0

Registered: Apr 2002
Posts: 17728 - Threads: 847
Location: Surrey



Poll Winner!
2016
Honourable Mention
Party Animal

Quote:
Matt wrote on 23-02-2017 09:02 AM

That page is showing a skyscraper ad on the lower right - HF doesn't run skyscrapers and nothing in that position.

A quick search suggests it's a browser add-on:

https://www.pcrisk.com/removal-guides/10184-counterflix-ads



I just noticed you've got a banner ad above Photos - that's not from HF either.

HF runs one banner top right, two hot boxes on the home page and one hot box on the music page.

Ouch, cheeky fuckers:

Quote:
Counterflix changes your computer’s DNS servers to ones under their own control. This allows them to not only monitor what sites you are visiting, but to also replace requests from legitimate ad servers with their own ad servers.

These DNS servers are one of the main reasons that people find it difficult to disable Counterflix ads from displaying on their browser. This is because if you uninstall the Counterflix program, but do not disable their DNS servers, they will continue to hijack ads and display ones of their own choosing.

When your machine is infected with the Counterflix adware, other common symptoms include:

* Advertising banners are injected with the web pages that you are visiting.
* Random web page text is turned into hyperlinks.
* Browser popups appear which recommend fake updates or other software.
* Other unwanted adware programs might get installed without the user’s knowledge.

To make matters worse, you will also find that Counterflix will cause your computer to act more sluggish or for your web browser to freeze.



Report this post to a moderator | IP: Logged

Old Post23-02-2017 09:23 AM
Matt is offline   Click Here to See the Profile for Matt   Click Here to send a Private Message to  Matt   Click Here to Email Matt   Visit the homepage of Matt       Link to this Post   Quote this message in a PM   Reply Quoting Entire Message   Reply Quoting Last Post   
ceekay
venomous fairy

Registered: Feb 2010
Posts: 39935 - Threads: 1064
Location: In a wide open space



Poll Winner!
2016
Winner
Thread
Honourable Mention
Member

I flagged it up on here because it wasn't happening on facebook, gmail or bbc and those were the other sites I had open at the time...

Also put up that pic because you can see the counterflix box on it.

It actually got past malwarebytes as well as malware adbytes and was finally banished by Defender (of all things!) following a full system scan. Crafty fucking software indeed...

"Do you believe in the devil? You know, a supreme evil being dedicated to the temptation, corruption, and destruction of man?"
"I'm not sure that man needs the help." (Calvin & Hobbes)

Report this post to a moderator | IP: Logged

Old Post23-02-2017 09:35 AM
ceekay is offline   Click Here to See the Profile for ceekay   Click Here to send a Private Message to  ceekay       Link to this Post   Quote this message in a PM   Reply Quoting Entire Message   Reply Quoting Last Post   
Matt
V2.0

Registered: Apr 2002
Posts: 17728 - Threads: 847
Location: Surrey



Poll Winner!
2016
Honourable Mention
Party Animal

I wondered how a pop-up could hook into HF and not BBC, FB or Gmail and I think it must be google ads. That would give them common code to replace and given how prevalent google ads are, it would make good sense to go for the biggest.

Report this post to a moderator | IP: Logged

Old Post27-02-2017 13:34 PM
Matt is offline   Click Here to See the Profile for Matt   Click Here to send a Private Message to  Matt   Click Here to Email Matt   Visit the homepage of Matt       Link to this Post   Quote this message in a PM   Reply Quoting Entire Message   Reply Quoting Last Post   
ceekay
venomous fairy

Registered: Feb 2010
Posts: 39935 - Threads: 1064
Location: In a wide open space



Poll Winner!
2016
Winner
Thread
Honourable Mention
Member

[Edited by ceekay on 01-03-2017 17:04 PM]

Guess what's back... back again...


May have found the ad though.


This is the log from the clean up file:

THE LINKS ARE FUCKING SPAM - no idea how it's done that.


***** [ Folders ] *****

Folder Found: C:\ProgramData\0732e5c7-0801-1
Folder Found: C:\ProgramData\0732e5c7-0aa5-0
Folder Found: C:\ProgramData\0732e5c7-33b1-1
Folder Found: C:\ProgramData\0732e5c7-3443-1
Folder Found: C:\ProgramData\0732e5c7-3737-1
Folder Found: C:\ProgramData\0732e5c7-38f7-0
Folder Found: C:\ProgramData\0732e5c7-40f5-0
Folder Found: C:\ProgramData\0732e5c7-4237-1
Folder Found: C:\ProgramData\0732e5c7-5791-0
Folder Found: C:\ProgramData\0732e5c7-5a15-0
Folder Found: C:\ProgramData\0732e5c7-5ff3-0
Folder Found: C:\ProgramData\d5588ab2


***** [ Files ] *****

No malicious files found.


***** [ DLL ] *****

No malicious DLLs found.


***** [ WMI ] *****

No malicious keys found.


***** [ Shortcuts ] *****

No infected shortcut found.


***** [ Scheduled Tasks ] *****

No malicious task found.


***** [ Registry ] *****

Key Found: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
Data Found: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{4e0172fc-0c96-4b54-9208-cdcf45ffbc3d} [NameServer] - 82.163.143.176 82.163.142.178
Data Found: [x64] HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{4e0172fc-0c96-4b54-9208-cdcf45ffbc3d} [NameServer] - 82.163.143.176 82.163.142.178
Key Found: HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\26D9E607FFF0C58C7844B47FF8B6E079E5A2220E


***** [ Web browsers ] *****

No malicious Firefox based browser items found.
Chrome pref Found: [C:\Users\Secretary\AppData\Local\Google\Chrome\User Data\Default\Web data] - eu.ask.com
Chrome pref Found: [C:\Users\Secretary\AppData\Local\Google\Chrome\User Data\Default\Web data] - zensearch
Chrome pref Found: [C:\Users\Secretary\AppData\Local\Google\Chrome\User Data\Default\Web data] - v9
Chrome pref Found: [C:\Users\Secretary\AppData\Local\Google\Chrome\User Data\Default\Web data] - uk.ask.com
Chrome pref Found: [C:\Users\Secretary\AppData\Local\Google\Chrome\User Data\Default\Web data] - searchinterneat-a.akamaihd.net


"Do you believe in the devil? You know, a supreme evil being dedicated to the temptation, corruption, and destruction of man?"
"I'm not sure that man needs the help." (Calvin & Hobbes)

Report this post to a moderator | IP: Logged

Old Post01-03-2017 17:02 PM
ceekay is offline   Click Here to See the Profile for ceekay   Click Here to send a Private Message to  ceekay       Link to this Post   Quote this message in a PM   Reply Quoting Entire Message   Reply Quoting Last Post   
Quin.
???

Registered: Oct 2010
Posts: 33316 - Threads: 426
Location: london

.

Click here to view original image


And those who were seen dancing were thought to be insane by those that could not hear the music -Nietzsche

Report this post to a moderator | IP: Logged

Old Post01-03-2017 17:05 PM
Quin. is offline   Click Here to See the Profile for Quin.   Click Here to send a Private Message to  Quin.   Click Here to Email Quin.       Link to this Post   Quote this message in a PM   Reply Quoting Entire Message   Reply Quoting Last Post   
ceekay
venomous fairy

Registered: Feb 2010
Posts: 39935 - Threads: 1064
Location: In a wide open space



Poll Winner!
2016
Winner
Thread
Honourable Mention
Member

Meant to post this there too.

And then I am logging off to thoroughly clean my machine as it won't fucking go away.


Click here to view original image


"Do you believe in the devil? You know, a supreme evil being dedicated to the temptation, corruption, and destruction of man?"
"I'm not sure that man needs the help." (Calvin & Hobbes)

Report this post to a moderator | IP: Logged

Old Post01-03-2017 17:10 PM
ceekay is offline   Click Here to See the Profile for ceekay   Click Here to send a Private Message to  ceekay       Link to this Post   Quote this message in a PM   Reply Quoting Entire Message   Reply Quoting Last Post   
All times are GMT. The time now is 12:05:14         Pages (4):  1  [2]  3  4   Post New Thread    Post A Reply
Forum Jump:

Forum Rules:
You may post new threads
You may post replies
You may post attachments
You may edit your posts
You may delete your posts
HTML code is OFF
BB Code is ON
Smilies are ON
 

HarderFaster Jump
Bookmark and Share
All trademarks and copyrights on this page are owned by their respective companies. All other content is (c) 2001-2024 HarderFaster.

Terms and Conditions | Privacy Statement | Text Mode