Pages: [1]   Go Down
Send this topic | Print
Author Topic: malicious ad url  (Read 345 times)
akaro
Member
*
Offline Offline

Posts: 1


WWW
« on: September 24, 2009, 12:49:47 AM »


My KIS 2010 detects a malicious url on main 110mb.com page in "connect with friends" section:
Please DO NOT OPEN them:
Code:
http://r1rk9np7bpcsfoeekl0khkd2juj27q3o.friendconnect.gmodules.com/gadgets/ifr?url=http%3A%2F%2Fwww.google.com%2Ffriendconnect%2Fgadgets%2Fmembers.xml&container=peoplesense&parent=http%3A%2F%2Fwww.110mb.com%2F&mid=0&view=profile&libs=opensocial-0.8%3Askins&v=0.444.1&lang=en&communityId=01898783130854715924&caller=http%3A%2F%2Fwww.110mb.com%2F

The login page tries to open another malicious url :

Code:
http://hit.clickaider.com/pv?lng=175&&lnks=&t=110MB.com%20-%20Free%20Hosting%20Site%20Everyone%20Loves!&c=6e5ac7a7-608&r=http%3A%2F%2Fwww.110mb.com%2F&tz=180&loc=http%3A%2F%2Fwww.110mb.com%2Flogin.php&rnd=5609

why is that?
Logged
Richard F
Authority Member
****
Online Online

Posts: 697


I'm a Gentoo Man!


WWW
« Reply #1 on: September 24, 2009, 05:49:09 AM »

My guess would be that you have a piece of malicious software on your computer. Quite often adware or spyware puts stuff like that into your websites.
Logged

ultimatebuster
Resident Spammer
Loyal 110MB Member
*******
Online Online

Posts: 3483


Visit TheKKS.Net


WWW
« Reply #2 on: September 24, 2009, 09:38:09 AM »

Scan for viruses. I doubt that 110mb got infected. Some malicious software maybe injecting ad code onto webpages. Check the source and see if you find any similar code on other sites
Logged

EpicCyndaquil
Building an Epic site...
Loyal 110MB Member
*******
Online Online

Posts: 2827


Check out my Porfolio!


WWW
« Reply #3 on: September 24, 2009, 01:28:43 PM »

No, listen to what he says guys. I noticed this too as soon as I updated to KIS 2010.

It claims malware is what it links to. 110mb should be wary of this.
Logged

$$$ - http://linkbee.com/34803
Scour sucks now with their new policy... Use SwagBucks instead to earn for searching! Uses Google + Ask, so you still get good results!
Earn at least $1 in about a minute!! No joke!! - http://www.youdata.com/join/epiccyndaquil
Piotr GRD
Honoured 110MB Member
Official 110mb Guru
*****
Offline Offline

Posts: 6669



WWW
« Reply #4 on: September 24, 2009, 04:57:23 PM »

As far as I know - gmodules.com and clickaider.com are safe.
So we can assume that subdomains of it are safe, too.
Possible that Kaspersky is giving false positive.

If so - 110mb AND ESPECIALLY Google and ClickAider should be aware of this and talk with Kaspersky team about.

« Last Edit: September 24, 2009, 04:59:16 PM by Piotr GRD » Logged

andre
Administrator
Loyal 110MB Member
*****
Offline Offline

Posts: 3122


« Reply #5 on: September 28, 2009, 05:28:45 PM »

Clickaider removed.
Logged

NOTE: ALL PM'S WILL BE IGNORED. UNLESS I ASKED YOU TO PRIVATE MESSAGE ME.

-- Use the "Search" on top-right before posting.
-- If your topic is resolved, put [Resolved] at end of subject.
EpicCyndaquil
Building an Epic site...
Loyal 110MB Member
*******
Online Online

Posts: 2827


Check out my Porfolio!


WWW
« Reply #6 on: September 29, 2009, 09:58:15 AM »

Clickaider removed.
AH HA! So it was something malicious! Thanks for doing something about it Andre.
Logged

$$$ - http://linkbee.com/34803
Scour sucks now with their new policy... Use SwagBucks instead to earn for searching! Uses Google + Ask, so you still get good results!
Earn at least $1 in about a minute!! No joke!! - http://www.youdata.com/join/epiccyndaquil
baby-boomer-rock-and-roll
Member
*
Offline Offline

Posts: 48


WWW
« Reply #7 on: September 30, 2009, 12:20:55 AM »

I was looking for a way to turn off radarurl (there is no option for this in my profile) Anyway I was looking in file manager and I looked in some files put there by 110mb and one file I clicked on was called "editor_images" and within this was a file called "bbutton_3.png" and when I clicked this Avast popped up with a warning :

file name - http://autoonline-advisor.us/
Malware name - HTMLIframe-inf
Malware type - Virus/Worm

AND

File Name - http://updatedownloadcenter2.com/news.php
Malware name - JS:Downloader-EK [Trj]
Malware type - Trojan Horse
VPS version - 090927-0, 09/27/2009

I just clicked abort and got outa there. Is this something 110mb should know about ? Does it mean my site is infected and spreading this stuff ?

BTW I never did find a way to turn off radarurl.
Logged
Clookster
Cookie-eating freak #257
Advanced Authority Member
*****
Online Online

Posts: 1485


I <3 snowboarding & surfing


WWW
« Reply #8 on: October 13, 2009, 12:30:03 AM »

Clickaider removed.
AH HA! So it was something malicious! Thanks for doing something about it Andre.
Not necessarily, but if every antivirus/antispyware/... gives a false positive on it, people will start losing trust in 110mb, because 90% of the people does not even know what a false positive is and blindly trusts their protection software... hence it's was better to remove it.

Note that I'm not saying it is malicious or not... just saying that you don't have to say it is if you're not sure, but just thinking that...
« Last Edit: October 13, 2009, 12:31:53 AM by Clookster » Logged

(\ /)
(O.o)
(> <)
This is Bunny.
Copy Bunny into your signature
to help him on his way to
world domination

Pages: [1]   Go Up
Send this topic | Print
Jump to: