Help - Search - Members - Calendar
Full Version: Virus through AYS ad
Get Paid Forum - Get Paid Discussion > Get Paid To Programs > Complaints
erikals88
I clicked on a link sent out on 2/8, where you must make five valid searches to receive credit. The link was rpdir.net/?REQ=FREE+car . As soon as I clicked on this link, I was bombarded with popups and mandatory downloads (you *Must* click this, you must click 'open'...) Norton immediately detected Downloader.trojan trying to download to my pc.

The runner was 200402082326341544. I'm not sure if the first link I clicked on was the same as the runner, and I'm not about to risk finding out laugh.gif

In any case, I posted over in the AYS forum, but thought it would be beneficial to post here as well.

You are warned!!! *eg*
ptrhost
QUOTE
you must make five valid searches to receive credit


Thank you for the heads up. But, this should be reported to the search engine. This is truly disgusting. 5 valid searchs to receive credit. Bull!
erikals88
I'm personally a little more concerned about the virus aspect....flagrant abuse of search engines is too common-place to really offend me anymore...and the lesser of two evils lol
ekelly
Thanks for the info....I found the email in my mailbox and deleted it without clicking. wink.gif
Dreamlab
I clicked on that ad already smile.gif Didn't get the Norton notification (I have Norton installed too and have had so many download.trojan attacks so I know which one you are talking about smile.gif )

Anyway since there are pop-ups spawned from that link, I suspect it came from one of the pop-ups.

Good that you have anti-virus software installed.
trishan
AYS members look out for my ad...My second so I'm all happy about it. It's the one about my sister giving birth...LOL...it's a search but my message is funny...or so I think...
Have a nice day everyone!
princessah
it doesnt say you have to click on 5 results to get credit it says you have to click on 5 to win a car
Jinker
QUOTE (trishan @ Feb 9 2004, 02:28 PM)
AYS members look out for my ad...My second so I'm all happy about it. It's the one about my sister giving birth...LOL...it's a search but my message is funny...or so I think...
Have a nice day everyone!

did you make the joke? mad.gif
erikals88
QUOTE (princessah @ Feb 9 2004, 12:32 AM)
it doesnt say you have to click on 5 results to get credit it says you have to click on 5 to win a car

"CLICK HERE TO GET PAID **CLICK ON 5 RESULTS YOU SEE NO NEED TO SEARCH**
there are 11 companies listed willing to give you free car so click 5 urls you see and see for yourself. click on 5 search results for you to see. Once you do a search or click on 5 results and closes the browser it will ask you if you want to make it a start page, pls. do so and support our site for our country to rise among the shadows."

So what's the difference? Click on 5 search results, or make a search? It's still searching.

I think you missed the purpose of my post, so the point is moot.
princessah
QUOTE (erikals88 @ Feb 9 2004, 01:43 AM)
QUOTE (princessah @ Feb 9 2004, 12:32 AM)
it doesnt say you have to click on 5 results to get credit it says you have to click on 5 to win a car

"CLICK HERE TO GET PAID **CLICK ON 5 RESULTS YOU SEE NO NEED TO SEARCH**
there are 11 companies listed willing to give you free car so click 5 urls you see and see for yourself. click on 5 search results for you to see. Once you do a search or click on 5 results and closes the browser it will ask you if you want to make it a start page, pls. do so and support our site for our country to rise among the shadows."

So what's the difference? Click on 5 search results, or make a search? It's still searching.

I think you missed the purpose of my post, so the point is moot.

well my point is that you dont HAVE to search to get paid the 5 cents which is what your post implied
erikals88
QUOTE (princessah @ Feb 9 2004, 12:52 AM)
QUOTE (erikals88 @ Feb 9 2004, 01:43 AM)
QUOTE (princessah @ Feb 9 2004, 12:32 AM)
it doesnt say you have to click on 5 results to get credit it says you have to click on 5 to win a car

"CLICK HERE TO GET PAID **CLICK ON 5 RESULTS YOU SEE NO NEED TO SEARCH**
there are 11 companies listed willing to give you free car so click 5 urls you see and see for yourself. click on 5 search results for you to see. Once you do a search or click on 5 results and closes the browser it will ask you if you want to make it a start page, pls. do so and support our site for our country to rise among the shadows."

So what's the difference? Click on 5 search results, or make a search? It's still searching.

I think you missed the purpose of my post, so the point is moot.

well my point is that you dont HAVE to search to get paid the 5 cents which is what your post implied

I got your point, and I wasn't *implying* anything. Is this your ad, by chance?

My most abject apologies *curtsy* dry.gif

katgirl3
QUOTE (princessah @ Feb 9 2004, 01:52 AM)
QUOTE (erikals88 @ Feb 9 2004, 01:43 AM)
QUOTE (princessah @ Feb 9 2004, 12:32 AM)
it doesnt say you have to click on 5 results to get credit it says you have to click on 5 to win a car

"CLICK HERE TO GET PAID **CLICK ON 5 RESULTS YOU SEE NO NEED TO SEARCH**
there are 11 companies listed willing to give you free car so click 5 urls you see and see for yourself. click on 5 search results for you to see. Once you do a search or click on 5 results and closes the browser it will ask you if you want to make it a start page, pls. do so and support our site for our country to rise among the shadows."

So what's the difference? Click on 5 search results, or make a search? It's still searching.

I think you missed the purpose of my post, so the point is moot.

well my point is that you dont HAVE to search to get paid the 5 cents which is what your post implied

I believe what erik meant was, this post is about a virus. Not search engines. Thanks for the heads up erik. Found the email and deleted it. smile.gif
princessah
no lol i barely know how to run ads. I appreciate what was said about the virus my only reason for posting is i have seen that people get in trouble for saying you have to click a result to get paid and i would hate to see the wm of ays get into trouble because of someone's ad when they clearly did not say that you had to clikck results to get paid it was some stupid scam to win a car
erikals88
I've seen some programs that require valid searches, but the info posted earlier was direct from the advertiser. "Only U.S. and Canada searches are valid for commissions payment, and pls. don't cheat I can detect multiple ip addresses clicks and only 1 unique I.p. address per 24 hour period is valid."

Even if you don't get the virus from the main site, who's to say the 5 links/search links won't use the same popup spawner?

So, five chances to win a virus aren't worth the 5 cents, 5 clicks, and 60 seconds it takes to get credit laugh.gif
ptre
Thanks a lot !!! I haven't got any trojan remover or spyware remover right now on my computer. I just installed windows XP.

Well, Thanks a Billion for mentioning the runner number as well.

Bye
Saad (Downloading Ad-aware right now)
Susy
I deleted that ad, not because of what's posted here but earlier. Due to the sheer concern I have over the sender, and what might be tracking my computer if I did click it. "Causes" tend to make me worry for my own privacy, more than anything else. wink.gif Also have a problem with the "just click the results". In MOST search engines, that's illegal. You're not supposed to be sending people to a results page at all, and it's abusive. And again, considering this advertiser's way of helping his people(?), kinda bothers me in what's being directed back to them.
Susy
PTRE, add these to your favorites and run them about once a week at least. They're free scans, and work well in conjunction with what you download. They're also updated frequently.

http://housecall.trendmicro.com/

http://www.pandasoftware.com/activescan/co...ang=2&IdPais=63

And don't forget to add Spybot Search & Destroy. You can get a free copy, and I'm sure someone here has the direct addy. It's been so long ago I loaded it, I don't remember exactly how I found it. wink.gif
Mango88
QUOTE (sooozie @ Feb 9 2004, 03:53 AM)
And don't forget to add Spybot Search & Destroy.  You can get a free copy, and I'm sure someone here has the direct addy.  It's been so long ago I loaded it, I don't remember exactly how I found it.  wink.gif

http://spybot.safer-networking.de/

I also recommend you use Ad-aware in combination w/ SpyBot .

http://www.webattack.com/get/adaware.shtml
KimH
QUOTE (sooozie @ Feb 9 2004, 03:53 AM)
PTRE, add these to your favorites and run them about once a week at least. They're free scans, and work well in conjunction with what you download. They're also updated frequently.

http://housecall.trendmicro.com/

http://www.pandasoftware.com/activescan/co...ang=2&IdPais=63

And don't forget to add Spybot Search & Destroy. You can get a free copy, and I'm sure someone here has the direct addy. It's been so long ago I loaded it, I don't remember exactly how I found it. wink.gif

Hi SisterLove,
Thank you for the Panda link, I thought I'd be searching for it half the night. Came here cause TrendMicro hasn't loaded for a couple days and I know that passiton thing is still on here even though I have ran everything else people have listed.
Love you,
Kim
antinomy
I click the same link, but my system worked... copied from the Trojan Horse thread a few days ago... NOT ONE POP UP or problem ensued! YEAH, YEAH...for me, and I really feel for you because I lost TWO desktops last fall to this type of ploy! Hard lesson to learn for me...

PLEASE Take the same steps:

You may not like the length of this, but you may find it saves your PC.

First, load Hi Jack This (available from CNET's Download site: http://download.com.com
BE VERY CAREFUL WITH THIS PROGRAMME and Make a BACKUP before DELETING entries.

Then PROTECT Yourself with the following or similarily excellent tools....

a) Windows Update security patches - should be on your IE menu (I'm assuming you're running IE) got to http://www.microsoft.com/ if you haven't yet done so.

Firewall - I suggest Sygate Personal Firewall as it can be tailored to application rather than every IP address.
http://download.com.com/3000-2092-10247416.html?tag=lst-0-1

c) Antivirus - if you're not using one, Avast's is pretty good
http://download.com.com/3000-2239-10245925.html?tag=lst-2-2 AVAST can check any questionable behaviour.

d) Spyware - I use the following programmes to get rid of and prevent the nasty bugs from scoping my machine....

1. Spybot Search & Destroy -
http://download.com.com/3000-2144-10194058.html?tag=lst-0-1
2. Spyware Blaster - http://www.wilderssecurity.net/index.html
3. MRU Blaster - gets rid of unwanted cookies, ie cache, etc.
http://www.wilderssecurity.net/index.html

e) IE Popup stopper (for the ones which use the MS Messenger function) -
ASHAMPOO IP Spam Blocker
http://download.com.com/3000-2144-10195339.html?tag=lst-0-2

I also set my IE security standards so that files cannot be
downloaded/installed without me knowing about it - I suggest a download manager like DAP http://download.com.com/3000-2071-10248332.html?tag=lst-0-1 which
is one which can catch individual files.

This might seem like a lot. Better safe than sorry....It is worth it, though you'll need to experiment with the settings so that it doesn't interfere with the programmes you really need. I was amazed at the number of things that were continually being "put" on my machine without me knowing about it - even with anti-virus and a firewall.

Hope this helps. Let me know.

This post has been edited by antinomy on Feb 6 2004, 01:19 PM


--------------------

Antinomy Strikes Twice!
http://www.boursesurf.com
Pay-Day Profit Rewards for FREE, 5%/day 7days/week
Want me to build a down-line for you?
Check my PTR list and nominate one which you'd like to trade!
clickcorporation
Yeah, not good.

What exactly was the virus you found?
erikals88
Downloader.trojan. Supposedly it would modify mscache.exe, or perhaps create mscache[1].exe. I dunno. Maybe there's some sort of script that would overwrite my original file on reboot.

Norton blocked it, but you can read about it here http://securityresponse.symantec.com/avcen...der.trojan.html

Apparently it's a program that will DL worms and trojans from multiple sites.
scotian
Yeah...I sure clicked on it...got about 7 popups from it and 3 were from Outwars, I was NOT impressed...I used Housecalls right away but it didn't detect anything so I must not have gotten anything from it...

Will do another scan today though with panda...thanks for the heads up...
erikals88
Well, I'm quite certain it was from that website, as it was the only link I had opened at the time.

But it makes sense that one of the popups could have spawned it, since their origin is another website altogether. And since those are fairly random...*shrug*

I'm surprised that Norton doesn't tell me what website the virus was on. I mean, without downloading the trojan, it was able to tell me what file on my pc it was attempting to modify/create.

Of course, that would make things too easy smile.gif
TonyB
QUOTE (erikals88 @ Feb 9 2004, 01:51 PM)
Downloader.trojan.  Supposedly it would modify mscache.exe, or perhaps create mscache[1].exe.  I dunno.  Maybe there's some sort of script that would overwrite my original file on reboot.

Norton blocked it, but you can read about it here http://securityresponse.symantec.com/avcen...der.trojan.html

Apparently it's a program that will DL worms and trojans from multiple sites.

Robert, of Mystical Maze had this problem the other day. The trojan was embedded in a link to/from TrafficThat Earns. It was not TTEs fault, probably someone who was promoting the program and/or using a rotator.

I'll dig out the thread link.
TonyB
Sorry, I didn't see it in a thread, it came in two emails from Robert:

QUOTE


Hello,

I was getting reports that a url had some nasty pop-ups , and had a application that was taking
over the computer.

I found: trafficthatearns.com/promotion.php?ref=XX
that was attempting to write to my registry, and
deposited an application (mshta.exe) on my hard
drive.

This Link Is Banned!!!!

But not the link:
trafficthatearns.com?ref=xxx that link checked
out fine! Just the link that ends with
promotion.php

Trafficthatearns.com support is on vacation!

My McAfee warned of the suspicious script running
within that page, but the application was still
there!

I suggest you run any adware or virus softwares,
as I\'m not sure what application this is!

Thank You,

Robert Palmer
admin@mysticalmaze.com


and:

QUOTE


Hello,

Ok, this appears to be a windows utility file, that has security holes.

That game/virus whatever it was- was trying to
write to the registry via the Windows mshta.exe
utility file. You don\'t need to delete this file.

Theres alot of info on this file:

mshta - mshta.exe - Process Information
Process File: mshta or mshta.exe
Process Name: Microsoft HTML Application Host
Description: Application used to run .HTA file under windows.It is loaded as soon as a .HTA application needs to run, and then terminates when the application completes.
Company: Microsoft Corp.
System Process: No
Security Risk ( Virus/Trojan/Worm/Adware/Spyware ): No
Common Errors: N/A

But there is a Trojan called VBS_GODWILL.B en
VBS_GODWILL.C, who wants to use mshta.exe

The link in question was using a script that
flagged my McAfee protection. Just run Virus-
spyware software.

The link has been removed, but could be within a
members rotator, and I wouldn\'t know that.

Not blaming anyone for using this link, it could
be a mistake on some java code added to the owners
site for all I know at this point, but that was
a real nasty link! :-/

I will keep you advised!

Thank You,

Robert Palmer
admin@mysticalmaze.com

BobbiePolk
QUOTE (sooozie @ Feb 9 2004, 02:53 AM)
PTRE, add these to your favorites and run them about once a week at least. They're free scans, and work well in conjunction with what you download. They're also updated frequently.

http://housecall.trendmicro.com/

http://www.pandasoftware.com/activescan/co...ang=2&IdPais=63

And don't forget to add Spybot Search & Destroy. You can get a free copy, and I'm sure someone here has the direct addy. It's been so long ago I loaded it, I don't remember exactly how I found it. wink.gif

I agree Soozie, I have the Platinum version of Panda, and it gets everything. Before when I would run Ad-aware and Spybot things would come up to be removed. Since I installed System Mechanic 4 Professional whcih had Panda, I haven't had not 1 thing pop up on my Ad-aware of SB&D. I love it!
qcp
I'm a member of AYS but I haven't seen this yet.Maybe a little behind.This sounds like a serious problem caused by an advertiser,not AYS.Without their knowledge I'm guessing.Has anyone contacted their admin about this?If not, someone should.

qcp
erikals88
QUOTE (qcp @ Feb 9 2004, 06:08 PM)
I'm a member of AYS but I haven't seen this yet.Maybe a little behind.This sounds like a serious problem caused by an advertiser,not AYS.Without their knowledge I'm guessing.Has anyone contacted their admin about this?If not, someone should.

qcp

I know AYS isn't responsible for this virus. It's one of the advertisers, through the pop-ups on their site most likely.

I posted this info in the AYS forum as well. Just thought that this might reach more members, since not all post at AYS.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.