»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 12-26-2003, 08:29 AM   #1 (permalink)
Registered User
 
Tazman's Avatar
 
Join Date: Oct 2001
Location: NY
Posts: 893
Tazman is on a distinguished road
Outdoors 3dguru.com + spyware

How low would a tech site stoop to generate income?

See it here. Select the download for Sandra 2004 and agree and you will be highjacked.

I just did this on a customers computer and couldn't beleive it. A full size window opened taking me away from any active windows. I alt+F4'ed and installed Sandra. Then I opened IE to d/l Zone Alarm and instead of yahoo as the homepage it took me to a spyware removal site and ejected the CD drive. Unreal. From a freakin' tech site.

In denial, I fired up my laptop which is up to my standards with security and went back to 3DGuru.com and sure enough it did it again (minus the CD thingy and the home page).

I understand a site needing to put ads up to generate income / pay for bandwidth and don't want to open the old discussions of a few years back, but that's nuts. To give an example, techimo has been my homepage since it was created. I've purchased probably $25K worth of merchandise from newegg this year and never typed the url in the address bar, nor is it in my favorites. I always click on the small logo here.

Maybe 3DGuru needs to host Adaware with the rest of the downloads.

/rant

Mike

Tazman is offline   Reply With Quote
Old 12-26-2003, 08:57 AM   #2 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Lake Helen, FL
Posts: 3,492
TOAD6147 is on a distinguished road
Send a message via ICQ to TOAD6147 Send a message via AIM to TOAD6147
You just never know anymore who's going to zap you with spy/mal-ware. It is a shame but most of these sites are trying to hang on by their fingernails. Not an excuse to be sure but just suggestive reasoning.
BTW, have you sent a complaint to their admin yet? It's definetly something that needs to be done ASAP.
TOAD6147 is offline   Reply With Quote
Old 12-26-2003, 09:01 AM   #3 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Lake Helen, FL
Posts: 3,492
TOAD6147 is on a distinguished road
Send a message via ICQ to TOAD6147 Send a message via AIM to TOAD6147
Quote:
...it took me to a spyware removal site and ejected the CD drive.
Not sure I understand exactly what you're saying it did.
TOAD6147 is offline   Reply With Quote
Old 12-26-2003, 09:11 AM   #4 (permalink)
Banned
 
Siliconjunkie's Avatar
 
Join Date: Feb 2003
Location: Houston, TX
Posts: 1,595
Siliconjunkie is on a distinguished road
Send a message via AIM to Siliconjunkie
Worked like normal for me. Perhaps you had already been infected elsewhere.
Siliconjunkie is offline   Reply With Quote
Old 12-26-2003, 10:07 AM   #5 (permalink)
Registered User
 
Tazman's Avatar
 
Join Date: Oct 2001
Location: NY
Posts: 893
Tazman is on a distinguished road
Quote:
...it took me to a spyware removal site and ejected the CD drive.
.

Sorry I didn't get in too much detail. I forgot what site it was it took me to when I reopened IE (I already removed the spyware). What happend was it changed IE's homepage from yahoo.com to the one of the spyware removal site (something like scansecurity ) and the CD in the CD drive popped out. Then the page said something to the effect that if the CD drive just opened, your computer needs to be cleaned from spyware and prompted me to download the site's program.

Funny thing is, I just spent the last hour trying to duplicate the same thing on 5 other computers. I disabled NAV, google popup blocker, set IE's security to almost nil and I can't get it to do it again .

The CD drive opening from a website had to be done via a script I assume? I know the computer is clean because I just finished formatting / reinstalling XP (that's why I was downloading Sandra). I didn't have Norton installed yet.

I'm holding off on the complaint until I figure out how this happened. The site is set so I can't view the source code so I can't see if there something funky there.

I'm going to finish installing all of the proggies on the computer and tweaking it, then ghost it. I'm then going to restore the computer to an image I took of it just before this happened and see if it does it again. I should just forget about it because I have pleanty to be doing but this was the strangest thing I've seen.


Mike
Tazman is offline   Reply With Quote
Old 12-26-2003, 10:48 AM   #6 (permalink)
Registered User
 
F/A-18 MechDood's Avatar
 
Join Date: Oct 2001
Location: DFW
Posts: 1,128
F/A-18 MechDood is on a distinguished road
Contact 3dguru and let them know what happened. I have downloaded about 5 files from them in the past 2 weeks (Sandra included) and haven't had a problem.
__________________
“MICROSOFT: Where do you want to go today? APPLE: Where do you want to go tomorrow? LINUX: Are you coming or what?”

Yeong-Yang Server Cube
Shuttle AN35N-Ultra
Barton 2500+ @ 3200+ (2.2 ghz) Vcore 1.63 according to CPU-z
Corsair XMS 512mb PC3200 ram oem speed
Alpha PAL-8035 32cfm fan 44°C load
Tyan Tachyon G9700-Pro
WD 80gb 8meg cache 7200rpm
Enermax EG465P-VE(FCA)
Pioneer DVR-106,Liteon 40x CDRW, Liteon DVD-rom
Turtle Beach Santa Cruz
Logitech Z-560
XP Pro
F/A-18 MechDood is offline   Reply With Quote
Old 12-29-2003, 02:42 AM   #7 (permalink)
Registered User
 
Tazman's Avatar
 
Join Date: Oct 2001
Location: NY
Posts: 893
Tazman is on a distinguished road


I tinkered around with this over the weekend. Here's my take (I'm guessing).

I was in a hurry and working on a computer that was freshly formatted. I usually do all of my tweaks, etc. before installing any benchmarking / diagnostic software. One of them is removing Windows messenger (RunDll32 advpack.dll,LaunchINFSection %windir%\INF\msmsgs.inf,BLC.Remove). Because I was in a hurry and got ahead of myself, I'm wondering if I was a victim of the dreaded Windows Messenger Spamming and, in my click-happy hurry, I clicked on a popup.

So I apologize to Guru3D, seems it wasn't thier fault as I've tried to replicate it on a total of 10 different computers now and it never happened again. I'm just glad I was dyslexic when I posted this rant .

Lesson learned: don't surf the net without getting rid of the annoying Windows messenger, install Google popup blocker, A/V. Oh, and be real sure that you know what you are talking about before accusing someone of wrongdoing. I'm glad I didn't contact them, I feel like a moron enough .

Now, off to the confessional to repent for my moronic ways .

Thanks y'all!

Mike
Tazman is offline   Reply With Quote
Old 12-29-2003, 03:56 AM   #8 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Lake Helen, FL
Posts: 3,492
TOAD6147 is on a distinguished road
Send a message via ICQ to TOAD6147 Send a message via AIM to TOAD6147
I didn't know they could say "y'all" in NY. I thought it was against the law or something. Anyway, glad you figured it out.
TOAD6147 is offline   Reply With Quote
Old 12-29-2003, 04:21 AM   #9 (permalink)
Registered User
 
bailey's Avatar
 
Join Date: Oct 2003
Location: Kansas City, Mo.
Posts: 558
bailey is on a distinguished road
would please explaine to me what you mean by getting rid of windows messenger
what is wrong with it ?
bailey is offline   Reply With Quote
Old 12-29-2003, 04:49 AM   #10 (permalink)
Registered User
 
Tazman's Avatar
 
Join Date: Oct 2001
Location: NY
Posts: 893
Tazman is on a distinguished road
Bailey -

This explains it better than I can .

Toad - there probably is a law here about saying "y'all" but I'm exempt because of all the years I lived down south . Hard to get rid of the twang I picked up.

Mike
Tazman is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 11:44 PM.