If you switch pages and see your browser being sent to:
httpscolon//softwareupdaterlp.com/campaign/countlight1/?ID=trillmstrcpi2&sub=trillmstrcpi2&S2=wO03N0J7RTAR4JQH0Q0BJT1I
DO NOT CLICK. I am still in the process of figuring whether I accidentally installed this crap as a plug in of Chrome but no avail. I didn't install anything new in the last 5 months, and this just started happening in the last 2 days.
So far, this only happened to me while I was browsing the forums. That's why I post this to see someone else experienced this.
Thanks,
httpscolon//softwareupdaterlp.com/campaign/countlight1/?ID=trillmstrcpi2&sub=trillmstrcpi2&S2=wO03N0J7RTAR4JQH0Q0BJT1I
DO NOT CLICK. I am still in the process of figuring whether I accidentally installed this crap as a plug in of Chrome but no avail. I didn't install anything new in the last 5 months, and this just started happening in the last 2 days.
So far, this only happened to me while I was browsing the forums. That's why I post this to see someone else experienced this.
Thanks,
Last edited:
Yup, I tried those suggestions before I posted.
There was no new software installed to Window except:
- Firefox 35.01
- Nvidia Audio Driver
- AVG 2015 upgrade
- Adobe Flash Player update
- Google Talk
Scan didn't turn up anything either. I don't rule out the fault was from my side, but it didn't pop (really not a pop up, simply the destination url was hijacked) except browsing the forum. Hence, my post to see anyone experienced the same thing, I certainly hope I am the only one 🙂
Maybe time to uninstall Chrome clean and resintall ..
Thanks!!
There was no new software installed to Window except:
- Firefox 35.01
- Nvidia Audio Driver
- AVG 2015 upgrade
- Adobe Flash Player update
- Google Talk
Scan didn't turn up anything either. I don't rule out the fault was from my side, but it didn't pop (really not a pop up, simply the destination url was hijacked) except browsing the forum. Hence, my post to see anyone experienced the same thing, I certainly hope I am the only one 🙂
Maybe time to uninstall Chrome clean and resintall ..
Thanks!!
Thanks for the suggestion. I downloaded it but haven't installed.
Will give it a spin in a moment.
Will give it a spin in a moment.
Clean bill from Malwarebytes, but that was after I resinstall Chrome after a clean uninstall. I hope that was it, crossing my fingers!!
If you're on Windows, use msconfig to look at your startup files. Some of the viruses will plant a startup program there which LOOKS like its innocent, and you quickly get reinfected.
Thankfully I think its gone...... I just tried that link posted above and it said NOT FOUND...
Im sorry you got pchw.. I hope you can get things cleared up soon!!
Im sorry you got pchw.. I hope you can get things cleared up soon!!
LOL, it was back this morning while browsing the forum. Clearly I am not out of the wood, more trouble shooting is needed.
FWIW, the malware link was slightly different this morning. It was to trick the users to install the real malware. The users may think they are updating the browser, but they are actually installing the crap. The Chrome version in the fake page didn't even match my Chrome. So far, I only saw this while I was browsing the forum. I wonder this is any extension to the browser can remember the last, let say, 20 redirections. With that, I should be able to get more info on how it happened.
Thanks,
FWIW, the malware link was slightly different this morning. It was to trick the users to install the real malware. The users may think they are updating the browser, but they are actually installing the crap. The Chrome version in the fake page didn't even match my Chrome. So far, I only saw this while I was browsing the forum. I wonder this is any extension to the browser can remember the last, let say, 20 redirections. With that, I should be able to get more info on how it happened.
Thanks,
I saw it yesterday evening (about 18 hours ago) but not yet today. (I've been on this site only about 15 minutes.)LOL, it was back this morning while browsing the forum. . . .
I recall seeing it, or something similar, several months ago - possibly last summer. It stopped showing up after a week or so. I mention this because it's outside your window of "I haven't installed anything in the last 5 months.". That suggests the infection may have happened earlier than you believe, and its been in some kind of hibernation for the past few months.
I'll make an offer to help you get rid of it, though I'm essentially clueless on the subject of viruses & malware so my contribution may be no more than sitting on the sidelines and cheering your efforts.
Dale
Well, it happened again about 20 minutes ago. I was looking at Post #2 on http://www.diyaudio.com/forums/software-tools/268746-ltspice-model-file-node-labels.html
Before I hit the browser's "BACK" arrow, I opened Snipping Tool and grabbed the window. (See atch)
In the lower left corner of the window is a message that the window was transferring data from ajax.cloudflare.com...
About 2 seconds after I got back to the Forum, it happened again. The on-screen message may have been worded slightly different. I couldn't grab another screenshot because my Snipping Tool was still full of the first capture. (And, I was losing my nerve to let this thing run rampant on my Personal Confuser while I tried to snap its photo.) This time, the browser said it was trying to transfer data from softwareupdaterlp.com
Don't know if this will be useful or not, but here it is.
Dale
Before I hit the browser's "BACK" arrow, I opened Snipping Tool and grabbed the window. (See atch)
In the lower left corner of the window is a message that the window was transferring data from ajax.cloudflare.com...
About 2 seconds after I got back to the Forum, it happened again. The on-screen message may have been worded slightly different. I couldn't grab another screenshot because my Snipping Tool was still full of the first capture. (And, I was losing my nerve to let this thing run rampant on my Personal Confuser while I tried to snap its photo.) This time, the browser said it was trying to transfer data from softwareupdaterlp.com
Don't know if this will be useful or not, but here it is.
Dale
Attachments
Hi Dale,
It just happened to me 5 mins ago when I tried to read your post!!! So, we experienced this in a relatively close time frame.
After I encountered one more last night with Firefox, I was browsing with Live Header on. Let see it captured the culprit or not.
At this point, I only ran into this while browsing the forum, and my comp was scanned clean by different adware scanner, I suspect a infected banner ad.
Will report again once I inspect the Live Header log. Stay tuned.
It just happened to me 5 mins ago when I tried to read your post!!! So, we experienced this in a relatively close time frame.
After I encountered one more last night with Firefox, I was browsing with Live Header on. Let see it captured the culprit or not.
At this point, I only ran into this while browsing the forum, and my comp was scanned clean by different adware scanner, I suspect a infected banner ad.
Will report again once I inspect the Live Header log. Stay tuned.
Here are the headers captured to show what led to the bad site:
It appeared to be from an ad served by Double Click. Full log is attached for the web master to report to Google.
At this point, the best defense is to install some extensions to block the site completely.... Just don't click the freaking page.
Thanks,
----------------------------------------------------------
Windows PC Repair
GET /4b97ef61-fb98-4676-a767-911fb601187c?account=bks&campaign=us&adgroup=1&banner=728-90&it=1422933709243&refurl=http%3A%2F%2Fgoogleads.g.doubleclick.net%2Fpagead%2Fads%3Fclient%3Dca-pub-4152851143442610%26output%3Dhtml%26h%3D90%26slotname%3D1485104632%26adk%3D1881724619%26w%3D728%26lmt%3D1422933708%26flash%3D16.0.0%26url%3Dhttp%3A%2F%2Fwww.diyaudio.com%2Fforums%2Fforum-problems%2F%26dt%3D1422933708672%26bpp%3D4%26bdt%3D361%26shv%3Dr20150129%26cbv%3Dr20141212%26saldr%3Dsa%26correlator%3D571726565100%26frm%3D20%26ga_vid%3D1198369492.1370662917%26ga_sid%3D1422933709%26ga_hid%3D2107695737%26ga_fc%3D1%26u_tz%3D-480%26u_his%3D17%26u_java%3D1%26u_h%3D1200%26u_w%3D1920%26u_ah%3D1163%26u_aw%3D1920%26u_cd%3D24%26u_nplug%3D16%26u_nmime%3D72%26dff%3Dverdana%26dfs%3D13%26adx%3D347%26ady%3D291%26biw%3D1651%26bih%3D1004%26eid%3D317150304%26oid%3D3%26ref%3Dhttp%3A%2F%2Fwww.diyaudio.com%2Fforums%2F%26rx%3D0%26eae%3D0%26fc%3D24%26brdim%3D%2C%2C207%2C59%2C1920%2C0%2C1683%2C1104%2C1669%2C1004%26vis%3D1%26rsz%3D1%7C0%7C%7Cp%26abl%3DXS%26ppjl%3Du%26fu%3D0%26bc%3D1%26ifi%3D2%26xpc%3DDPpbuJ6cgy%26p%3Dhttp%3A%2F%2Fwww.diyaudio.com%26dtd%3D95 HTTP/1.1
Host: sr311.voluumservicer.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://googleads.g.doubleclick.net/...c=DPpbuJ6cgy&p=http://www.diyaudio.com&dtd=95
Cookie: 4b97ef61-fb98-4676-a767-911fb601187c-v4=4b97ef61-fb98-4676-a767-911fb601187c; voluum-cid-v4=%7B%0A%20%20%22cid%22%20%3A%20%22w6RIBRNNI3RRMBSH0SKST1E0%22%2C%0A%20%20%22caid%22%20%3A%20%224b97ef61-fb98-4676-a767-911fb601187c%22%0A%7D
Connection: keep-alive
HTTP/1.1 302 Found
Cache-Control: no-store, no-cache, pre-check=0, post-check=0
Date: Tue, 03 Feb 2015 03:21:48 GMT
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Location: Open Software Updater
Pragma: no-cache
Server: Voluum-Traffic/1.0
Set-Cookie: 4b97ef61-fb98-4676-a767-911fb601187c-v4=4b97ef61-fb98-4676-a767-911fb601187c; Domain=sr311.voluumservicer.com; Path=/; HttpOnly
Set-Cookie: voluum-cid-v4=%7B%0A%20%20%22cid%22%20%3A%20%22wMUM5H14PS7E6BSH09239J4A%22%2C%0A%20%20%22caid%22%20%3A%20%224b97ef61-fb98-4676-a767-911fb601187c%22%0A%7D; Domain=sr311.voluumservicer.com; Expires=Wed, 03-Feb-2016 03:21:49 GMT; Path=/; HttpOnly
Content-Length: 0
Connection: keep-alive
----------------------------------------------------------------------------
Open Software Updater
GET /click.php?ID=trillmstrcpi2&sub=trillmstrcpi2&S2=wMUM5H14PS7E6BSH09239J4A HTTP/1.1
Host: click.bounceads.net
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://googleads.g.doubleclick.net/...c=DPpbuJ6cgy&p=http://www.diyaudio.com&dtd=95
Cookie: __cfduid=d482629a4a39ccc962b842449649c89021422847799
Connection: keep-alive
HTTP/1.1 302 Found
Date: Tue, 03 Feb 2015 03:21:49 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Location: https://softwareupdaterlp.com/campa...sub=trillmstrcpi2&S2=wMUM5H14PS7E6BSH09239J4A
Server: cloudflare-nginx
CF-RAY: 1b2b8022d01d012d-SJC
----------------------------------------------------------
https://softwareupdaterlp.com/campa...sub=trillmstrcpi2&S2=wMUM5H14PS7E6BSH09239J4A
GET /campaign.php?ID=trillmstrcpi2&sub=trillmstrcpi2&S2=wMUM5H14PS7E6BSH09239J4A HTTP/1.1
Host: softwareupdaterlp.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://googleads.g.doubleclick.net/...c=DPpbuJ6cgy&p=http://www.diyaudio.com&dtd=95
Cookie: __cfduid=d966e76ee3ea3e0d8222a61a1cd79f8c61422847800
Connection: keep-alive
HTTP/1.1 302 Found
Server: cloudflare-nginx
Date: Tue, 03 Feb 2015 03:21:49 GMT
Content-Type: text/html; charset=UTF-8
Location: /campaign/rushtrust8/?ID=trillmstrcpi2&sub=trillmstrcpi2&S2=wMUM5H14PS7E6BSH09239J4A
CF-RAY: 1b2b802520250657-SJC
X-Firefox-Spdy: 3.1
It appeared to be from an ad served by Double Click. Full log is attached for the web master to report to Google.
At this point, the best defense is to install some extensions to block the site completely.... Just don't click the freaking page.
Thanks,
Attachments
I never heard of "Live Header", much less tried to analyze one. From your posted example I can comprehend what its trying to do. Let's hope the folks who have their feces amalgamated can track this thing down and annihilate it.
Dale
Dale
Live HTTP Headers is a Firefox extension which can be used to inspect the http headers from upon a click. I support my co-workers who work on the web pages. So, I do perform similar tasks to trouble shoot their problems. I am less competent in DIY and am still learning everyday 🙂
- Status
- Not open for further replies.
- Home
- Site
- Forum Problems & Feedback
- Forum pages sending me to download the Open Software Updater crap ware