Forum pages sending me to download the Open Software Updater crap ware

Status
This old topic is closed. If you want to reopen this topic, contact a moderator using the "Report Post" button.
If you switch pages and see your browser being sent to:

httpscolon//softwareupdaterlp.com/campaign/countlight1/?ID=trillmstrcpi2&sub=trillmstrcpi2&S2=wO03N0J7RTAR4JQH0Q0BJT1I

DO NOT CLICK. I am still in the process of figuring whether I accidentally installed this crap as a plug in of Chrome but no avail. I didn't install anything new in the last 5 months, and this just started happening in the last 2 days.

So far, this only happened to me while I was browsing the forums. That's why I post this to see someone else experienced this.

Thanks,
 
Last edited:
Yup, I tried those suggestions before I posted.
There was no new software installed to Window except:
- Firefox 35.01
- Nvidia Audio Driver
- AVG 2015 upgrade
- Adobe Flash Player update
- Google Talk
Scan didn't turn up anything either. I don't rule out the fault was from my side, but it didn't pop (really not a pop up, simply the destination url was hijacked) except browsing the forum. Hence, my post to see anyone experienced the same thing, I certainly hope I am the only one :)

Maybe time to uninstall Chrome clean and resintall ..

Thanks!!
 
LOL, it was back this morning while browsing the forum. Clearly I am not out of the wood, more trouble shooting is needed.

FWIW, the malware link was slightly different this morning. It was to trick the users to install the real malware. The users may think they are updating the browser, but they are actually installing the crap. The Chrome version in the fake page didn't even match my Chrome. So far, I only saw this while I was browsing the forum. I wonder this is any extension to the browser can remember the last, let say, 20 redirections. With that, I should be able to get more info on how it happened.

Thanks,
 
LOL, it was back this morning while browsing the forum. . . .
I saw it yesterday evening (about 18 hours ago) but not yet today. (I've been on this site only about 15 minutes.)

I recall seeing it, or something similar, several months ago - possibly last summer. It stopped showing up after a week or so. I mention this because it's outside your window of "I haven't installed anything in the last 5 months.". That suggests the infection may have happened earlier than you believe, and its been in some kind of hibernation for the past few months.

I'll make an offer to help you get rid of it, though I'm essentially clueless on the subject of viruses & malware so my contribution may be no more than sitting on the sidelines and cheering your efforts.

Dale
 
Well, it happened again about 20 minutes ago. I was looking at Post #2 on http://www.diyaudio.com/forums/software-tools/268746-ltspice-model-file-node-labels.html

Before I hit the browser's "BACK" arrow, I opened Snipping Tool and grabbed the window. (See atch)

In the lower left corner of the window is a message that the window was transferring data from ajax.cloudflare.com...

About 2 seconds after I got back to the Forum, it happened again. The on-screen message may have been worded slightly different. I couldn't grab another screenshot because my Snipping Tool was still full of the first capture. (And, I was losing my nerve to let this thing run rampant on my Personal Confuser while I tried to snap its photo.) This time, the browser said it was trying to transfer data from softwareupdaterlp.com

Don't know if this will be useful or not, but here it is.

Dale
 

Attachments

  • Updater_Grab.PNG
    Updater_Grab.PNG
    345.7 KB · Views: 42
Hi Dale,

It just happened to me 5 mins ago when I tried to read your post!!! So, we experienced this in a relatively close time frame.

After I encountered one more last night with Firefox, I was browsing with Live Header on. Let see it captured the culprit or not.

At this point, I only ran into this while browsing the forum, and my comp was scanned clean by different adware scanner, I suspect a infected banner ad.

Will report again once I inspect the Live Header log. Stay tuned.
 
Here are the headers captured to show what led to the bad site:
----------------------------------------------------------
Windows PC Repair

GET /4b97ef61-fb98-4676-a767-911fb601187c?account=bks&campaign=us&adgroup=1&banner=728-90&it=1422933709243&refurl=http%3A%2F%2Fgoogleads.g.doubleclick.net%2Fpagead%2Fads%3Fclient%3Dca-pub-4152851143442610%26output%3Dhtml%26h%3D90%26slotname%3D1485104632%26adk%3D1881724619%26w%3D728%26lmt%3D1422933708%26flash%3D16.0.0%26url%3Dhttp%3A%2F%2Fwww.diyaudio.com%2Fforums%2Fforum-problems%2F%26dt%3D1422933708672%26bpp%3D4%26bdt%3D361%26shv%3Dr20150129%26cbv%3Dr20141212%26saldr%3Dsa%26correlator%3D571726565100%26frm%3D20%26ga_vid%3D1198369492.1370662917%26ga_sid%3D1422933709%26ga_hid%3D2107695737%26ga_fc%3D1%26u_tz%3D-480%26u_his%3D17%26u_java%3D1%26u_h%3D1200%26u_w%3D1920%26u_ah%3D1163%26u_aw%3D1920%26u_cd%3D24%26u_nplug%3D16%26u_nmime%3D72%26dff%3Dverdana%26dfs%3D13%26adx%3D347%26ady%3D291%26biw%3D1651%26bih%3D1004%26eid%3D317150304%26oid%3D3%26ref%3Dhttp%3A%2F%2Fwww.diyaudio.com%2Fforums%2F%26rx%3D0%26eae%3D0%26fc%3D24%26brdim%3D%2C%2C207%2C59%2C1920%2C0%2C1683%2C1104%2C1669%2C1004%26vis%3D1%26rsz%3D1%7C0%7C%7Cp%26abl%3DXS%26ppjl%3Du%26fu%3D0%26bc%3D1%26ifi%3D2%26xpc%3DDPpbuJ6cgy%26p%3Dhttp%3A%2F%2Fwww.diyaudio.com%26dtd%3D95 HTTP/1.1
Host: sr311.voluumservicer.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://googleads.g.doubleclick.net/...c=DPpbuJ6cgy&p=http://www.diyaudio.com&dtd=95
Cookie: 4b97ef61-fb98-4676-a767-911fb601187c-v4=4b97ef61-fb98-4676-a767-911fb601187c; voluum-cid-v4=%7B%0A%20%20%22cid%22%20%3A%20%22w6RIBRNNI3RRMBSH0SKST1E0%22%2C%0A%20%20%22caid%22%20%3A%20%224b97ef61-fb98-4676-a767-911fb601187c%22%0A%7D

Connection: keep-alive

HTTP/1.1 302 Found
Cache-Control: no-store, no-cache, pre-check=0, post-check=0
Date: Tue, 03 Feb 2015 03:21:48 GMT
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Location: Open Software Updater
Pragma: no-cache
Server: Voluum-Traffic/1.0
Set-Cookie: 4b97ef61-fb98-4676-a767-911fb601187c-v4=4b97ef61-fb98-4676-a767-911fb601187c; Domain=sr311.voluumservicer.com; Path=/; HttpOnly
Set-Cookie: voluum-cid-v4=%7B%0A%20%20%22cid%22%20%3A%20%22wMUM5H14PS7E6BSH09239J4A%22%2C%0A%20%20%22caid%22%20%3A%20%224b97ef61-fb98-4676-a767-911fb601187c%22%0A%7D; Domain=sr311.voluumservicer.com; Expires=Wed, 03-Feb-2016 03:21:49 GMT; Path=/; HttpOnly
Content-Length: 0
Connection: keep-alive

----------------------------------------------------------------------------
Open Software Updater

GET /click.php?ID=trillmstrcpi2&sub=trillmstrcpi2&S2=wMUM5H14PS7E6BSH09239J4A HTTP/1.1
Host: click.bounceads.net
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://googleads.g.doubleclick.net/...c=DPpbuJ6cgy&p=http://www.diyaudio.com&dtd=95
Cookie: __cfduid=d482629a4a39ccc962b842449649c89021422847799
Connection: keep-alive

HTTP/1.1 302 Found
Date: Tue, 03 Feb 2015 03:21:49 GMT
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Location: https://softwareupdaterlp.com/campa...sub=trillmstrcpi2&S2=wMUM5H14PS7E6BSH09239J4A
Server: cloudflare-nginx
CF-RAY: 1b2b8022d01d012d-SJC

----------------------------------------------------------
https://softwareupdaterlp.com/campa...sub=trillmstrcpi2&S2=wMUM5H14PS7E6BSH09239J4A

GET /campaign.php?ID=trillmstrcpi2&sub=trillmstrcpi2&S2=wMUM5H14PS7E6BSH09239J4A HTTP/1.1
Host: softwareupdaterlp.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:35.0) Gecko/20100101 Firefox/35.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://googleads.g.doubleclick.net/...c=DPpbuJ6cgy&p=http://www.diyaudio.com&dtd=95
Cookie: __cfduid=d966e76ee3ea3e0d8222a61a1cd79f8c61422847800
Connection: keep-alive

HTTP/1.1 302 Found
Server: cloudflare-nginx
Date: Tue, 03 Feb 2015 03:21:49 GMT
Content-Type: text/html; charset=UTF-8
Location: /campaign/rushtrust8/?ID=trillmstrcpi2&sub=trillmstrcpi2&S2=wMUM5H14PS7E6BSH09239J4A
CF-RAY: 1b2b802520250657-SJC
X-Firefox-Spdy: 3.1

It appeared to be from an ad served by Double Click. Full log is attached for the web master to report to Google.

At this point, the best defense is to install some extensions to block the site completely.... Just don't click the freaking page.

Thanks,
 

Attachments

  • live_header_captured.zip
    7.1 KB · Views: 22
Live HTTP Headers is a Firefox extension which can be used to inspect the http headers from upon a click. I support my co-workers who work on the web pages. So, I do perform similar tasks to trouble shoot their problems. I am less competent in DIY and am still learning everyday :)
 
Status
This old topic is closed. If you want to reopen this topic, contact a moderator using the "Report Post" button.