View Full Version : More on the hijacking popups here
Elvin Presler
11-24-05, 04:10 PM
OK, they hijack the entire browser window, all of it, including the title bar, tool bars, and address bar. Then clicking anywhere acts as a link to the popup. So it's more being forced to click links than popups. Then it just goes on and on. Every 30 seconds - 2 minutes a new one.
It ONLY happens on this site! So if I am infected with spyware/adware, whatever...I got it here and it only attacks me here. This has been going on for weeks and several clean Windows installs. This is not a knee jerk reaction.
This was the main page when it started just now
http://members.cox.net/elvinpresler/banners.jpg
This was the first popup, flash, but url's are in the title bars on some of them. Probably bull**** urls but....
http://members.cox.net/elvinpresler/popup.jpg
Then, as I am typing this post, this one, when closed it spawns the next one...
http://members.cox.net/elvinpresler/popup2.jpg
The fake warning is spawned from the last popup, then this new one poped up with it as I was trying to printscreen.
http://members.cox.net/elvinpresler/popup4.jpg
This URL was on the address bar of one of them not pictured here:
http://inqwire.com/index_tiny.asp?st=6755&sc=807&lc=18&ld=9&sf=1&flc=3&fld=15&sp=0
einstein_314
11-24-05, 08:17 PM
Have you tried using a different web browser? This is really weird. I have yet to have a pop up from this site. I don't know why you're the only one having this problem. Kinda weird. Makes me think its not the site. But I've read your other thread and it doesn't look like you'r'e infected. Weird.
Have you tried using a different web browser? This is really weird. I have yet to have a pop up from this site. I don't know why you're the only one having this problem. Kinda weird. Makes me think its not the site. But I've read your other thread and it doesn't look like you'r'e infected. Weird.
He's not the only one. I had a problem with this as well though I haven't had a pop up again in a few days.
-=Gib-McFragger=-
11-24-05, 10:12 PM
Did you notice that each popup window including your browser title is followed by "Popup Generator Pro"? You might want to dig deeper into that. ;)
I have been surfing this site since before 2002 (when the server blew up) and I have never, ever, seen a single popup window. Mike doesn't use popups. I think you need to look elsewhere. Something has hijacked your system and although the popups seem to be triggered when you come here, they are not generated FROM here.
Elvin Presler
11-24-05, 11:14 PM
I should have clarified that. That would be because I name it that as a joke. I have a registry file I made that I double click to make a few registry changes quickly when I install Windows that includes my bandwidth connection tweaks and other stuff, including "popup generator pro". I've had it like that for years.
[HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\Internet Explorer\Main]
"Window Title"="Popup Generator Pro"
I am not hijacked. This site, or one of it's banners, or something is the source. I have installed Windows, fresh (not from my backup image even) completely offline, then came straight to this site first thing after connecting my network cable. Nowhere else. And the popups started here...and nowhere else.
If you don't get them, maybe you have a popup stopper working for you or whatever, but these popups are coming from this site. My built in Windows popup stopper is set to medium and Spybot is updated and blocking whatever it blocks...and they still popup here. Not every time I visit, just sometimes.
-=Gib-McFragger=-
11-24-05, 11:16 PM
Oh ok. That's funny because Popup Generator Pro is an actual piece of popup creating software, but you probably already knew that. ;)
Elvin Presler
11-24-05, 11:25 PM
Actually, I didn't. Hahaha. I just thought it was funny, so when I learned to change it years ago, that's what I named it.
einstein_314
11-25-05, 01:05 AM
Well, I just spent half an hour on this site using IE with no pop up blockers, I don't have spybot installed, no MS antispyware. Nothing. IE security set to medium (It won't let it go lower than that for some reason). No pop ups. No freezing. No nothing . Everything was 100% normal.
|JuiceZ|
11-28-05, 11:44 PM
In the 6yrs I've been here, I've never once experienced a popup produced by browsing this site, this includes using IE, Firefox, Opera or any other browser. You have spyware on your machine but it wasn't produced by this site or our web host.
Stupid question: have you tried a different browser? I also find it hard to believe you did a fresh windows install, immediately browsed this site and got pop ups. Doesn't make sense but then again, maybe there's something I'm missing?
oldsk00l
11-28-05, 11:53 PM
I disabled popup blocking just for kicks and uhm, elvin nvnews doesn't generate popups.
Your own system is the source of your problem, sorry to put it that way but...ya gots to hear the truth sometimes :)
Elvin Presler
11-29-05, 12:13 AM
...You have spyware on your machine but it wasn't produced by this site or our web host.
Stupid question: have you tried a different browser? I also find it hard to believe you did a fresh windows install, immediately browsed this site and got pop ups. Doesn't make sense but then again, maybe there's something I'm missing?
Whatever. Believe what you choose, but I did come straight here from a clean install, about 3 times over the last month or so in fact. My system is absolutely clean. The only remote possibility is a banner or something from this site is loading a cookie (I block 3rd party cookies), java script, or whatever. I don't get popups ANYWHERE ELSE, unless of course it's a site known for them...then I fire up Ad Muncher before I go there.
I'm not interested in using another browser. I used Firefox and Opera for a bit and didn't care for them.
I don't always get the popups here either, but when I do, they always behave the same (hijacking the entire browser window), and always happen here, and here only. If I close my browser, delete cookies and clear cache then come straight back, usually all is well....for a while. I have not had any popups for about 3 days now. If I had any kind of spyware, that would not be the case.
The popups were caused by this site or something on it. Period. So don't try to make me look like a clueless fool because "the powers that be" can't keep the advertisers here clean.
-=Gib-McFragger=-
11-29-05, 12:34 AM
Once again, you seem to be the only one getting popups from this site. If this site was indeed the source (which I can assure you it isn't), then don't you think there would be a larger number than one or two people experiencing them?
I am not calling you stupid, I am just saying that there is probably something you missed in the equation ;)
I use IE and Ad Muncher and I don't get any popups. Have you tried updating ad muncher's filters? There was an update not too long ago.
Edit: Actually, are you saying you still get them when ad muncher is running or only when it isn't. I've been running with it off for a while this evening and didn't see any but of course, you say you haven't seen any lately either. Also, when I had ad muncher running, there was a "munched" near the beginning of your post. So, it seems something you posted was being blocked by ad muncher.
|JuiceZ|
11-29-05, 01:21 AM
Whatever. Believe what you choose, but I did come straight here from a clean install, about 3 times over the last month or so in fact. My system is absolutely clean. The only remote possibility is a banner or something from this site is loading a cookie (I block 3rd party cookies), java script, or whatever. I don't get popups ANYWHERE ELSE, unless of course it's a site known for them...then I fire up Ad Muncher before I go there.
I'm not interested in using another browser. I used Firefox and Opera for a bit and didn't care for them.
I don't always get the popups here either, but when I do, they always behave the same (hijacking the entire browser window), and always happen here, and here only. If I close my browser, delete cookies and clear cache then come straight back, usually all is well....for a while. I have not had any popups for about 3 days now. If I had any kind of spyware, that would not be the case.
The popups were caused by this site or something on it. Period. So don't try to make me look like a clueless fool because "the powers that be" can't keep the advertisers here clean.
Why don't you get that chip off your shoulder and insert some logic into your thinking before you start making accusations. Tell me do you not find it odd that out of the millions of pages views this website receives every month, if it was indeed causing popups, don't you think there would be a lot more users complaining about it besides just you?
-=Gib-McFragger=-
11-29-05, 01:34 AM
Why don't you get that chip off your shoulder and insert some logic into your thinking before you start making accusations. Tell me do you not find it odd that out of the millions of pages views this website receives every month, if it was indeed causing popups, don't you think there would be a lot more users complaining about it besides just you?:werd: (mag)
Elvin Presler
11-29-05, 02:52 AM
There are some others who said they had the same problem. As I said, it's not constant, so it's only going to happen when the bad banner, or whatever it is, gets loaded. The only way others would notice this is by visiting with no popup stoppers running, and if the offending banner (or whatever) happens to load, so no, I don't expect the place would get flooded with complaints. It's just a rogue banner or something.
I also said I have had no popups for about 3 days, so it seems the problem, whatever it was, has gone away on it's own. If I had any spyware/adware or whatever on my system, this would not be the case. I would still be getting popups...here and everywhere else.
If I run Ad Muncher, I do not get any popups here. I usually don't run it though except when I am going "surfing" in unknown territory.
I don't have a chip on my shoulder. I only brought this up to inform whoever might want to know about it. It's not a problem for me, I can just block all ads on this site. The point is, I didn't think I had to.
The reason I seem testy about it, is the people who "find it hard to believe I did a fresh windows install, immediately browsed this site and got pop ups" (calling me a liar) and insist I have spyware when there is no way in hell I do, and I think I pretty well demonstrated that in my other thread with all the hijack this logs and task manager screens. Not to mention I already said I have reinstalled Windows, from scratch, completely offline (unplugged network cable) then plugged in and came straight here, and only here, and got the popups. I did this between my first and second posts in this very thread...to make damned sure I wasn't just making an ass of myself.
Elvin Presler
12-09-05, 05:01 PM
They're back. Same hijacking deal.
FYI, I just restored my clean offline backup moments ago too and am reinstalling Far Cry. I've gotten hijacked twice this visit. I went to Rage3d Gaming Forum, then here, nowhere else.
So either these are coming from here, or (conspiracy theory) Rage3d has a malicious script that only activates if the visitor leaves them and comes here. (wham, just got hit again while typing, 3 times now). Usually that is the order I browse in too so....(wham! hit again and AdMuncher is running. I started it after the first hijacking).
As usual, this ONLY happens HERE and nowhere else, and it is random, don't get them every time.
EDIT: This is really wierd. I'm going to stay here while this is happening and try to get logs or something from AdMuncher for you....
Elvin Presler
12-09-05, 05:12 PM
Holy shi*! Here's what I am getting from AdMuncher right now. I cleared the logs first thing and Rage3d is still showing up....Why? Bad Cookie? And why does it only happen here? Is Rage3d trying to make you look bad? Why do I get no popups while visiting them?
Most of this is mumbo jumbo to me, but maybe someone can make sense of it. I have grabbed all my cookies and Temp Internet Folder contents just now as well, if the powers that be would be interested in snooping around in them, I'll be glad to send them to you (1.6 Meg zipped file).
Link Target URL's:
===============
http://www.nvnews.net/vbulletin/profile.php?do=addlist&userlist=buddy&u=27131
http://www.nvnews.net/vbulletin/search.php?do=finduser&u=27131
http://www.nvnews.net/vbulletin/private.php?do=newpm&u=27131
http://www.nvnews.net/vbulletin/member.php?u=27131
http://www.nvnews.net/vbulletin/newreply.php?do=newreply&p=766940
http://www.nvnews.net/vbulletin/editpost.php?do=editpost&p=766940
http://www.nvnews.net/vbulletin/showpost.php?p=766940&postcount=17
http://www.rage3d.com/board/index.php?
Image/Etc Source URL's:
==================
http://www.nvnews.net/vbulletin/images/buttons/quickreply.gif
http://www.nvnews.net/vbulletin/images/buttons/quote.gif
http://www.nvnews.net/vbulletin/images/buttons/edit.gif
http://www.nvnews.net/vbulletin/images/statusicon/user_offline.gif
http://www.nvnews.net/vbulletin/images/icons/icon1.gif
http://www.nvnews.net/vbulletin/image.php?u=27131&dateline=1094323907
http://www.nvnews.net/vbulletin/images/statusicon/post_new.gif
http://www.nvnews.net/vbulletin/images/statusicon/user_online.gif
http://www.rage3d.com/board/images/purerage/site/logo.gif
http://www.rage3d.com/board/clientscript/vbulletin_menu.js
http://www.rage3d.com/board/clientscript/vbulletin_global.js Sending me Java scripts when I am not even at their site? WTF?
http://www.strawberry-red.info/def/45/5010_746.swf
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,29,0
Popup Opening URL's:
================
http://www.strawberry-red.info/def/45/5010.html
Retrieved URL's:
============
http://www.nvnews.net/vbulletin/editpost.php
http://www.nvnews.net/vbulletin/ajax.php
http://www.nvnews.net/vbulletin/images/statusicon/user_offline.gif
http://www.nvnews.net/vbulletin/newreply.php
http://www.nvnews.net/vbulletin/images/gradients/gradient_tcat.gif
http://www.nvnews.net/vbulletin/images/gradients/gradient_panel.gif
http://www.nvnews.net/vbulletin/images/gradients/gradient_panelsurround.gif
http://www.nvnews.net/vbulletin/images/gradients/gradient_thead.gif
http://www.nvnews.net/vbulletin/images/buttons/quickreply.gif
http://www.nvnews.net/vbulletin/images/buttons/quote.gif
http://www.nvnews.net/vbulletin/images/buttons/edit.gif
http://www.nvnews.net/vbulletin/images/statusicon/user_online.gif
http://www.nvnews.net/vbulletin/images/icons/icon1.gif
http://www.nvnews.net/vbulletin/images/statusicon/post_new.gif
http://www.nvnews.net/vbulletin/images/editor/resize_1.gif
http://www.nvnews.net/vbulletin/images/editor/resize_0.gif
http://www.nvnews.net/vbulletin/images/editor/spelling.gif
http://www.nvnews.net/vbulletin/images/editor/separator.gif
http://www.nvnews.net/vbulletin/images/editor/quote.gif
http://www.nvnews.net/vbulletin/images/editor/insertimage.gif
http://www.nvnews.net/vbulletin/images/editor/createlink.gif
http://www.nvnews.net/vbulletin/images/editor/menupop.gif
http://www.nvnews.net/vbulletin/clear.gif
http://www.nvnews.net/vbulletin/images/editor/color.gif
http://www.nvnews.net/vbulletin/images/editor/underline.gif
http://www.nvnews.net/vbulletin/images/editor/italic.gif
http://www.nvnews.net/vbulletin/images/editor/bold.gif
http://www.nvnews.net/vbulletin/images/editor/removeformat.gif
http://www.strawberry-red.info/def/45/5010_746.swf
http://www.rage3d.com/board/
http://www.strawberry-red.info/def/45/5010.html
http://www.foxnews.com/story/0,2933,178282,00.htmlread this ...even thoe we joked about a possible root kit but i think that might be your cause....run this tool...
http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&displaylang=en
let us know how you make out.
Elvin Presler
12-09-05, 06:32 PM
I'm on it....back in a few with result......
Edit: Nope, I'm clean. I still think it is bad Java from here...or Rage3d. I've been cleaning my caches and bouncing back and forth here and there but can't get the popups going again.
http://members.cox.net/elvinpresler/clean.jpg
what about clearing out the precache folder?
Holy shi*! Here's what I am getting from AdMuncher right now. I cleared the logs first thing and Rage3d is still showing up....Why? Bad Cookie? And why does it only happen here? Is Rage3d trying to make you look bad? Why do I get no popups while visiting them?
Your saying that even though you don't have Rage3D open, you are still making outbound requests to Rage3D? I've only seen this kind of behavior when behind a buggy proxy server. Does your ISP use a proxy? Its possible its dishing out those popup ads to you.
Your saying that even though you don't have Rage3D open, you are still making outbound requests to Rage3D? I've only seen this kind of behavior when behind a buggy proxy server. Does your ISP use a proxy? Its possible its dishing out those popup ads to you.
That's what I'm thinking, too. If you are absolutley, positively, without-a-doubt SURE that your system is clean, then this is the only possibility. You would be surprised how vulnerable a system can be, though, even with a fresh install and updates. If you do a fresh install w/out SP2 slipstreamed, you are very vulnerable if you are hooked to ANY network. Even with SP2 slipstreamed, I recommend not even having your network connected physically until firewalling EVERYTHING, installing your Antivirus with recent definitions, and running Spybot immunization. Connect to the internet and get every update from Microsoft immediately. If you don't do this, you can be infected just by sitting on the network. Using IE, however, this doesn't even promise you a lack of infection.
The only way you are getting popups here is going to be found between the chair and the server the site is stored on. If you've done everything right, then its between your computer and the server. Since NO one who has a clean system (even infected systems), other than you, has had an issue with popups it has to be your ISP. Mike does not allow popups on his site and would have a damn fit if there were any on here.
AthlonXP1800
12-14-05, 10:50 PM
I am surprise Elvin still have problems with pop ups, you probably must had missed some important things to do.
Make sure you follow these steps to get rid of pop ups:
1. Check and make sure your Internet Explorer's Privacy is set to Medium-High.
2. Pop up Blocker should be ticked.
3. Download Spyware Doctor (http://www.pctools.com/spyware-doctor/) and also download latest updates for the program and then scanning for spyware.
4. Update your Anti-Virus and Firewall software then do scanning for virus.
Let me know if these steps help you. :)
vBulletin® v3.7.1, Copyright ©2000-2012, Jelsoft Enterprises Ltd.