Virus in the ads?

Discuss your questions or comments concerning the Slacker Web Player.

Virus in the ads?

Postby certtrainer on Thu Sep 24, 2009 6:51 am

First- like to say that I love Slacker- been using it for many months now.

But, over the last week, on four different occasions, a Slacker ad in the free version has attempted to launch a .pdf-bourne virus. I am certain it is from the Slacker website (only site open).

It attempts to connect to sites such as:
hkw.ewenona.net/amuw

Have there been any other reports of your ads attempting to propagate a virus? Is there any vetting being done on the content coming from the ads?


Here are my AV logs if you need more info:
9/17/2009 6:41:01 AM 1253187661 SYSTEM 1856 Sign of "JS:Downloader-ED [Trj]" has been found in "http://wqw.vtrxaoh.net/viwm/in.php" file.
9/17/2009 6:43:02 AM 1253187782 SYSTEM 1856 Sign of "JS:Downloader-ED [Trj]" has been found in "C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\18XDFCGK\in[1].htm" file.
9/17/2009 8:34:47 PM 1253237687 SYSTEM 1856 Sign of "JS:Downloader-ED [Trj]" has been found in "http://hkw.ewenona.net/amuw/in.php" file.
9/17/2009 8:34:48 PM 1253237688 SYSTEM 1856 Sign of "JS:Pdfka-PO [Trj]" has been found in "http://hkw.ewenona.net/amuw/pdfNode.php" file.
9/17/2009 9:34:47 PM 1253241287 SYSTEM 1856 Sign of "JS:Downloader-ED [Trj]" has been found in "C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\KJZ17ZRN\in[1].htm" file.
certtrainer
New Slacker
 
Posts: 4
Joined: Thu Sep 24, 2009 5:39 am
Top


Re: Virus in the ads?

Postby RomeE on Fri Sep 25, 2009 2:58 pm

certtrainer wrote:First- like to say that I love Slacker- been using it for many months now.

But, over the last week, on four different occasions, a Slacker ad in the free version has attempted to launch a .pdf-bourne virus. I am certain it is from the Slacker website (only site open).

It attempts to connect to sites such as:
hkw.ewenona.net/amuw

Have there been any other reports of your ads attempting to propagate a virus? Is there any vetting being done on the content coming from the ads?


Here are my AV logs if you need more info:
9/17/2009 6:41:01 AM 1253187661 SYSTEM 1856 Sign of "JS:Downloader-ED [Trj]" has been found in "http://wqw.vtrxaoh.net/viwm/in.php" file.
9/17/2009 6:43:02 AM 1253187782 SYSTEM 1856 Sign of "JS:Downloader-ED [Trj]" has been found in "C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\18XDFCGK\in[1].htm" file.
9/17/2009 8:34:47 PM 1253237687 SYSTEM 1856 Sign of "JS:Downloader-ED [Trj]" has been found in "http://hkw.ewenona.net/amuw/in.php" file.
9/17/2009 8:34:48 PM 1253237688 SYSTEM 1856 Sign of "JS:Pdfka-PO [Trj]" has been found in "http://hkw.ewenona.net/amuw/pdfNode.php" file.
9/17/2009 9:34:47 PM 1253241287 SYSTEM 1856 Sign of "JS:Downloader-ED [Trj]" has been found in "C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\KJZ17ZRN\in[1].htm" file.



We do take this type of report very seriously. While I hadn't responded to this, we have passed this over to our Ad's people. We actually use a number of nationwide ad networks, so none of the ads are handled by us ourselves. The ad networks provide ads to a number of websites (not just Slacker) and are the same ad networks you probably see on your other websites. At this time, I haven't heard of any problems from those ad networks in regards to any type of virus, but we have already contacted them and asked them the same question.

Best regards,
Rome E
Slacker Support
RomeE
Slacker Staff
 
Posts: 1969
Joined: Wed Nov 14, 2007 9:59 am
Location: San Diego, CA
Top


Re: Virus in the ads?

Postby lordratman on Fri Sep 25, 2009 5:32 pm

This is the second time the last 15 minutes that I've been navigated away from slacker without actually clicking on any links.

pescanner1.info

is the general link. Attack site disguised as a free scan. Have to control alt delete to get out of the window. Of course firefox does this wonderful thing were it saves your tabs when the program crashes....
lordratman
New Slacker
 
Posts: 3
Joined: Wed May 07, 2008 4:16 pm
Top


Re: Virus in the ads?

Postby suldae on Fri Sep 25, 2009 11:35 pm

To Lordratman:

I've had the same thing happen to me. The same virus scan thing. At first I thought it was firefox crashing, or my antivirus popping up. But I noticed it was a window in my browser. It's happened to me 4 times tonight, within an hour of the previous occurance. It's extremely annoying.
suldae
New Slacker
 
Posts: 1
Joined: Fri Sep 25, 2009 11:31 pm
Top


Re: Virus in the ads?

Postby DoublEE on Tue Sep 29, 2009 2:13 pm

Malware Torrent Delivered Over Google, Yahoo! Ad Services

Some of the web’s bigger websites were flooded with a torrent of malicious banner ads after cyber crooks managed to sneak them onto syndication services operated by Google, Yahoo, and a third company, according to a security firm.

The ads - which attacked previously-patched vulnerabilities in Adobe’s PDF Reader and Microsoft’s DirectShow - starting appearing on sites such as the DrudgeReport, horoscope.com and lyrics.com last Friday, according to ScanSafe researcher Mary Landesman. They were delivered over networks belonging to Google’s DoubleClick; Right Media’sYield Manager (owned by Yahoo); and Fastclick, owned by an outfit called ValueClick.

End users visiting sites that used the ad syndication services often saw nothing more than a brief flash as the malware-laced ads caused their browsers to open - and then close - a booby-trapped PDF file. But behind the scenes, the payload installed Win32/Alureon, a trojan that drops a backdoor on infected machines.

The malicious ads, which also appeared on slacker.com, ended on Monday, when the website used by the malware purveyors abruptly vanished. During their three-day stint, the attacks accounted for 11 percent of pages blocked by ScanSafe, a service used by businesses to prevent employees from visiting malicious sites.

The report, issued Wednesday, came the same day a Google executive called on internet service providers, website operators, and others to do more to combat malicious ads. Over the past few years, so-called malvertisements - which employ social-engineering and exploit code targeting vulnerabilities in operating systems and applications - have become an increasingly common way of spreading malware to the masses.

Of course, none of this would be possible without the help of the ad syndication services, which provide the software and services webmasters use to display ads to hundreds of millions of end users. DoubleClick, Right Media, and other networks have repeatedly been found to distribute malware-laced banner ads on of the net’s most popular sites.

A spokesman for Google said the content of ads are up to websites that use the service.

“With DoubleClick ad management, publishers are in control of what content they are serving and are therefore ultimately responsible for determining what advertising appears on their site,” a Google spokesman, who asked that his name not be included in this article, wrote in an email. “The publisher sells the space to the advertiser and must approve the content that goes on the site before it is introduced into DoubleClick’s servers.”

No doubt, The DrudgeReport, horoscope.com, lyrics.com, and slacker.com should be called to account for the attacks on their users. And so far, none of those websites has responded to requests to comment. And neither did representatives for Yahoo or ValueClick, either. That doesn’t inspire confidence that any of those companies are doing nearly enough to protect their visitors from a growing threat.
User avatar
DoublEE
Slacker Wannabe
 
Posts: 88
Joined: Tue Oct 28, 2008 4:24 pm
Top


Re: Virus in the ads?

Postby certtrainer on Thu Nov 05, 2009 10:14 am

Here we go again:
Just got another virus attempt- this time a JScript file from cdn.doubleverify.com
certtrainer
New Slacker
 
Posts: 4
Joined: Thu Sep 24, 2009 5:39 am
Top


Re: Virus in the ads?

Postby charles@nyc on Tue Nov 10, 2009 8:50 pm

I got hit with viruses twice in the last few days. It was an "antivirus" program that tries to disable your antivirus program from running a scan. I shut it down using task manager and ran AVG to clean it it out. Now I'm afraid to ever use the site again.
charles@nyc
New Slacker
 
Posts: 1
Joined: Tue Nov 10, 2009 8:39 pm
Top


Re: Virus in the ads?

Postby RomeE on Wed Nov 11, 2009 2:20 pm

charles@nyc wrote:I got hit with viruses twice in the last few days. It was an "antivirus" program that tries to disable your antivirus program from running a scan. I shut it down using task manager and ran AVG to clean it it out. Now I'm afraid to ever use the site again.


If you run into something like this, please contact us via LiveChat. We need to know the ad that is doing this. We are taking these reports very seriously, but we need more information in order to make sure that we are able to assist here.

Thanks,
Rome E
Slacker Support
RomeE
Slacker Staff
 
Posts: 1969
Joined: Wed Nov 14, 2007 9:59 am
Location: San Diego, CA
Top


Re: Virus in the ads?

Postby csa819 on Fri Nov 27, 2009 11:38 am

I've also had issues with popups for fake scans and other assorted malware. Adblock plus took care of it. Don't mind the ads so much, but when they're distributing malware........ When I get another, I'll post details
csa819
New Slacker
 
Posts: 3
Joined: Fri Nov 27, 2009 11:25 am
Top


Re: Virus in the ads?

Postby certtrainer on Tue Dec 01, 2009 6:01 am

...and another one. I am in the middle of something so I don't have time to do a Live Chat- but I did catch that the name of the file it was trying to download was pdf.pdf. The site may have been something like bradtz.net.
It was trying to install Win32/ShellCode.A

Hasn't this been addressed with your ad distributor?
certtrainer
New Slacker
 
Posts: 4
Joined: Thu Sep 24, 2009 5:39 am
Top


Re: Virus in the ads?

Postby csa819 on Sat Dec 05, 2009 12:52 am

I have a Mozilla prism webapp set up with Slacker (slacker's the only site in the instance of the browser), and a spyware scan just found another infection in that app. Seriously guys, that's enough. Please get your ad serving situation under control. Tried to live chat, but it was closed.
csa819
New Slacker
 
Posts: 3
Joined: Fri Nov 27, 2009 11:25 am
Top



Return to Web Player Discussions

Who is online

Users browsing this forum: No registered users and 0 guests