SaabCentral Forums banner

1 - 20 of 38 Posts

·
Registered
Joined
·
5,297 Posts
Discussion Starter #1
I received similar intrusions on two separate computers, on two browsers, on two networks in the past two days.... they are definitely being served by SC, probably by an ad provider. Capture.JPG
 

·
Registered
Joined
·
5,297 Posts
Discussion Starter #3
The problem happened in both Edge and Chrome.... I don't have FF anywhere. They haven't come back in a couple weeks, so it seems wherever they came from got shut down.
 

·
Administrator
Joined
·
1,102 Posts
This could be a myriad of things, but it wouldn't surprise me if we have already cleared the malicious ads. With help from the community, we regularly clean and prune our ads looking for bad ones just like this. If you run into one again please help us root them out by providing as much of the following information as possible:
  • Device & Version:
  • OS & Version:
  • Browser & Extensions:
  • Screenshot of the issue:
  • URL you were redirected to:
Thanks in advance for helping us keep this site clean and ensuring the ads you see are relevant and of interest to you.

-Gerrit
 

·
Registered
Joined
·
5,297 Posts
Discussion Starter #5
The problem has resurface, for whatever it's worth.

If it helps:

1. Multiple devices, all PC
2. All Windows 10, all 1909
3. Always Edge, always InPrivate mode, no extensions, no add-ins, no nothing
4. I posted a screenshot originally, it's not always possible. Usually I just end the Edge process (taskkill /IM "MicrosoftEdgeCP.exe")
5. As above, I'm not paying a bunch of attention when the screen is commandeered with an annoying PC speaker tone and "YOUR COMPUTER HAS BEEN INFECTED" or whatever

I'll try and grab a screenshot next time it happens. FWIW, I'm a long time system admin and I have complete confidence it's SC serving this stuff up. Zero chance it's anything else.
 

·
Administrator
Joined
·
1,102 Posts
Hello all,

Our team has a bit of a backlog so sorry for any delayed responses.

Right now our main focus is the site speed issues and reviewing spam tools, once those are sorted out we will move back towards adding new features and bug fixes.

No need to report the 500 errors as we are logging them on our side.

Jeff M
 

·
Registered
Joined
·
5,297 Posts
Discussion Starter #7
Here is an example of malware served by SC... seems unlikely it's an exploit of the site, more likely malware being served by an advertiser.

It's admittedly hilarious, but, you know, not good.
 

Attachments

·
Registered
Joined
·
5,297 Posts
Discussion Starter #10
The problem stopped for a week or so, but resurfaced again last night. I will try and grab URLs next time they show up. As you can imagine, I'm hesitant to let them remain up for very long.
 

·
Registered
Joined
·
5,297 Posts
Discussion Starter #11
Here's one:

Code:
https://pkiniswve.club/minip/index.php?lpkey=154f858a9313760089&clickid=0b7a46jd552dza04&uclick=vc3va0i4&uclickhash=vc3va0i4-6jd552dz-vr-vr-170-ntfe-wf3y-6064a1#
Literally popped up in the middle of typing a reply.
 

·
Registered
Joined
·
5,297 Posts
Discussion Starter #12
Another:

Code:
https://windowsappcenter.360securesa-safeaa.live/esqmfcrd204/?utm_source=dhara1&utm_pubid=9ddce5b1-9e76-4334-b338-66bd549a3f52&x-context=w2tf11msok4a8c4u1sm3bgae
 

·
Registered
2000 93 Vert Auto : 2001 93 Vert Manual
Joined
·
53 Posts
As of Saturday I am having issues with screen takeovers from Norton and Flash. I am using Safari. It only happens when visiting this site.

To get it to stop I have to completely close Safari or sometimes I can just hit the back button.
 

·
Registered
Joined
·
5,297 Posts
Discussion Starter #14
Another:

Code:
https://user-expdatisu.club/main-d/index.php?lpkey=158d861f181a83fe92&clickid=72d608wxobgvr5a6&uclick=8wxobgvr&uclickhash=8wxobgvr-8wxobgvr-vr-0-vr-4kfe-x9-fd4b6a#
 

·
Registered
Joined
·
5,297 Posts
Discussion Starter #17
Again -

Code:
https://windowsappcenter.antiwindows.space/esqmfcrd204/?utm_source=dhara1&utm_pubid=464aee48-c976-460b-91b8-d22340b483fc&x-context=w06g59get7p5gi6uhlms8sf6
 

·
Registered
Joined
·
5,297 Posts
Discussion Starter #18
Zazz - please encapsulate your posts in "code" boxes, otherwise someone can click on them!!!
 

·
Registered
Joined
·
5,297 Posts
Discussion Starter #19
Another -

Code:
https://actuinternet.com/norton/antivirusgreen.html?cep=yN_I5sq6nSPGL0kqmdWsml5F1YHdnp9ehLInUiLa5PV_3KdNS08_XOzGTvSmone1fsnxQB6vdpfLH2B3UqsiaEWGswv8rB2LM2gyU1tj7gPZ-ulJPHTZr8lWmzp0bFa1RoH4Xd74V0TId8p6SIQt6fZ0iuO0UB0j4VckCaY25KPMD5MuwyCahuqv0VrbrZ20MYqEKRAP-WL2R9zEuaYIA_djh-cYrKMj91ckLhsp8xixxpfJDZVqLrXL6nLX8YQrP2tzGAu9h04C_xhHwapzJCvg8neBag8R6JGtF9LP-JNzz4wfFNd6a-8fAbdUHzO7m4-fwgwc7S3Iv9McJYeTEIy2ur_eTrJj1Ui4NLTRc-UB5alBm8j6X8WecSqwqB_cwMZCsBEAkXe3DDDmbS-pOZsjk72cM-fWgHrOUPeRbQxXe2DhPZ8TOGVyZ5CbVQO16BbKypnq3kTuRTouTcw3vQ&lptoken=15a1864d31ac395d74b5#
 
1 - 20 of 38 Posts
Top