Home Discord Chat
Go Back   ChiefsPlanet > Nzoner's Game Room
Register FAQDonate Members List Calendar

Reply
 
Thread Tools Display Modes
Old 02-02-2015, 10:03 PM  
AustinChief AustinChief is offline
Administrator
 
AustinChief's Avatar
 
Join Date: Aug 2000
Location: Austin
Casino cash: $2689112
softwareupdaterlp MALWARE

Ok, there is a nasty piece of malware floating around the web so I thought I'd post the solution to the problem here.

This malware may be keying off certain ads on CP but the ads themselves shouldn't be an issue. Google is claiming to have fixed the previous ad hijack/redirect issue that we saw.

OK, to fix this for PC check this...

http://malwaretips.com/blogs/remove-...rlp-com-virus/

For Mac check this...

https://discussions.apple.com/thread/6802324


Please post here if the problem gets resolved or if it persists. If you have never had the problem (I have yet to see it) then feel free to ignore this.
Posts: 19,495
AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.
    Reply With Quote
Old 02-03-2015, 05:12 PM   #16
ghak99 ghak99 is offline
MVP
 

Join Date: Jan 2007
Location: Missouri
Casino cash: $1942250
My Mac just started redirecting again via Safari and this thread 3 times in a row after force quitting each time.

These redirects didn't appear to be softwareupdater related, but the adds at the bottom of the page have been dominated by malware and virus related advertisements. Seems connected in this case.


The address bar image is hard to read, but I didn't see a softwareuploader connection in it.
Attached Thumbnails
Click image for larger version

Name:	Screen Shot 2015-02-03 at 4.59.29 PMa.jpg
Views:	69
Size:	29.0 KB
ID:	109115   Click image for larger version

Name:	Screen Shot 2015-02-03 at 4.59.29 PMb.jpg
Views:	65
Size:	3.5 KB
ID:	109116  
Posts: 8,199
ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.
    Reply With Quote
Old 02-03-2015, 05:42 PM   #17
penguinz penguinz is offline
Supporter
 
penguinz's Avatar
 

Join Date: Mar 2003
Casino cash: $3117626
Quote:
Originally Posted by ghak99 View Post
My Mac just started redirecting again via Safari and this thread 3 times in a row after force quitting each time.

These redirects didn't appear to be softwareupdater related, but the adds at the bottom of the page have been dominated by malware and virus related advertisements. Seems connected in this case.


The address bar image is hard to read, but I didn't see a softwareuploader connection in it.
Get rid of avast. It contains malware in it.
__________________
Posts: 16,314
penguinz is too fat/Omaha.penguinz is too fat/Omaha.penguinz is too fat/Omaha.penguinz is too fat/Omaha.penguinz is too fat/Omaha.penguinz is too fat/Omaha.penguinz is too fat/Omaha.penguinz is too fat/Omaha.penguinz is too fat/Omaha.penguinz is too fat/Omaha.penguinz is too fat/Omaha.
    Reply With Quote
Old 02-03-2015, 06:09 PM   #18
AustinChief AustinChief is offline
Administrator
 
AustinChief's Avatar
 

Join Date: Aug 2000
Location: Austin
Casino cash: $2689112
Quote:
Originally Posted by ghak99 View Post
My Mac just started redirecting again via Safari and this thread 3 times in a row after force quitting each time.

These redirects didn't appear to be softwareupdater related, but the adds at the bottom of the page have been dominated by malware and virus related advertisements. Seems connected in this case.


The address bar image is hard to read, but I didn't see a softwareuploader connection in it.
Did you follow all the instruction in that thread? One thing it advises to do is to reset your browser and delete all cookie. If you are ok with that, it should keep you from getting the trigger ads displayed so the malware will still likely be on your system but won't activate.
Posts: 19,495
AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.
    Reply With Quote
Old 02-03-2015, 06:36 PM   #19
ghak99 ghak99 is offline
MVP
 

Join Date: Jan 2007
Location: Missouri
Casino cash: $1942250
Quote:
Originally Posted by AustinChief View Post
Did you follow all the instruction in that thread? One thing it advises to do is to reset your browser and delete all cookie. If you are ok with that, it should keep you from getting the trigger ads displayed so the malware will still likely be on your system but won't activate.
I followed the instructions in the pm you sent me which included running both scans and resetting browsers, cookies, and checking for extensions in Safari, Chrome, and Firefox. It seemed to cure the softwareupdater redirecting, but then I was later redirected to the MacKeeper as I mentioned.
Posts: 8,199
ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.ghak99 has parlayed a career as a truck driver into debt free trailer and jon boat ownership.
    Reply With Quote
Old 02-03-2015, 06:56 PM   #20
AustinChief AustinChief is offline
Administrator
 
AustinChief's Avatar
 

Join Date: Aug 2000
Location: Austin
Casino cash: $2689112
Quote:
Originally Posted by ghak99 View Post
I followed the instructions in the pm you sent me which included running both scans and resetting browsers, cookies, and checking for extensions in Safari, Chrome, and Firefox. It seemed to cure the softwareupdater redirecting, but then I was later redirected to the MacKeeper as I mentioned.
Well hell!
Posts: 19,495
AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.
    Reply With Quote
Old 02-03-2015, 07:17 PM   #21
Rams Fan Rams Fan is offline
Greatest QB Duo of 2015
 
Rams Fan's Avatar
 

Join Date: Mar 2010
Casino cash: $2591133
This had been happening to me the past few days. Uninstalled Chrome and downloaded Malwarebytes. Everything's been OK since.
Posts: 17,070
Rams Fan 's phone was tapped by Scott Pioli.Rams Fan 's phone was tapped by Scott Pioli.Rams Fan 's phone was tapped by Scott Pioli.Rams Fan 's phone was tapped by Scott Pioli.Rams Fan 's phone was tapped by Scott Pioli.Rams Fan 's phone was tapped by Scott Pioli.Rams Fan 's phone was tapped by Scott Pioli.Rams Fan 's phone was tapped by Scott Pioli.Rams Fan 's phone was tapped by Scott Pioli.Rams Fan 's phone was tapped by Scott Pioli.Rams Fan 's phone was tapped by Scott Pioli.
    Reply With Quote
Old 02-03-2015, 08:29 PM   #22
Fish Fish is online now
Ain't no relax!
 
Fish's Avatar
 

Join Date: Sep 2005
Casino cash: $2298919
Quote:
Originally Posted by AustinChief View Post
Did you follow all the instruction in that thread? One thing it advises to do is to reset your browser and delete all cookie. If you are ok with that, it should keep you from getting the trigger ads displayed so the malware will still likely be on your system but won't activate.
Hey bud,

I've been in the middle of deploying new machines at work. And in doing so, I tend to browse CP on whatever machine I happen to be working on in the field. I've noticed the issue on brand new retail OS installs. OS X. Chrome/Safari/Firefox. All these machines I installed the OS myself, and know exactly what's been installed. Also running MS Endpoint virus client, OS X malware detection, etc. I have a very advanced knowledge of OS X and all possible locations for running apps, and I can tell you this isn't OS X malware/adware or browser extensions. I'm very familiar with the removal suggestions in the links provided, and this particular issue isn't part of the group of malware/adware that app looks for. Somehow it's being triggered by the ads displayed.

That said, I'd be happy to leverage any quick troubleshooting on OS X/Win 7 vanilla setups if you have anything specific to test. I generally have both vanilla OS X and Windows installs handy, with or without Flash/Java/adblock/etc. Let me know if I can do anything to help.
__________________
Posts: 47,491
Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.
    Reply With Quote
Old 02-03-2015, 08:47 PM   #23
DaveNull DaveNull is offline
Veteran
 
DaveNull's Avatar
 

Join Date: Nov 2011
Location: Villa Straylight
Casino cash: $10005610
Is there another ad network that is a viable option? I feel like the only time I see posts like this on any site I visit is here.

I know you've got to pay the bills but damn. Its harming your users and even when it works properly the ads just torture Safari on iOS.
Posts: 2,367
DaveNull Forgot to Remove His Claytex and Got Toxic Shock Syndrome.DaveNull Forgot to Remove His Claytex and Got Toxic Shock Syndrome.DaveNull Forgot to Remove His Claytex and Got Toxic Shock Syndrome.DaveNull Forgot to Remove His Claytex and Got Toxic Shock Syndrome.DaveNull Forgot to Remove His Claytex and Got Toxic Shock Syndrome.DaveNull Forgot to Remove His Claytex and Got Toxic Shock Syndrome.DaveNull Forgot to Remove His Claytex and Got Toxic Shock Syndrome.DaveNull Forgot to Remove His Claytex and Got Toxic Shock Syndrome.DaveNull Forgot to Remove His Claytex and Got Toxic Shock Syndrome.DaveNull Forgot to Remove His Claytex and Got Toxic Shock Syndrome.DaveNull Forgot to Remove His Claytex and Got Toxic Shock Syndrome.
    Reply With Quote
Old 02-03-2015, 08:48 PM   #24
DaFace DaFace is offline
Kind of a mod
 
DaFace's Avatar
 

Join Date: Aug 2005
Location: Donkey Land
Casino cash: $2046899
Quote:
Originally Posted by Fish View Post
Hey bud,

I've been in the middle of deploying new machines at work. And in doing so, I tend to browse CP on whatever machine I happen to be working on in the field. I've noticed the issue on brand new retail OS installs. OS X. Chrome/Safari/Firefox. All these machines I installed the OS myself, and know exactly what's been installed. Also running MS Endpoint virus client, OS X malware detection, etc. I have a very advanced knowledge of OS X and all possible locations for running apps, and I can tell you this isn't OS X malware/adware or browser extensions. I'm very familiar with the removal suggestions in the links provided, and this particular issue isn't part of the group of malware/adware that app looks for. Somehow it's being triggered by the ads displayed.

That said, I'd be happy to leverage any quick troubleshooting on OS X/Win 7 vanilla setups if you have anything specific to test. I generally have both vanilla OS X and Windows installs handy, with or without Flash/Java/adblock/etc. Let me know if I can do anything to help.
I find it hard to believe that it's client side as well. I've seen it on three computers that I have control over in terms of virus/malware detection, and in all three cases it's happened for an hour or two, then disappeared. Manual scans have revealed nothing.
Posts: 51,757
DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.
    Reply With Quote
Old 02-03-2015, 09:18 PM   #25
AustinChief AustinChief is offline
Administrator
 
AustinChief's Avatar
 

Join Date: Aug 2000
Location: Austin
Casino cash: $2689112
Quote:
Originally Posted by Fish View Post
Hey bud,

I've been in the middle of deploying new machines at work. And in doing so, I tend to browse CP on whatever machine I happen to be working on in the field. I've noticed the issue on brand new retail OS installs. OS X. Chrome/Safari/Firefox. All these machines I installed the OS myself, and know exactly what's been installed. Also running MS Endpoint virus client, OS X malware detection, etc. I have a very advanced knowledge of OS X and all possible locations for running apps, and I can tell you this isn't OS X malware/adware or browser extensions. I'm very familiar with the removal suggestions in the links provided, and this particular issue isn't part of the group of malware/adware that app looks for. Somehow it's being triggered by the ads displayed.

That said, I'd be happy to leverage any quick troubleshooting on OS X/Win 7 vanilla setups if you have anything specific to test. I generally have both vanilla OS X and Windows installs handy, with or without Flash/Java/adblock/etc. Let me know if I can do anything to help.
Thanks man. I think we may be conflating two separate issues though. The softwareupdater thing (this thread) is definitely malware. That doesn't mean the same people aren't also injecting softwareupdater redirect code into google ads but I think that is unlikely. The other issue is purely with Google ads causing redirects. Google claims to have addressed this but if people are still getting them (not softwareupdater) then apparently they haven't.

It's frustrating as hell because I have yet to see either problem myself except when it first started I could replicate it by going to our ad panel and reviewing ads. There I found offending ads and blocked them from being served. I have continued to do so and haven't seen the issue lately.

What would help is if we could determine exactly which ones are occurring NOW (after Google claims to have fixed it) on clean machines.
Posts: 19,495
AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.
    Reply With Quote
Old 02-03-2015, 09:19 PM   #26
AustinChief AustinChief is offline
Administrator
 
AustinChief's Avatar
 

Join Date: Aug 2000
Location: Austin
Casino cash: $2689112
Quote:
Originally Posted by DaveNull View Post
Is there another ad network that is a viable option? I feel like the only time I see posts like this on any site I visit is here.

I know you've got to pay the bills but damn. Its harming your users and even when it works properly the ads just torture Safari on iOS.
Yep, I have reached out to a few and am waiting on them getting back to me. Unfortunately Google is the best one but obviously not if they keep letting this crap happen.
Posts: 19,495
AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.
    Reply With Quote
Old 02-03-2015, 09:26 PM   #27
Fish Fish is online now
Ain't no relax!
 
Fish's Avatar
 

Join Date: Sep 2005
Casino cash: $2298919
The fact that the same exact redirect happens in iOS would rule out malware and point to adware redirect.
__________________
Posts: 47,491
Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.
    Reply With Quote
Old 02-03-2015, 09:30 PM   #28
DaFace DaFace is offline
Kind of a mod
 
DaFace's Avatar
 

Join Date: Aug 2005
Location: Donkey Land
Casino cash: $2046899
Quote:
Originally Posted by AustinChief View Post
Thanks man. I think we may be conflating two separate issues though. The softwareupdater thing (this thread) is definitely malware. That doesn't mean the same people aren't also injecting softwareupdater redirect code into google ads but I think that is unlikely. The other issue is purely with Google ads causing redirects. Google claims to have addressed this but if people are still getting them (not softwareupdater) then apparently they haven't.

It's frustrating as hell because I have yet to see either problem myself except when it first started I could replicate it by going to our ad panel and reviewing ads. There I found offending ads and blocked them from being served. I have continued to do so and haven't seen the issue lately.

What would help is if we could determine exactly which ones are occurring NOW (after Google claims to have fixed it) on clean machines.
It could be two separate issues, but I definitely got the softwareupdaterlp thing as a redirect on a machine that has been scanned and seems to be clean. It hasn't happened in a week or so though.

I suppose conceivably it could be the same site - the redirect gets people fooled into installing it, and then it installs other adware that forces pop ups later.
Posts: 51,757
DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.DaFace is obviously part of the inner Circle.
    Reply With Quote
Old 02-03-2015, 09:56 PM   #29
SPchief SPchief is offline
In Search of a Life
 
SPchief's Avatar
 

Join Date: Feb 2004
Casino cash: $1862905
FWIW I ran malwares and haven't had any issues since. That was around 5 tonight.
__________________
http://give.somo.org/site/TR/Plunge/...nal&fr_id=1244

^^^^^^^^^^
Click here to help with a special cause. Please help me out


Posts: 36,007
SPchief is obviously part of the inner Circle.SPchief is obviously part of the inner Circle.SPchief is obviously part of the inner Circle.SPchief is obviously part of the inner Circle.SPchief is obviously part of the inner Circle.SPchief is obviously part of the inner Circle.SPchief is obviously part of the inner Circle.SPchief is obviously part of the inner Circle.SPchief is obviously part of the inner Circle.SPchief is obviously part of the inner Circle.SPchief is obviously part of the inner Circle.
    Reply With Quote
Old 02-03-2015, 10:05 PM   #30
AustinChief AustinChief is offline
Administrator
 
AustinChief's Avatar
 

Join Date: Aug 2000
Location: Austin
Casino cash: $2689112
Quote:
Originally Posted by Fish View Post
The fact that the same exact redirect happens in iOS would rule out malware and point to adware redirect.
The iOS issue was definitely ad redirects. But "supposedly" Google fixed that... who know though.

Here is another weird thing... I have been doing iOS devel lately so the last 2 months I have primarily been accessing CP from my Mac... and haven't seen the issue once. Just bizarre.
Posts: 19,495
AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.AustinChief is obviously part of the inner Circle.
    Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump




All times are GMT -6. The time now is 11:27 AM.


This is a test for a client's site.
Fort Worth Texas Process Servers
Covering Arlington, Fort Worth, Grand Prairie and surrounding communities.
Tarrant County, Texas and Johnson County, Texas.
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2024, vBulletin Solutions, Inc.