I disabled my ABP and No Script tonight for a brief view of the current environment. If ads are still turned "off", here's what I saw within 2 or 3 minutes. As well as of course the WoW ad, quite frequently.
This is still happening. It happened to me 2x today from two different computers. It's always the first time you navigate to the site. Then it works normally.
Private Mod Note
():
Rollback Post to RevisionRollBack
Quote from Bateleur »
Ambush Krotiq makes me laugh so much. I keep rereading the card and it keeps not having Flash. In what sense is this an ambush again? I just have visions of this huge Krotiq poorly concealed in some bushes, feeling slightly sad that his carefully planned ambushes never seem to work.
I havent been on my regular computer in the past 1-2 days (I have firefox and this has never happened to me on that computer). The computers I haved used have Internet Explorer, and both had me redirected to that site. Thankfully they both have virus protection.
I'm on a school laptop so I don't mind if I somehow get this infected. However, I did take some screen shots. I believe it is the same screenshots that have already been taken.
Someone mentioned that this only seems to happen the first time you visit the site after a reboot or something. I have yet to test this theory but so far today I am beginning to think it is true since I had the pop-up happen once at work on a computer that has never been to mtgsalvation before, and just moments ago on this laptop.
I think an esier way to test this to see if it is true would be to use something like CCleaner to wipe all the temporary files / browsing history and whatnot. Then open your browser and visit mtgsalvation to see if it pops up the fake virus scanner.
If you can repeatedly cause the pop-up to occur you can study whats going on in greater detail. Use some port scanning software (like Nmap) or something to watch the interactions between your computer and the site the pop-up is redirecting you to.
Sorry if any of this is confusing. I'm fairly techy but not always that good at explaining techy stuff.
This pops up occasionally when I try to go to the site. I think it might only happen when I go to mtgs from another website (i.e. not by traveling between mtgs pages) but that might just be a coincidence.
Anyway, finally remembered to take a screenshot, so here it is. Larger one available if that helps.
I think I have been able to track down the ad that has been plaguing us for the past two weeks. It has been removed as of a couple of hours ago.
Please let me know if it happens again. And sadly, for this ad, screenshots won't do it. The only thing that helps is a network log (for example done with Wireshark). I know this is too advanced for most users, but if you are a technical person, this is the right tool.
I am so sorry for the inconvenience caused, and I will do everything in my power to stop these ads from messing up MTGS.
Be advised, I think I got a rootkit from one of these rogue ads. The free program Combofix took care of it, Malwarebytes found a chunk of the trojans, but couldn't find the rootkit. If anyone has any similar issues with actually getting an infection, hit it with Malwarebytes and Combofix.
Private Mod Note
():
Rollback Post to RevisionRollBack
Legacy: TES
EDH: Grand Arbiter $tax, Freyalise Stompy, Mimeoplasm Death From the Grave
Be advised, I think I got a rootkit from one of these rogue ads. The free program Combofix took care of it, Malwarebytes found a chunk of the trojans, but couldn't find the rootkit. If anyone has any similar issues with actually getting an infection, hit it with Malwarebytes and Combofix.
And to throw out another opinion to warn any who might be reading, the professionals do not recommend Combofix for just everyday or casual use. It is a rather complicated tool and should only be used as directed by pros, such as http://forums.spybot.info/forumdisplay.php?f=21 or (I think it is) Bleepingcomputer.com.
MAlwarebytes is good and usable for all. Spybot Search and Destroy (from the above link) is good as well, and offers a free resident scanner when MB does not (but it does take up memory).
Just got to say, you've definitely earned distinction as an MTGS hero
Quote from Stardust »
Because he's the hero MTGS deserves, and the one it needs right now. So we'll global him. Because he can take it. Because he's not just our hero. He's a silent guardian, a watchful protector. An expired rascal.
Quote from LuckNorris »
ExpiredRascals you sir are a god-like hero.
Quote from Lanxal »
ER is a masterful god who cannot be beaten in any endeavour.
An ad popped up on my screen with a "You've been selected as a winner for June 15th" I closed the ad (I had pop up blocker on) and then my browser crashed. I was infected with Vista 2012 AntiVirus trojan.
No screen shot was available because of my firefox crashing.
This happened when traveling from Google to MTGS homepge
**** right after I restarted I got back on to check my mafia games, and it happened again. Malewarebytes got another 10 hits so far. >.<
Hannes, this needs to be fixed.
I had the "fake" antispyware thing happen to me again. I've only been on salvation today on this computer. I was in the EDH forums this time. All these "fake" antispyware programs are triggered and installed through Java. I noticed that Java Script always opens up and the program installs itself. If you guys noticed your Java Script randomly pop up, press Ctrl Alt Delete and go to your Task Manager ASAP. End Task on your Java Script. Then you will see a new process pop up it won't look normal. It will be like 1023082150.exe or kadsjkflawejf.exe or a3wf93jiadw3.exe END TASK this ASAP this is the fake spyware thing. It will change your internet settings, block you from connecting to the internet, and it'll change your homepage to try and make you buy the "real" non-trail version of the program. It's the same as before just a different name.
Note: This has been the first time in a while, probably 2 or 3 months.
I had the "fake" antispyware thing happen to me again. I've only been on salvation today on this computer. I was in the EDH forums this time. All these "fake" antispyware programs are triggered and installed through Java. I noticed that Java Script always opens up and the program installs itself. If you guys noticed your Java Script randomly pop up, press Ctrl Alt Delete and go to your Task Manager ASAP. End Task on your Java Script. Then you will see a new process pop up it won't look normal. It will be like 1023082150.exe or kadsjkflawejf.exe or a3wf93jiadw3.exe END TASK this ASAP this is the fake spyware thing. It will change your internet settings, block you from connecting to the internet, and it'll change your homepage to try and make you buy the "real" non-trail version of the program. It's the same as before just a different name.
Note: This has been the first time in a while, probably 2 or 3 months.
This is basically what happened to me last night. I got the Vista Antivirus 2012 Trojan.
Private Mod Note
():
Rollback Post to RevisionRollBack
Originally Posted by Arcadic View Post
scumbag
Want Higher Level Card Evaluation? Visit Diestoremoval.com
To post a comment, please login or register a new account.
I disabled my ABP and No Script tonight for a brief view of the current environment. If ads are still turned "off", here's what I saw within 2 or 3 minutes. As well as of course the WoW ad, quite frequently.
yeah, I just got the E-Set redirect too. Which is different than what it has been for me.
And if ads have been off, they've never turned off for me.
EDH: Grand Arbiter $tax, Freyalise Stompy, Mimeoplasm Death From the Grave
They promised me improvement, but apparently they have not delivered it yet. I will keep working on it, doing the best I can.
I am so sorry for all the inconvenience caused.
I spent some time double checking all the active ads, and couldn't get it to show.
Just got this ad. It scrolled down the screen.
Because of all the shenanigans lately I have Ad-block Plus installed. ABP was online and active while the ad popped up.
Thanks for all your hard work.
Matt
BUWGRChilds PlayGRWUB
BUWGR Highlander GRWUB
UBSquee's Shapeshifting PetBU
BW Multiplayer Control WB
RG Changeling GR
UR Mana FlareRU
UMerfolkU
B MBMC B
This.
Happened again to me this morning, fwiw.
Fully-powered 600-Card "Dream Cube" https://cubecobra.com/cube/list/dreamcube
450-Card "Artificer's Cube" https://cubecobra.com/cube/list/artificer
Cubing in Indianapolis...send me a PM!!
If you do get redirected to that site cancel the download that pops up
Someone mentioned that this only seems to happen the first time you visit the site after a reboot or something. I have yet to test this theory but so far today I am beginning to think it is true since I had the pop-up happen once at work on a computer that has never been to mtgsalvation before, and just moments ago on this laptop.
I think an esier way to test this to see if it is true would be to use something like CCleaner to wipe all the temporary files / browsing history and whatnot. Then open your browser and visit mtgsalvation to see if it pops up the fake virus scanner.
If you can repeatedly cause the pop-up to occur you can study whats going on in greater detail. Use some port scanning software (like Nmap) or something to watch the interactions between your computer and the site the pop-up is redirecting you to.
Sorry if any of this is confusing. I'm fairly techy but not always that good at explaining techy stuff.
Anyway, finally remembered to take a screenshot, so here it is. Larger one available if that helps.
Very annoying.
WUB Merieke Ri Berit BUW
GWU Phelddagrif 1 2 3 4 UWG
BR Kaervek the Merciless RB
B Chainer, Dementia Master B
WUB Sen Triplets BUW
BG Sisters of Stone Death GB
WUBRG Scion of the Ur-Dragon GRBUW
GWU Angus Mackenzie UWG
R Kumano, Master Yamabushi R
WB Teysa BW
U Higure U
B Geth B
WUBRG Child of Alara 1 2GRBUW
R Zirilan R
U Arcum U
UR Nin RU
BRG Sek'Kuar GRB
U Teferi U
G Melira G
GU Edric UG
BG Glissa GB
Casual
GUB Knacksaw Clique BUG
RWU Sunforger UWR
Please let me know if it happens again. And sadly, for this ad, screenshots won't do it. The only thing that helps is a network log (for example done with Wireshark). I know this is too advanced for most users, but if you are a technical person, this is the right tool.
I am so sorry for the inconvenience caused, and I will do everything in my power to stop these ads from messing up MTGS.
EDH: Grand Arbiter $tax, Freyalise Stompy, Mimeoplasm Death From the Grave
And to throw out another opinion to warn any who might be reading, the professionals do not recommend Combofix for just everyday or casual use. It is a rather complicated tool and should only be used as directed by pros, such as http://forums.spybot.info/forumdisplay.php?f=21 or (I think it is) Bleepingcomputer.com.
MAlwarebytes is good and usable for all. Spybot Search and Destroy (from the above link) is good as well, and offers a free resident scanner when MB does not (but it does take up memory).
Good luck online friends.
http://forums.mtgsalvation.com/showpost.php?p=4557651&postcount=1
TheWarden's Creative Commons Music Pick Project (Retired):
http://forums.mtgsalvation.com/showthread.php?t=336498
Body Count: GRRRUUUUUUUUUUU
إن سرقت إسرق جمل
Level 1 Judge
My Cube for use with 6th ed. Rules
No screen shot was available because of my firefox crashing.
This happened when traveling from Google to MTGS homepge
**** right after I restarted I got back on to check my mafia games, and it happened again. Malewarebytes got another 10 hits so far. >.<
Hannes, this needs to be fixed.
scumbag
Want Higher Level Card Evaluation? Visit Diestoremoval.com
Note: This has been the first time in a while, probably 2 or 3 months.
This is basically what happened to me last night. I got the Vista Antivirus 2012 Trojan.
scumbag
Want Higher Level Card Evaluation? Visit Diestoremoval.com