• Hey Guest. Check out your NeoGAF Wrapped 2025 results here!

Was just redirected to a shady "anti virus" site from a GAF thread

Status
Not open for further replies.

Demon Ice

Banned
Anyone else getting this? It was in the Post pics of yourself thread, went to change pages and got redirected.

Didn't catch the URL before I reflexively backed out.
 
Yeah friend just directed me to this. Gonna run a full scan, if it finds something I'll probably system restore to be safe.

Wait... if it finds something you'll system restore? Do you even know how long you've had that? You could restore back to when you had it. It can probably just remove it.
 
Bumping this as I also got a redirect. And malwarebytes ran clean.

Norton detected it and stopped it, but it may be ad related.

Norton:


Category: Intrusion Prevention
Date & Time,Risk,Activity,Status,Recommended Action,IPS Alert Name,Default Action,Action Taken,Attacking Computer,Attacker URL,Destination Address,Source Address,Traffic Description
6/28/2012 12:20 PM,High,An intrusion attempt by 96.44.181.170 was blocked.,Blocked,No Action Required,Fake App Attack: Fake AV Redirect 21,No Action Required,No Action Required,"96.44.181.170, 80",queerprocessrisksutility.in/78dee9e271084cb2/999/,"(MY PC) ((MY IP), 55396)",96.44.181.170,"TCP, www-http"
 
No I got that same thing like 5 minutes ago. This computer has seemed to be alright before that.
I will run some anti-malware programs, but I looked in my running programs and nothing looked suspicious, so I dunno.


edit: here are some screencaps. Anyone else getting these, or close to these?

5224e59e.png


461816dd.png
 
I keep getting propmts for Java related things from Neogaf.

A few months ago I got repeatedly attacked with malware from neogaf somehow.

Just as the Java prompts started popping up here on Neogaf Ive had my Homepage redirected twice and my actual Neogaf favorite button redirected to another site.
 
I'm sure it happens because some people don't use legit image hosting sites.

Almost 100% sure I keep getting problems from going into the "Pics that make you laugh" thread.

Heres the Java prompt I keep getting from GAF. Ive updated and everything, not sure what it is.
Java.png
 
Queerprocessrisksutility.in is my goto for security information when effeminatewindowsregistrytool.ck is down.
 
Same for me, but this happened at a school library computer. It even finished removing a bunch of files. I feel so stupid because it's dressed up like in XP but I'm using 7. How does this shit get onto GAF?
 
No I got that same thing like 5 minutes ago. This computer has seemed to be alright before that.
I will run some anti-malware programs, but I looked in my running programs and nothing looked suspicious, so I dunno.


edit: here are some screencaps. Anyone else getting these, or close to these?

5224e59e.png


461816dd.png

Ok, just got for the first time right now. I got the other things I posted before but I just got this warning/bullshit for the first time.
 
So uh I clicked this thread an hour ago and got it lol. NICE JOB OP!

Edit: I'm using chrome and if I got it from this thread its most likely an ad and not a picture in the post your pics thread, right?
 
Those warning messages aren't actually malware. They're just a clever piece of social engineering that tries to get you to download the actual malware. As long as you don't actually click on the "protect now" link and run the .exe you'll be fine.

Almost 100% sure I keep getting problems from going into the "Pics that make you laugh" thread.

Heres the Java prompt I keep getting from GAF. Ive updated and everything, not sure what it is.
Java.png

That message should only pop up if you're trying to use a site that uses Java (or a piece of malware that uses Java) and you haven't got Java installed. You're fine.

As far as I'm concerned, unless you really need Java don't install it. The amount of exploits that use Java is ridiculous.
 
From being a techie all my life and countless of times I try to do a system restore in windows, I have NEVER had this work correctly once. Until, last week when my parents XP pc had malware on it. I was in Awe!

It doesn't get rid of the malware it just undoes some of what the malware done did like take over file association.
 
Yeah, I got the "queerprocessutility.in" thing as well. I'm already an hour into scanning my computer with Malwarebytes. So far I haven't noticed anything different.
 
No I got that same thing like 5 minutes ago. This computer has seemed to be alright before that.
I will run some anti-malware programs, but I looked in my running programs and nothing looked suspicious, so I dunno.


edit: here are some screencaps. Anyone else getting these, or close to these?

5224e59e.png


461816dd.png

Hmm, I recall that one being really freaking annoying to get rid of. I may have to lay off GAF for a while if there's an infected ad again.
 
I just got this.

Probably no help, but I clicked on Nottheguyyoukill's user name in the GAF confessional thread to find out what he got banned for and it opened up a link to the above pictured site.

Otherwise, I know nothing.

Running a scan from orbit. The only way to be sure.
 
i just got the pop up box when trying to look at a really old thread. killed chrome without clicking OK and did a MSE scan and it says i'm ok..
 
Hmm, I recall that one being really freaking annoying to get rid of. I may have to lay off GAF for a while if there's an infected ad again.
Is that the one that hides folders and says your hard-drive crashed and a bunch of other parts failed? I remember panicking like hard when I got it.
 
Anyone confirm where it's coming from?

I don't know if it's related to an ad or not, but this seems to be the URL that people get redirected to. - queerprocessrisksutility.in/78dee9e271084cb2/999/ -

I've just checked and it's still live.
 
Status
Not open for further replies.
Top Bottom