ublock log (trying to get to the bottom of some adware)

4.9K Posts



in Techie Stuff
ublock log linked; really struggling to find some Malware on a neighbours computer (would have been much easier to clean install but its not going to beat me). Done all the usual checks including root scan. Kaspersky Internet Security is installed - you can see it kicking in at various points in the log.
What happens? (Randomly, starting at the bottom of the log file) type bbc.co.uk in Firefox and a new adware tab opens - freelotto.com - in this case. (top of log)
https://expirebox.com/download/378342b0fac1ea7343459ea09fdaa0e8.html
What happens? (Randomly, starting at the bottom of the log file) type bbc.co.uk in Firefox and a new adware tab opens - freelotto.com - in this case. (top of log)
https://expirebox.com/download/378342b0fac1ea7343459ea09fdaa0e8.html
If you put your general location in your Profile, somebody here may be able to come and help you.
0
This discussion has been closed.
Latest MSE News and Guides
Replies
Can't see much wrong with the BBC story source
I've never had the need to use noscript (and am java/script ignorant) but seeing all those .js files in the ublock log has me thinking I cannot ignore it.
One problem is the randomness of the adware; its very difficult to repeat.
Things start to go wrong (I think) when the following scripts are run
http://service.maxymiser.net/cdn/mbbccoUK/js/mmcore.js
http://b.scorecardresearch.com/beacon.js
which I'll look up now.
service.mymaxymiser.net as 0.0.0.0 (ie black hole)
ditto b.scorecardresearch.com
so i don't see anything like that
try copying this in the hosts and retry
Process explorer also reveals hidden software. Also look under the virusTotal column and the company, path and verified signer columns for rougues.
to be honest I would install another browser like my favorite slimjet, just to isolate if it is a pc/dns, or browser issue
this may help, but may not too http://www.nirsoft.net/utils/tcp_log_view.html and expand the window
Part of my hosts file looks like this
# [Doubleclick (Google)]
0.0.0.0 ad-g.doubleclick.net
0.0.0.0 ad.doubleclick.net
0.0.0.0 ad.mo.doubleclick.net
0.0.0.0 doubleclick.net
0.0.0.0 googleads.g.doubleclick.net
and it seems to help. Therefore I may be proactive and add freelotto.
Try typing directly:-
212.58.244.67
for the BBC, and it should go there directly, albeit to a page you dont want. Avoiding some of the lookup and mis-direction.
I haven't been able to repeat the issue. Still getting these for bbc:-
(which may be normal)
http://service.maxymiser.net/cdn/mbbccoUK/js/mmcore.js
http://static.chartbeat.com/js/chartbeat.js
http://edigitalsurvey.com/l.php
I had Adblock Plus and NoScript for years and only just swapped to uBlock which is wow... Why didnt i try it sooner?
I do wonder if uBlock makes Noscript worthless though?
Run adwcleaner
https://www.malwarebytes.com/adwcleaner/
Check report is not picking up any false positive and nuke away when done.
Install another browser
Create a new username and see if it does same thing
disable all add ons in firefox and see if remains
Good luck!