GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Spyware is Killing our industry. Proof inside! Long Thread and VIDEO (https://gfy.com/showthread.php?t=720781)

Quickdraw 04-04-2007 03:34 PM

Quote:

Originally Posted by tolik (Post 12196005)
triplexporn.org(an ESTDOMAIN) came from Tolik's sig btw.
also on triplexporn is a javascript that includes /cgi-bin/counter2.pl which has this code-- blablabla

who care what code have img src what wroting 0*0 image at bottom of page?

and i cannot get at all where you get and for what this at all frame/iframe breaking code what you posted?

and also - for what this here:
_____________________________
which contains a popup to--
nichetgp.com/amateur/in.cgi?a=340
_____________________________

i never traded or have a links to this site.
if some toplist open this link for some countries - not for me or i have popup blockers on.

cannot understand what relation this have to me?

Your counter2.pl redirects to triplexporn.org/err.html which has the frame breaker code you asked about.
This err.html redirects to erotiqsex.com/cgi-bin/td/tfr.pl?act=out&acc=topyo which earlier had the popup to nichetgp, but now amazingly is 404

As far as how it relates to you. Well these were sites that you force traffic to, so anyone that trades with you is essentially getting their traffic infected with the sites where you force traffic.

You are right, everyone has a choice with who they trade with, and honest webmasters don't like to trade with sites that get their potential customers infected with shitware.

tolik 04-04-2007 03:36 PM

Quote:

Originally Posted by Quickdraw (Post 12196127)
Your counter2.pl redirects to triplexporn.org/err.html .

did you have any idea what will be if img src html file?

as i see no.

Quickdraw 04-04-2007 03:44 PM

Quote:

Originally Posted by tolik (Post 12196141)
did you have any idea what will be if img src html file?
as i see no.

Makes no difference to me.
The point is your site forces traffic to places on the web that infect users with trojans/malware/zango and whatever else.

tolik 04-04-2007 03:50 PM

yes. very clever. sure. i forcing traffic using img scr of html site.
go faster register pattent for this new technology.
you will be reach in seconds.

Quickdraw 04-04-2007 03:59 PM

Quote:

Originally Posted by tolik (Post 12196249)
yes. very clever. sure. i forcing traffic using img scr of html site.
go faster register pattent for this new technology.
you will be reach in seconds.

Sorry, you can try to deflect this all you want, but your trade script specifically is what I am referring to. The err page just tied you to more shit sites.
Your site forces traffic to these sites--
xtoplist.com/topteen/toplist.php3?Action=In&Login=porevo -- a zango spot
and
top-amateur.com/?28363 a site that is explained above

u-Bob 04-04-2007 04:19 PM

Quote:

Originally Posted by tolik (Post 12195319)
Registrant Organization:UltraHoster
this company registering domain under esthost. does not see any problem here.

1. ultrahoster = russian
2. ultrahoster.com = a domain used in tons of guestbook (and other) spam campaigns.
3. ultrahoster.com is on several spyware lists (including the coolwebsearch (=spyware) domain lists)

tolik 04-04-2007 04:36 PM

Quote:

Originally Posted by u-Bob (Post 12196464)
1. ultrahoster = russian
2. ultrahoster.com = a domain used in tons of guestbook (and other) spam campaigns.
3. ultrahoster.com is on several spyware lists (including the coolwebsearch (=spyware) domain lists)

so - how this related to me if i just purashed domains using this company?
and this was been more then 2 years ago. what wrong with this?

joy 04-05-2007 06:19 AM

This thread keeps getting better by the day.

kektex 04-10-2007 07:54 PM

I like this thread

maalox 04-10-2007 09:14 PM

Great thread thanks for the info
If you are using xclicks.net here's all you have to do:cut-copy-paste this into the banned page in your script:
83.69.20.130, 81.169.224.98, 83.188.23.87, 70.84.80.50, 88.85.81.195, 72.55.148.87, 85.255.127, 85.255.121, 85.255.120, 85.255.119, 85.255.118, 85.255.117, 85.255.116, 85.255.115, 85.255.114, 85.255.113, 85.255.112, 69.50.191, 69.50.190, 69.50.189, 69.50.188, 69.50.187, 69.50.186, 69.50.185, 69.50.175, 69.50.169, 69.50.170, 69.50.168, 209.51.132.202, 209.8.19.242, 72.232.215.77, 72.232.215.74, 72.232.194.58, 216.255.178, 72.232.215.76, 216.255.178.60, 67.15.187.2, 216.240.149, 216.255.178, 70.84.80, 66.29.35.37, 74.52.6.43, lookmycunt.com,
mpeggalls.com, youngperfection.net, sexymovs.com, trygirls.com, pinkypussies.com, good-teens.com, teensinlaw.com, smokyvids.com, angelsvids.com, mixteenies.com, teensseduction.com, chickswar.com, pushpussy.com, hardsaloon.com, pinkyteenies.com, sappypussy.com, dullworld.com, perkyteenies.com, onlinesexmovie.net, pjunkie.net, brothervids.com, extrablow.com, fuckingcraft.org, 100freegalls.com, tgpporn.net, startfreevideo.com, sexgall.net, hotdailynudes.com, mashathumbs.com, shyteenies.com, yourthumbnails.com, xxxdesert.com, asianscity.com, girlsrussian.net, pornstarocean.com, lovelyteenvids.com, porn-cinema.net, need4pornvids.com, 216.255.189.123, 70.84.80.50, 216.255.189, 216.240.149.117, 66.29.35, 74.52.6, 216.255.189, 216.255.176.124, 74.52.6.43,
216.255.176, 216.255.178.52, 91.192.117.46, 69.50.160, 69.50.161, 69.50.162, 69.50.163, 69.50.167, 69.50.166, 69.50.165, 69.50.164, 69.50.171, 69.50.172, 69.50.173, 69.50.174, 69.50.176, 69.50.177, 69.50.178, 69.50.179, 69.50.180, 69.50.181, 69.50.182, 69.50.183, 69.50.184, 85.255.122, 85.255.123, 85.255.124, 85.255.125, 85.255.126, 88.151.106.252, 81.169.235.6, 81.169.234.219, 69.166.67.221, 91.192.117.46, 72.232.65.178, 64.151.36.201, 86.57.128.201, 91.124.155.94

AK 04-10-2007 10:39 PM

Quote:

Originally Posted by A1R3K (Post 12188604)
edit: fuck it. no one listens anyhow.

hey bro.. would you like a Fuck Spyware T shirt?

http://justak.com/fspyware

Ray@TastyDollars 04-11-2007 03:24 PM

Quote:

Originally Posted by AK (Post 12234317)
hey bro.. would you like a Fuck Spyware T shirt?

http://justak.com/fspyware

Haha nice!

MrCain 04-11-2007 03:42 PM

Fuck Spyware.

Quickdraw 04-26-2007 07:32 AM

Back to what the original post in this thread was about.
If you haven't installed this stuff, you should find a way to research it further.
This affects anyone that buys traffic via PPC engines, gets natural traffic from the SE's, or even has just a little bit of traffic.

Say for instance that a surfer with this malware searches for "thehun.net" into google. The first result is of course thehun.net, but clicking on it won't get you there.
After several clicks that surfer might actually get to TheHun, but clicks from there are just redirected as well. This scenario seems to ring true for most sites and all keywords. Users are redirected to either their(zlob) sponsor, or redirected through a PPC engine to another destination.

If you use any of the smaller ppc engines, search123, goclick, searchfeed etc., you might have noticed a huge drop in your campaign returns since this scumware(moviebox,zlob) came out, especially for more generic terms.

There is a lot more to it, if you have a spare computer, check it out. You might be surprised :(

Quickdraw 04-30-2007 07:19 AM

Anyone else watch the videos or download this MOVIEBOX 'codec'?
http://img89.imageshack.us/img89/653...ivexvidbt6.jpg

joy 05-04-2007 03:51 AM

May 4th. This is why sales are down to the point that they are the past 3-4 days

Sponsors need to open their eyes and look at the big picture. Look at your sales the past 3-4 days, compare your join page VS 1st bill page. You will see that your join page traffic has not changed, however your biller page traffic went to shit.

shermo 05-04-2007 05:08 AM

Bump for an interesting thread which is posing a real issue to this industry. This needs to be stopped, and learning about it's workings is the first step. :thumbsup

StarkReality 05-04-2007 06:08 AM

This thread would deserve a STICKY !

Voodoo 05-04-2007 06:36 AM

Simple.

GEOIP check the user's country on ALL of your sites. If the user/webmaster is from Russia... Send them to an auto-install badware page that monetizes off of their legacy of scamming and unscrupulous methods of doing business.

martinsc 05-05-2007 10:19 AM

bump bump bump

Big_Red 05-05-2007 10:25 AM

100.....,..

joy 05-07-2007 05:11 AM

Notice your sales on May 2, 3, 4, 5th? Now watch what happens as of 6th.

If we all dont unite and do something the sky WILL fall

timberlands 05-07-2007 05:18 AM

spyware doctor = best anti spyware program.

joy 05-07-2007 08:44 AM

Quote:

Originally Posted by timberlands (Post 12384611)
spyware doctor = best anti spyware program.

Nope, once infected with the stuff in this thread there is not much they can do except reinstall.

The best solution (besides taking these fuckheads down..thats in the works btw) is to make the surfers awear.

StickyGreen 05-07-2007 06:31 PM

Bump.../

Andreas 05-08-2007 03:58 AM

i lost about 80% of my sales mostly from payed spots from GTS :(

Humpy Leftnut 05-08-2007 04:06 AM

lol what? You bought GTS traffic and then suddenly your sales took a nosedive?

Corleone 05-08-2007 04:33 AM

very good thread

Andreas 05-08-2007 06:50 AM

Quote:

Originally Posted by Humpy Leftnut (Post 12390848)
lol what? You bought GTS traffic and then suddenly your sales took a nosedive?

I've been buying gallery spots from them for a long time not that i bought it now for the first time then the sales went down :) I am saying that sales are down 80% from those spots compared to a few weeks ago.

VforVendetta 05-08-2007 08:46 AM

today bump

RawAlex 05-08-2007 08:54 AM

The truly big issue here is that the program owners aren't feeling any pain because sales continue for them, just different affiliates are getting credited for the sales. Something will happen when the spyware guys start massively redirecting traffic away from program join pages and onto other program's join pages. Then suddenly the "Bros club" will wake up and smell the shit they are standing in.

Until then, it sucks to be an affiliate.

Jizar II 05-08-2007 02:41 PM

Quote:

Originally Posted by joy (Post 12369973)
May 4th. This is why sales are down to the point that they are the past 3-4 days

Sponsors need to open their eyes and look at the big picture. Look at your sales the past 3-4 days, compare your join page VS 1st bill page. You will see that your join page traffic has not changed, however your biller page traffic went to shit.

this sounds like that we're experiencing on our paysite, have you heard about other owners who are having these direct issues? :Oh crap

biskoppen 05-08-2007 02:59 PM

Don't ask where I know this from but...

These guys are stealing ALOT OF FUCKING sales (more than you can imagine) and for some unknown reason their script do not, in many cases at least, change the refering URL when they replace your affiliate ID with their affiliate ID when your surfer clicks his way to the sponsor..

So... these guys accounts has alot of sales with your domains (your galleries) as the refering URL..

So... the program owners who looks at their data on a regular basis is fully aware of this problem .. and knows it's HUGE

I'm not sure how many surfers who's infected with this CODEC trojan, but I think it's MANY .. the way it's installed is genious... "You need this codec to watch this movie" .. I almost clicked the fucking download the first time I saw it... and I'm just average stupid ;)

I'm afraid we're talking 1000s of stolen sales a day..

joy 05-08-2007 03:04 PM

Quote:

Originally Posted by Jizar II (Post 12393889)
this sounds like that we're experiencing on our paysite, have you heard about other owners who are having these direct issues? :Oh crap

99% of programs are seeing this. Rather than face the facts and attack the issue at hand they are busy changing billers, hosting and tweaking tours.

They/we will all get how serious this is soon.....I hope

Jizar II 05-08-2007 03:11 PM

Quote:

Originally Posted by joy (Post 12394065)
99% of programs are seeing this. Rather than face the facts and attack the issue at hand they are busy changing billers, hosting and tweaking tours.

They/we will all get how serious this is soon.....I hope

i would like to talk with you, can i have your icq/email?

StarkReality 05-08-2007 03:29 PM

Quote:

Originally Posted by RawAlex (Post 12392063)
The truly big issue here is that the program owners aren't feeling any pain because sales continue for them, just different affiliates are getting credited for the sales. Something will happen when the spyware guys start massively redirecting traffic away from program join pages and onto other program's join pages. Then suddenly the "Bros club" will wake up and smell the shit they are standing in.

Until then, it sucks to be an affiliate.

Since most programs depend on affiliates and don't have loads of inhouse traffic, they'll be fucked...as soon as really big affiliates look for other programs because ratios go shit.

It's only a matter of time and owners still have the choice if they'll be losers or winners in this ugly game.

RawAlex 05-08-2007 03:35 PM

Quote:

Originally Posted by StarkReality (Post 12394298)
Since most programs depend on affiliates and don't have loads of inhouse traffic, they'll be fucked...as soon as really big affiliates look for other programs because ratios go shit.

It's only a matter of time and owners still have the choice if they'll be losers or winners in this ugly game.

Yes, but it takes time - most people aren't going to go back and pull up long embedded links, they aren't going to kill off older galleries... so there is plenty of traffic that just doesn't go away. The program owners will feel it though if they lose major listings because they don't convert.

joy 05-08-2007 03:36 PM

Quote:

Originally Posted by Jizar II (Post 12394139)
i would like to talk with you, can i have your icq/email?

What's your email? I will hit you up asap

Aussie Rebel 05-08-2007 05:05 PM

Bump, For the program owners to read

Quickdraw 05-08-2007 05:32 PM

This is only the tip of things but it is a good example of how traffic is being diverted from many places.

The following comes from 1 click on an infected machine. Everything in the quote all took place in about a second.
Notice that after clicking an ad on the Google results, it takes the user through the Google ad to the intended advertiser. It is then redirected so fast that most people won't even realize they even went to the intended site.

So, the advertisers on Google(and the other engines) are getting hit by a PPC charge, for traffic that really doesn't even make it to their site, but for a millisecond.

The traffic that is redirected is sent to various smaller PPC engines, through multiple redirects. The user finally lands at a, non-affiliated, top paying advertiser for these various PPC engines and the terms used. In this case the term was 'tomato seeds'.

this is happening for all keywords and all niches, mainstream and adult.


Code:

GET http://www.google.com/search?hl=en&q=tomato+seeds&btnG=Google+Search
200 OK

GET http://85.255.119.189/frame.php
200 OK
##### Ad click started here #####
GET http://www.google.com/pagead/iclk?sa=l&ai=BjKu1_sNARsnNGpOYgQOgg8SqDPrVqB6Ws_XxA_bK6IAB4M0vCAAQARgBKAM4AFDEz9zh-_____8BYMme94fso-QXmAHAqQegAZ2ok_8DqgEEMk5SU8gBAYACAdkDI1XjKDBjSCg&adurl=http://store.tomatofest.com/%3FClick%3D2
302 Found to http://www.googleadservices.com/pagead/adclick?sa=L&ai=BjKu1_sNARsnNGpOYgQOgg8SqDPrVqB6Ws_XxA_bK6IAB4M0vCAAQARgBKAM4AFDEz9zh-_____8BYMme94fso-QXmAHAqQegAZ2ok_8DqgEEMk5SU8gBAYACAdkDI1XjKDBjSCg&adurl=http://store.tomatofest.com/%3FClick%3D2&val=ChAzMTIzMTJmNGNmODUyMzQ3EMn07LEEGggd1oiS36BCxCAB

GET http://www.googleadservices.com/pagead/adclick?sa=L&ai=BjKu1_sNARsnNGpOYgQOgg8SqDPrVqB6Ws_XxA_bK6IAB4M0vCAAQARgBKAM4AFDEz9zh-_____8BYMme94fso-QXmAHAqQegAZ2ok_8DqgEEMk5SU8gBAYACAdkDI1XjKDBjSCg&adurl=http://store.tomatofest.com/%3FClick%3D2&val=ChAzMTIzMTJmNGNmODUyMzQ3EMn07LEEGggd1oiS36BCxCAB
302 Found to http://store.tomatofest.com/?Click=2&gclid=CPu04_mb_4sCFQqgYgodaRs_zA

GET http://store.tomatofest.com/?Click=2&gclid=CPu04_mb_4sCFQqgYgodaRs_zA
200 OK

GET http://85.255.119.189/click.php?PHPSESSID=B043EDE50C4D4AACA85F6083F8EFF1CF&qq=b01bb5eae6568bd2aa6bd8a775309ac1&id=1&qnaes={B043EDE5-0C4D-4AAC-A85F-6083F8EFF1CF}
302 Found to http://64.111.208.122/click.php?c=c3fe4046bef70c09d404&r=1&d=B043EDE50C4D4AACA85F6083F8EFF1CF

GET http://64.111.208.122/click.php?c=c3fe4046bef70c09d404&r=1&d=B043EDE50C4D4AACA85F6083F8EFF1CF
302 Found to /dclick.php?c=0855c9e17bd60d2c196b&r=1

GET http://64.111.208.122/dclick.php?c=0855c9e17bd60d2c196b&r=1
302 Found to http://66.250.74.152/click.php?go=aHR0cDovLzY3LjI5LjEzOS4yMjAvY2xpY2svP2FmZmlsaWF0ZT1TUzIyJnN1YmlkPTE5MzZfMTYxNSZUZXJtcz10b21hdG8lMjBzZWVkcyZzaWQ9WjAxODA0NTA1MEBFelgxRXpkM2QzWHlNek14Y2pNMUFET3dNak0yZ3pYNWdETjI4Vk81VVRPMFlETzNFVE0=&b=MC4xOTA=&aff=1936&subaff=1615&time=1178649599&searcher_ip=24.119.49.119&cnt=21843&qq=tomato+seeds&mode=&seid=czATgc4633g1Tpvi+H2xw7C/0UMC/RjUkek0QQaz&se=YWJjU2VhcmNoUA==&sid=39&pos=1

GET http://66.250.74.152/click.php?go=aHR0cDovLzY3LjI5LjEzOS4yMjAvY2xpY2svP2FmZmlsaWF0ZT1TUzIyJnN1YmlkPTE5MzZfMTYxNSZUZXJtcz10b21hdG8lMjBzZWVkcyZzaWQ9WjAxODA0NTA1MEBFelgxRXpkM2QzWHlNek14Y2pNMUFET3dNak0yZ3pYNWdETjI4Vk81VVRPMFlETzNFVE0=&b=MC4xOTA=&aff=1936&subaff=1615&time=1178649599&searcher_ip=24.119.49.119&cnt=21843&qq=tomato+seeds&mode=&seid=czATgc4633g1Tpvi+H2xw7C/0UMC/RjUkek0QQaz&se=YWJjU2VhcmNoUA==&sid=39&pos=1
302 Found to http://66.250.74.152/click_second_new3.php?go=aHR0cDovLzY3LjI5LjEzOS4yMjAvY2xpY2svP2FmZmlsaWF0ZT1TUzIyJnN1YmlkPTE5MzZfMTYxNSZUZXJtcz10b21hdG8lMjBzZWVkcyZzaWQ9WjAxODA0NTA1MEBFelgxRXpkM2QzWHlNek14Y2pNMUFET3dNak0yZ3pYNWdETjI4Vk81VVRPMFlETzNFVE0=&b=MC4xOTA=&aff=1936&subaff=1615&time=1178649599&searcher_ip=24.119.49.119&cnt=21843&qq=tomato+seeds&mode=&seid=czATgc4633g1Tpvi+H2xw7C/0UMC/RjUkek0QQaz&se=YWJjU2VhcmNoUA==&sid=39&pos=1&country=US

GET http://66.250.74.152/click_second_new3.php?go=aHR0cDovLzY3LjI5LjEzOS4yMjAvY2xpY2svP2FmZmlsaWF0ZT1TUzIyJnN1YmlkPTE5MzZfMTYxNSZUZXJtcz10b21hdG8lMjBzZWVkcyZzaWQ9WjAxODA0NTA1MEBFelgxRXpkM2QzWHlNek14Y2pNMUFET3dNak0yZ3pYNWdETjI4Vk81VVRPMFlETzNFVE0=&b=MC4xOTA=&aff=1936&subaff=1615&time=1178649599&searcher_ip=24.119.49.119&cnt=21843&qq=tomato+seeds&mode=&seid=czATgc4633g1Tpvi+H2xw7C/0UMC/RjUkek0QQaz&se=YWJjU2VhcmNoUA==&sid=39&pos=1&country=US
302 Found to http://67.29.139.220/click/?affiliate=SS22&subid=1936_1615&Terms=tomato%20seeds&sid=Z018045050@EzX1Ezd3d3XyMzMxcjM1ADOwMjM2gzX5gDN28VO5UTO0YDO3ETM

GET http://67.29.139.220/click/?affiliate=SS22&subid=1936_1615&Terms=tomato%20seeds&sid=Z018045050@EzX1Ezd3d3XyMzMxcjM1ADOwMjM2gzX5gDN28VO5UTO0YDO3ETM
200 OK

POST http://67.29.139.220/jump/?affiliate=ss22&subid=1936_1615&Terms=tomato%20seeds&e=
200 OK
#### This is the top position on abcsearch.com ####
GET http://samson-exotic-gardens.com/14.html
200 OK

In this redirect it appears they are using abcsearch.com.
They use spoofed referrers such as indaxis.info/search.php?q=term-used and many other similarly styled refs.


All times are GMT -7. The time now is 11:42 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123