Mwb Alert 707.teracreative.com

Discussion in 'Software' started by Mr.Magoo, May 2, 2016.

  1. Mr.Magoo

    Mr.Magoo Private First Class

    Hi Folks,

    I'm sorry I couldn't figure out where to post this but here.

    I get this alert from MWB every time I sign in here and only here. I have done extensive searches on my machine and there is no sign of it on my machine. I ran MWBs, Adwcleaner, and Ccleaner with no reports of a problem. It only happens when I sign on here which has me very confused, I would never expect something like this showing up anyplace near Major Geeks :)

    http://i206.photobucket.com/albums/bb170/kahsr/707.teracreative.com%20MWB%20Warning_zpsqoy3cktm.png
     
  2. satrow

    satrow Major Geek Extraordinaire

    Your IE appears to be trying to connect to a site run by voxel.net, when I try to reach voxel, I get a big red banner marked UNTRUSTED. On checking the details, the certificate isn't for voxel but for the following sites, presumably hosted by them and might contain the blocked site that your IE is trying to contact:

    The Malwarebytes site is the place to ask about this but I'd suggest you get a checkup from the malware team here while you wait.



    EDIT: see VirusTotal's page, it does appear to show some nefarious activity from there: https://www.virustotal.com/ru/domain/707.teracreative.com/information/
     
    Last edited: May 2, 2016
    LauraR likes this.
  3. Earthling

    Earthling Interplanetary Geek

    But you are managing to sign in. How?
     
  4. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    Everything (which is not much) that I am seeing in regards to teracreative.com seems to be in regards to how to remove the 'redirect virus'.

    On one website I found, it recommended you go through your Programs in your Control Panel and remove anything that you don't recognize that could be suspicious (another site said it could even have the name Teracreative listed, but I don't know the validity of this). It also mentioned going into your add-ons/extensions in your browser...which I would definitely suggest doing as it's supposedly another way it installs on your PC. One other thing...have you tried logging on here using a different browser than IE? If you haven't, please do so and see if Malwarebytes flags anything when logging on here.

    You said you've done scans...have you gone through our malware removal guide? I may be tempted to do that if I were you.
     
    satrow likes this.
  5. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    5 computers in the house run MBAM pro. 4 are running Win 7 and one is running XP.
    I don't normally use IE but I will fire it up and test.
    Be back with results.

    No warning - desktop IE 11. See screenshot
     

    Attached Files:

  6. Mr.Magoo

    Mr.Magoo Private First Class

    Yes, I saw this information the other day thanks for mentioning it. VT is one of my go to sites for checking into these types of things.

    I have run various scans for Malware (etc.) with nothing being spotted.
     
  7. Mr.Magoo

    Mr.Magoo Private First Class

    Yes, it signs in just fine. I don't get the warning until a minute or so after logging in then it just pops up at random times while using the site.
     
  8. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    Here is what the site looks like in XP on IE8; I don't have adblockplus installed.
     

    Attached Files:

  9. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    What version of IE are you using? Because I see nothing in IE 8 and IE11. I don't run Vista so I can't test IE 10.

    What addons have you added?

    We also need to go through your settings to see what in your install of IE is trying to connect to a suspicious site.

    I do get popups about enabling Adobe flash here but I just x them out. I do not want flash turned on. But i don't see any complaints from MBAM.
     
  10. Mr.Magoo

    Mr.Magoo Private First Class

    No I have not done this yet as it is such a timely process although I might have to bite the bullet and give it a try. The thing is I know my machine and my habits and really don't believe I am infected. I know we all "think" we know these things and us that do, we can never be 100% sure. To many new things try to hit us possibly hourly but defiantly daily:(
     
  11. Mr.Magoo

    Mr.Magoo Private First Class

    Just curious how long did you leave it signed in with IE?
     
  12. Mr.Magoo

    Mr.Magoo Private First Class

    I don't get the popups because I do leave it on as many of the sites I frequently go to use it.
     
  13. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member


    Well, at the very least, I would suggest going into your IE settings under Add ons and Extensions and look to see if anything is in there that you did not install.

    Please also log on with another browser and see if it happens again. If it doesn't, that would narrow it down to IE.
     
  14. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    Long enough to take a screenshot and save it, find this thread and upload the screenshot to the thread.
     
  15. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    I'm digging into it.. Funny thing is I'm not getting the error and I'm running MBAM on this machine
     
    Mr.Magoo and satrow like this.
  16. Mr.Magoo

    Mr.Magoo Private First Class

    Interesting plodr, as soon as I signed in to reply to this message I got the popup.
     
  17. Mr.Magoo

    Mr.Magoo Private First Class

    Hi Laura,

    I did look at my addons and didn't see anything that "to my knowledge" didn't belong there.

    I signed in with FF having the same popup hit me as soon as I signed on.

    *Note to all - I have contacted MWB and will let everyone know when I have received word back from them.*

    One more thing - I have not received another popup since signing on which unusual I normally get one every couple of minutes while on the site. I find this interesting to say the least.
     
  18. Mr.Magoo

    Mr.Magoo Private First Class

    Hi Corporal Punishment, thanks for looking into this for me as it is very concerning and confusing to me.
     
  19. Eldon

    Eldon Major Geek Extraordinaire

    Last edited by a moderator: May 3, 2016
  20. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    OK - So here is what I know. teracreative is the ad server for Convert media. http://convertmedia.com/. In other words, it's just a platform. It looks like they are plugged into a lot of things in the real time buying world. Much like the one we use, openx. However with openx we get our own domain like ox.majorgeeks.com teracreative doesn't seem to do that. So a lot of advertisers can be on the same domain. Looks like someone is running some bad stuff on that network and hence the whole domain is being blocked. I tracked the ad that was being blocked here and it was 100% legit. ... but I blocked to domain until they fix their stuff.

    This sort of thing happens from time to time. Ad companies have a way of policing their stuff because sites like us block them when we get compliants I will see if I can write them to give a heads up. Kinda hard for them - but hey ... Not our problem. ;)

    As for terra creative being malware, it isn't. It;s just an ad server. Ads on it may lead to bad places, but if you look at the articles written about the topic they are 100% sales pitches for certain anti-spyware products. They is no need in this case unless----- you happen to have clicked on a bad ad.

    So hopefully that helps.
     
    satrow and LauraR like this.
  21. Anon-469e6fb48c

    Anon-469e6fb48c Anonymized

    This is why i said that malware-bytes is far to picky on a lot of web sites.When a lot of them are just fine.
     
  22. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    Yeah - I see both sides of that coin. MB has a big responsibility and sometimes it;s hard to know where to draw the line.

    Don't get me started on the whole PUP thing, though. I think it's an industry nightmare,
     
  23. plodr

    plodr MajorGeek Super Extraordinaire Moderator Staff Member

    Seriously? I'd rather be blocked from something than let it slide through!

    If I want to get to a site, I can always over ride MBAM's site block. I have done it once or twice then when I was finished looking at a particular site, I went back in and removed the site from the ignore list.
     
    satrow likes this.
  24. Mr.Magoo

    Mr.Magoo Private First Class

    Hi Eldon, no disrespect but my machine is various free I do appreciate your looking into this also.
     
  25. Mr.Magoo

    Mr.Magoo Private First Class

    Hi CP,

    The problem I am having is that the site wants to upload something to my machine not download it.
     
  26. Mr.Magoo

    Mr.Magoo Private First Class

    Just a few things:

    I want to thank everyone here who has taken the time to help me with this problem and so many more.

    MWB help has been no help at all.

    This issue stopped this morning, both upon signing in here and happening every 10-15 minutes both on IE and FF I have absolutely no idea why. Some may think it was because of a reboot but that was not the case.

    I will just have to scratch my head for a while.
     
  27. Corporal Punishment

    Corporal Punishment Head of Software Shenanigans Staff Member

    Prob a cookie or the like. I've been in touch with the guys at MB. One of them still owes me for keeping quite about our last trip to vegas. ;) They were working on the issue that may be why it stopped for you. But, I also put a block on for all ads from that network until it is cleared. It;s probably something minor, but uneducated users may think it is something wrong with us. The odd thing is I run MBAM here and never got the error. But, now that I type that, it sorta makes sense as I almost never delete cookies, and I'll wager you do. Hence, nothing needed to be downloaded to my machine.

    This sort of thing happens more than you would think though.

    -- - off topic. I think the fonts need to be bigger on the forums. maybe I'm just getting old
     
  28. Mr.Magoo

    Mr.Magoo Private First Class

    Hi CP,

    Now that I would buy, as I am very confident my machine is clean. I am overly conscious about what goes into "Bear". Nothing is downloaded without being run through Scamadvisor fist, this include ALL links. I also run them through Total Virus when I feel it might be needed but I find TV is much less aggressive than SV, JMHO.

    The truth is I only dump my cookies bi-annually and haven't done so yet.

    I will be very interested in what your friend has to saw about this issue. Just an FYI, no warning again today when I signed in.

    As far as the font I use the default font for everything. When I read the forum it seems as though most do the same. Is there something I am missing?
     
  29. Eldon

    Eldon Major Geek Extraordinaire

    Maybe one size up?
    Or, in settings of your browser, select to ignore font sizes specified on webpages.
     
  30. Earthling

    Earthling Interplanetary Geek

    I just use Ctrl +, Ctrl - and Ctrl 0 (zero). As Firefox remembers your setting for each site you can fine tune it to your needs.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds