legitreviews.com

VirtualLarry

No Lifer
Aug 25, 2001
56,554
10,171
126
I searched for A10-4600M, and was led to a page on legitreviews.com.

Now when I attempt to close the page, it brings up a dialog box asking me if I really want to leave the page. I REALLY DISLIKE those "page trap" dialogs.

IMHO, no legit web site would ever use those. Thus, "Legit"reviews isn't so legit in my book.

http://www.legitreviews.com/article/1931/1/

Edit: MAYBE HACKED. DO NOT CLICK.

Edit: Reported to be fixed?
 
Last edited:

inf64

Diamond Member
Mar 11, 2011
3,864
4,546
136
It's legit. They probably just don't want you to leave without clicking on some ads I guess . Don't worry about it.
 

Idontcare

Elite Member
Oct 10, 1999
21,110
59
91
I think they've been hacked:



^ that is what I get when I go to your link.

I don't know what that toolkit does, but Norton blocked it and I was able to close the page without getting the popup you got. You may be infected since you got the pop-up.
 

inf64

Diamond Member
Mar 11, 2011
3,864
4,546
136
Wow IDC,good thing I haven't clicked on it :O. My AVG free might have failed for the 1st time,who knows
 

VirtualLarry

No Lifer
Aug 25, 2001
56,554
10,171
126
Ok, that's a little scary, IDC. I don't run an AV on this box. Is Waterfox 13.0 vulnerable? Flash Player (dunno what version I'm running)?

Any way to know how to check for infection?

http://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=24092

Symantec claims you should download and run their "Norton Power Eraser", which I did, and it came up clean, except for "Hosts", but I know I modified my hosts file manually, so that's not a problem.
 
Last edited:

Zstream

Diamond Member
Oct 24, 2005
3,395
277
136
Every now and then I get an ad from Anandtech that takes up the entire page.... *shrug*
 

Idontcare

Elite Member
Oct 10, 1999
21,110
59
91
Ok, that's a little scary, IDC. I don't run an AV on this box. Is Waterfox 13.0 vulnerable? Flash Player (dunno what version I'm running)?

Any way to know how to check for infection?

http://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=24092

Symantec claims you should download and run their "Norton Power Eraser", which I did, and it came up clean, except for "Hosts", but I know I modified my hosts file manually, so that's not a problem.

You did exactly what I would do (download the free cleaner and give it a go), if it came up clean then I would personally conclude my system was clean.

You will know if it isn't clean if you start getting browser hijacks (redirects).

The other one you could try is superantispyware which a free trial for their pro edition, install that just to give your system a once-over.

When I was visiting some, uh, questionable websites :sneaky: it was able to find stuff that was causing browser hijacks that Norton wasn't able to find. Just sayen Surfing the web is like being in college and it is the weekend, protection is key.
 

AdamK47

Lifer
Oct 9, 1999
15,546
3,246
136
Whenever I come across one of those dialog prompts I immediately kill the browser process. Any input from a dialog could be inviting trouble.
 

Idontcare

Elite Member
Oct 10, 1999
21,110
59
91
Whenever I come across one of those dialog prompts I immediately kill the browser process. Any input from a dialog could be inviting trouble.

I'm of the exact same school of thought. Just because the dialogue boxes are labeled "cancel" or "ok" doesn't mean you aren't actually agreeing to "go ahead and install your root-kit, I accept".

The label on the button and the action that comes from clicking the button are not required to be the same, you just hope they are.

Instead, pull open task manager and deep-6 the PID for the browser itself.
 

Majic 7

Senior member
Mar 27, 2008
668
0
0
Took a chance on my new install of Widows 8 and clicked on the link. No pop up, no warning from defender or Malwarebytes Pro. I do have every security option except in private browsing ticked. I just had to see if 8 and IE10 does make a difference. Scanned with both Defender and MB Pro and nothing showed up. I finally have something that uses 8 threads, Defender was going over 80% on all threads occasionally, usually about 50%.
 
Last edited:

kowalabearhugs

Senior member
Sep 19, 2010
204
8
81
www.mattkowal.net
I run AdBlocker, Ghostery and NoScript. Pages load much faster and I maintain a lil more privacy. Many popups are javascript based - NoScript simply removes these scripts sans the items in my whitelist. Temporary and permanent whitelisting is available.
 

kaos kid

Member
Oct 12, 2005
97
0
61
It was an Ad Server exploit. They have deleted the old Ad Server and Database and have installed new. All should be fine now.
 

blastingcap

Diamond Member
Sep 16, 2010
6,654
5
76
In the future you guys may want to contact infected sites ASAP alerting them of problems, so fewer people will get infected.
 

kaos kid

Member
Oct 12, 2005
97
0
61
I just ran "virustotal" scan for "LegitReviews.com"and it came up clean 0/31

So feel free to go back and check out the reviews!
 

Idontcare

Elite Member
Oct 10, 1999
21,110
59
91
Edit: Reported to be fixed?

I don't get the norton warning now when I visit their site or your link in the OP. Looks like they fixed it :thumbsup:

And hopefully they suffer no long-term effects in terms of negative publicity because of the ad breach, legitreviews is legit :thumbsup: Vigilance is key though, this is what being a community is all about, so I'm glad to see it came up for discussion versus no one bothering to warn each other of the situation
 

Aikouka

Lifer
Nov 27, 2001
30,383
912
126
I recall Anandtech having at least one malevolent ad in its rotation before. Most sites use third party ad rotation services, which appear to not be infallible.
 

podspi

Golden Member
Jan 11, 2011
1,982
102
106
Every now and then I get an ad from Anandtech that takes up the entire page.... *shrug*


This has been driving me nuts lately. Is there anywhere we can complain about these, since I assume AT isn't serving these on purpose?
 

ViRGE

Elite Member, Moderator Emeritus
Oct 9, 1999
31,516
167
106
I recall Anandtech having at least one malevolent ad in its rotation before. Most sites use third party ad rotation services, which appear to not be infallible.
AnandTech has had worse than that. They had their ad servers hacked in 2010.:|
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |