Admin: Malicious Ad...
 

[Closed] Admin: Malicious Advert

235 Posts
109 Users
0 Reactions
901 Views
Posts: 0
Free Member
Topic starter
 

Evening,
You're serving up a malicious add.
Browsing the forum on my android I will occasionally get a pop up with the text:
The page at ads.yahoo.com says:
"Virus affecting your android ? Turn on Virus scanner Now!"
Has Ok and Cancel dialogue boxes, am presuming Ok takes you to a site with an APK with shady permissions but haven't had a look.
Thought I would bring it to your attention.

All users, don't select Ok or download any suspect files after being invited to click on a link.

Can someone please report this post for visibility? You can't report your own posts! 😉


 
Posted : 07/12/2013 5:37 pm
Posts: 9187
Full Member
 

Reported.


 
Posted : 07/12/2013 5:45 pm
Posts: 33627
Full Member
 

Not an issue. 😉


 
Posted : 07/12/2013 5:46 pm
Posts: 0
Free Member
 

[quote=CountZero said]Not an issue.

Burn him!

😉


 
Posted : 07/12/2013 5:54 pm
Posts: 16372
Free Member
 

Its been happening for a while:

http://singletrackworld.com/forum/topic/android-pop-ups-from-ads-on-this-site


 
Posted : 07/12/2013 5:55 pm
 Drac
Posts: 50484
 

For future reference.

Website technical enquiries

If you have any questions or concerns about this website – tech@singletrackworld.com


 
Posted : 07/12/2013 5:57 pm
Posts: 0
Free Member
 

There are good reasons to install AVG or similar apps on your 'droid.


 
Posted : 07/12/2013 6:04 pm
Posts: 31062
Free Member
 

If you have any questions or concerns about this website

Please email us privately so we can keep it quiet.


 
Posted : 07/12/2013 6:14 pm
Posts: 0
Free Member
 

I get a lot Lovelinks pop up on my android tab and then opens play store. 🙄


 
Posted : 07/12/2013 6:32 pm
 Drac
Posts: 50484
 

Please email us privately so we can keep it quiet.

If that were the case we'd delete any reference to problems but yet we don't.


 
Posted : 07/12/2013 6:35 pm
Posts: 31062
Free Member
 

If that were the case we'd delete any reference to problems but yet we don't.

Admirable.


 
Posted : 07/12/2013 6:36 pm
Posts: 0
 

And a advert to the right for free malware removal. See how the world goes round.


 
Posted : 07/12/2013 7:02 pm
Posts: 43644
Full Member
 

I reported this to the mods earlier in the week. They are usually pretty quick at removing these ads.


 
Posted : 07/12/2013 8:05 pm
Posts: 33627
Full Member
 

allthepies - Member
CountZero said » Not an issue.
Burn him!

Is there an app for that?
😆


 
Posted : 08/12/2013 12:35 am
Posts: 0
Free Member
 

Bump

Getting fedup of it now. Constantly occurring on both android phone and tablet.

Any suggestions yet?


 
Posted : 08/12/2013 8:58 pm
Posts: 13783
Full Member
 

virus in your device(s)?

not an issue here.


 
Posted : 08/12/2013 9:00 pm
Posts: 0
Free Member
 

Don't think so... can never be 100% though


 
Posted : 08/12/2013 9:06 pm
Posts: 0
Free Member
 

I've been looking into this a bit more and have a few observations,
We only use the major ad networks Google, Microsoft, AOL and Switch. They are very conscious of ad malware and I would be surprised if they were distributing this code.
We have hundreds of thousands of Android users on the site and it is the same few who report recurring problems.
I use the site on my Android Nexus 7 and HTC One S regularly and have never encountered a problem.
All this leads me to believe the problem may be with the users devices. Google does not vet the quality of apps distributed via the Google Play store so the odds are that some of our users may have installed a dodgy app at some stage. Equally, Android devices are vulnerable to viruses and other malware. It is recommended that you should run anti virus package on your device.

Ultimately as I have been unable to replicate the problem I can't see how I can help further. If you have any further information that would help me identify the cause of the problem I would be happy to investigate further.

We are keeping the ad networks informed of the concerns in case they are the source..


 
Posted : 10/12/2013 10:19 am
Posts: 43644
Full Member
 

It's on the device but only happens when browsing Singletrack?

Chinny reckon


 
Posted : 10/12/2013 10:57 am
Posts: 0
Free Member
 

I had the same thing happen last night on an android phone.


 
Posted : 10/12/2013 11:01 am
Posts: 251
Full Member
 

[i]It's on the device but only happens when browsing Singletrack?[/i]

I'm with patrick - if it weren't the device there would be an awful lot more people complaining about this across a range of platforms and devices.

And why only on Android devices - the ad serving systems that stw use are largely OS agnostic.

no idea if there's a malwarebytes equivalent for android and I've not needed it on my Sony but if I were affected I'd assume it wa sme and not stw.


 
Posted : 10/12/2013 11:02 am
Posts: 0
Free Member
 

My laptop keeps blocking a popup today; this is only occurring on STW.


 
Posted : 10/12/2013 11:15 am
Posts: 251
Full Member
 

have you run malwarebytes etc?

unless the code to launch the pop-up is delivered by stw or it's ad partners it's not really down to them is it?


 
Posted : 10/12/2013 11:17 am
Posts: 0
Free Member
 

Merely commenting that I am getting this on a windows system and only with STW. Seems likely to me that a popup that only appears on STW and not on the 100's of other sites I browse may be something to do with STW.


 
Posted : 10/12/2013 11:20 am
Posts: 36
Free Member
 

Patrick- do you make allowances for the difference between premier users reporting issues and the lowly proles?


 
Posted : 10/12/2013 11:46 am
Posts: 0
Free Member
Topic starter
 

Afternoon,
Flashed to downgrade back to 4.3 Jellybean.
Only re-installed a few apps after reading the latest reviews on Play store,
Still having the issue.
For what that's worth! 🙂

lowly proles?

I only let [b]P[/b] lapse because I never rceived a free gift!


 
Posted : 10/12/2013 12:00 pm
 kcr
Posts: 2949
Free Member
 

I got a similar dodgy pop up while browsing on an Android phone, suggesting a virus had been detected and inviting me to clean it. No "Cancel" option, only an "OK", so clearly a scam. I just used the back button to cancel the window.
As reported by others, I have only experienced this on the STW site.


 
Posted : 10/12/2013 12:17 pm
Posts: 0
Free Member
 

Been experiencing this for about last week, and only on STW. No apps downloaded recently. Running a Desire S with Gingerbread & Avast installed


 
Posted : 10/12/2013 12:23 pm
Posts: 0
Free Member
 

I only let P lapse because I never rceived a free gift!

Scuzz: Did you contact us at the time?
Also, what apps did you install and were you flashing from a clean distro with security updates applied?

Patrick- do you make allowances for the difference between premier users reporting issues and the lowly proles?

Stoner: Not sure what you mean. Are you asking if Premier users with ads switched off are being affected?


 
Posted : 10/12/2013 12:33 pm
 cp
Posts: 8952
Full Member
 

Happened a couple of times to me during the last week on Android. Only on STW, not had it on any other site.


 
Posted : 10/12/2013 12:35 pm
Posts: 0
Free Member
 

cp: do you have ads on or off?


 
Posted : 10/12/2013 12:37 pm
Posts: 0
Free Member
Topic starter
 

Hi Patrick,
I didn't & I'm not too fussed, I was just having a dig at Stoner - I know you're good at sorting out missed free gifts and didn't mean to imply any fault on your part 🙂


 
Posted : 10/12/2013 12:39 pm
 cp
Posts: 8952
Full Member
 

patricksingletrack - Singletrack Webby
cp: do you have ads on or off?

I have them off.


 
Posted : 10/12/2013 12:49 pm
 cp
Posts: 8952
Full Member
 

I'll run AVG or something on the phone this afternoon, just to be sure.


 
Posted : 10/12/2013 12:50 pm
Posts: 0
Free Member
 

Cheers cp, that suggests it may not be ad networks.


 
Posted : 10/12/2013 12:54 pm
Posts: 4097
Free Member
 

Surely if the adverts are tailored to your browsing habits (which everyone always says is the case) then you would expect only some users to be served the "dodgy" ones, no?


 
Posted : 10/12/2013 12:56 pm
Posts: 457
Free Member
 

I'm getting the same messages. Android KitKat 4.4


 
Posted : 10/12/2013 1:01 pm
Posts: 0
Free Member
 

I have both AVG and malwarebytes running on android. I get the popups fairly frequently on both phone and tablet.


 
Posted : 10/12/2013 1:04 pm
 Mark
Posts: 4293
Level: Black
 

Not all the ads are targeted. Some are targeted at demographics, some using geographical data, some using past browsing data. We are treating this seriously and are looking under the hood and examining everything we can think of. But the suggestion that it's happened to a user with ads turned off is causing some head scratching here.
If anyone has any more technical details they can pass on to us, browser data, version etc then all of that will help us. The more details the better for us. And if you can post it directly to us at tech@singletrackworld.com that will be really helpful.


 
Posted : 10/12/2013 1:05 pm
Posts: 0
Free Member
 

This is not happening on my kindle fire or htc one. You guys sure you haven't installed a file by accident that's searching itself to your most used sites?


 
Posted : 10/12/2013 1:11 pm
Posts: 20690
Free Member
 

You do know what the solution is don't you?....

[img] [/img]


 
Posted : 10/12/2013 1:13 pm
Posts: 0
Free Member
 

Or as a test turn off your wi fi, then load up singletrack from cached memory and see if it still pops up


 
Posted : 10/12/2013 1:14 pm
Posts: 43644
Full Member
 

[quote=Mark ]Not all the ads are targeted. Some are targeted at demographics, some using geographical data, some using past browsing data. We are treating this seriously and are looking under the hood and examining everything we can think of. But the suggestion that it's happened to a user with ads turned off is causing some head scratching here.
FWIW, I've only had it once and I'm pretty sure that was before I'd logged on to STW.


 
Posted : 10/12/2013 1:17 pm
Posts: 0
Free Member
 

I've just browsed the site using silk chrome and explorer, no issues some of you guys need to clean your devices up!


 
Posted : 10/12/2013 1:21 pm
Posts: 77753
Free Member
 

Which browser are you all using?

Seems bloody weird to me that it's [i]only [/i]STW and [i]only [/i]certain people affected. I might give it a battering during lunch.


 
Posted : 10/12/2013 1:42 pm
Posts: 43644
Full Member
 

In-built browser on HTC phone (i.e. not Chrome) for me.


 
Posted : 10/12/2013 1:46 pm
Posts: 1048
Free Member
 

I'll get some stuff together when I get a moment, but if it helps, one of the pop-ups originated from ib.adnxs.com

Edit: Chrome on a Nexus 4

Further Edit: ib.adnxs.com does indeed set a cookie in Chrome - Settings > Content Settings > Website Settings, you may see it in there. Which could be a clue. I haven't had an ad for a while, but I am going to bin the cookie as a first step.


 
Posted : 10/12/2013 2:00 pm
Posts: 251
Full Member
 

[i]ib.adnxs.com[/i]

quick google implies that's a malware site...


 
Posted : 10/12/2013 2:03 pm
Posts: 77753
Free Member
 

quick google implies that's a malware site...

It's not a malware site in and of itself I don't think, however some browser redirect malware uses that site to generate click-through revenue.


 
Posted : 10/12/2013 2:13 pm
 Mark
Posts: 4293
Level: Black
 

Appnexus is a legitimate ad network. We are looking into what is going on but I learned quite a lot by googling the OP's pop up message text "Virus affecting your android ? Turn on Virus scanner Now!".. This issue is not restricted to our site users it seems. It does look like it's a virus that causes a popup to appear encouraging you to download AV software. It seems to be triggered by opening a browser.
I've found the ad campaigns on our sysetm that are being delivered via the Appnexus network. Like I said, it's a legit ad network but I'm about to turn it off and see what happens.

Thanks to all those sending us specifics via email - It's helping.


 
Posted : 10/12/2013 2:23 pm
Posts: 77753
Free Member
 

Flashed to downgrade back to 4.3 Jellybean.

With an official RUU or a homebrew ROM? Check the thread on XDA for that ROM, see if there's any known issues?

Only re-installed a few apps after reading the latest reviews on Play store,

Try flashing again and testing it before installing any other apps.


 
Posted : 10/12/2013 2:27 pm
Posts: 0
Free Member
 

Just a thought, had you all turned on "Block pop-ups" in your Chrome or Android Browser settings?

Caveat: As this appears to be a virus, blocking pop-ups after the virus has installed on your device may not help as the virus could overcome browser settings.


 
Posted : 10/12/2013 3:13 pm
Posts: 0
Free Member
Topic starter
 

Ey up Cougar,
Sorry for the confusion, I was downgrading (official build) as a result of other unrelated issues, I just thought I'd add some additional information.
Thanks for the assistance mind, may give that a go tonight.

Block popups is ticked in Chrome, I haven't ticked it since the reflash - unsure what the default behaviour is or whether this is synced to my account. Closing the settings page and refreshing Singletrack and it appeared again!


 
Posted : 10/12/2013 3:15 pm
Posts: 0
Free Member
Topic starter
 

Out of edit-time update:
Popup does not appear every time.
When pop up does appear, it is when the banner at the top of the home page displays an Android Virus Scan advert.
The popup appears 7/8ths of the way through loading the page, pausing the page load. After dismissing the popup, the banner at the top loads immediately (showing the virus scan ad). This banner ad then changes, cycling through new ads for other products.
Haven't managed to catch the banner and find its link, each new ad has a new link...


 
Posted : 10/12/2013 3:40 pm
Posts: 0
Free Member
 

Scuzz: forum home page or site home page?
ie
http://singletrackworld.com/
or
http://singletrackworld.com/forum/


 
Posted : 10/12/2013 3:54 pm
Posts: 0
Free Member
Topic starter
 

Forum, there's a mainsite?! 😉


 
Posted : 10/12/2013 3:59 pm
Posts: 621
Free Member
 

Only seen it in Chrome, not the native browser.

[URL= http://i.imgur.com/EE2jsIMl.pn g" target="_blank">http://i.imgur.com/EE2jsIMl.pn g"/> [/IMG][/URL]

Looks like it's from yahoo?

Edit: this is a freshly flashed (Google official) build of 4.1.2 on a GNex, only a few apps installed and they are all mainstream, such as Chrome, BBC news etc. No shitty games or anything. Also not appearing on any other sites.


 
Posted : 10/12/2013 4:02 pm
 cp
Posts: 8952
Full Member
 

that's reminded me, mine was ads.yahoo.com too


 
Posted : 10/12/2013 4:19 pm
Posts: 0
Free Member
 

Also had this. But only once. Then installed avg and not seen it since


 
Posted : 10/12/2013 4:30 pm
 Mark
Posts: 4293
Level: Black
 

Thanks for all those details. That's a great help. The hunt is on.


 
Posted : 10/12/2013 4:56 pm
Posts: 0
Free Member
 

Yes I've experienced this too. Have had a few times exactly what Retro83 has pictured above. Also use Chrome.


 
Posted : 10/12/2013 6:03 pm
Posts: 0
Free Member
Posts: 93
Free Member
 

Just got it from that ad up there as well. Brand new nexus 7, fully updated, no dodgy software or apps installed.


 
Posted : 11/12/2013 6:53 pm
Posts: 0
Free Member
Topic starter
 

Oh come off it.
[img] [/img]
Sorry chaps, adblock's going on now 🙁


 
Posted : 11/12/2013 7:08 pm
Posts: 1048
Free Member
 

Just got exactly the same ad and pop-up combination as scuzz.


 
Posted : 11/12/2013 11:35 pm
Posts: 251
Full Member
 

*is beginning to reconsider previous view that it was the phones causing the problem*


 
Posted : 12/12/2013 8:08 am
Posts: 1375
Full Member
 

Just to add my experience- running a Nexus 4 and a 7, no AV installed, and have never had a pop up from the site.

Bog standard 4.4 on the 7, and 4.4.2 on the 4.


 
Posted : 12/12/2013 8:13 am
Posts: 0
Free Member
 

"Just got exactly the same ad and pop-up combination as scuzz."

Same here on my tablet constantly, seems to want me to download
app Mobogenie.


 
Posted : 12/12/2013 8:43 am
Posts: 1048
Free Member
 Drac
Posts: 50484
 

They're on looking into they were discussing what to do this am until they can find the problem of the cause. Sorry it's causing some of you issues folks.


 
Posted : 12/12/2013 2:09 pm
Posts: 3149
Free Member
 

I am having exactly the same problem - lovelinks "your APP store need update immediately" routing to the play store. Very odd - Please post up a solution when it arises.

Only happens when not on Wi-Fi and only with STW web site.


 
Posted : 15/12/2013 4:09 pm
Posts: 77753
Free Member
 

Who's your service provider? Is everyone affected on the same network?

Anyone get the issue when on a wifi connection?


 
Posted : 15/12/2013 4:14 pm
Posts: 3149
Free Member
 

O2.


 
Posted : 15/12/2013 4:22 pm
Posts: 77753
Free Member
 

Hm. Probably not a provider issue then, as I'm on O2 and I've never seen it. Just a thought.


 
Posted : 15/12/2013 4:36 pm
Posts: 357
Free Member
 

Just seen this thread and I am having the same issues with my android phone(Samsung S4) when browsing this site (Chrome). I also keep getting that lovelinks message. Happens when I use the wifi connection or mobile network (I am based in Germany).


 
Posted : 15/12/2013 4:46 pm
Posts: 0
Free Member
 

I'm in Germany too.

Refresh happening constantly....

Getting sick of it. Close to not using the site anymore & moving on...

Maybe time to get the Web site sorted by pro puter geeks.


 
Posted : 15/12/2013 5:24 pm
 pk13
Posts: 2728
Full Member
 

Just so folks know this is happening on other sites as well it's not just an issue on singletrack. It's very annoying though.


 
Posted : 15/12/2013 5:30 pm
Posts: 0
Free Member
 

Been getting the scuzz posted combo on phone and now a love links popup that downloads some crap no matter what you press. Not happy.


 
Posted : 16/12/2013 6:06 pm
Posts: 0
Free Member
 

I was at a hotel on Saturday night and accessed the forum on my tablet through the hotel wifi, and was getting these popups.

Back home and no popups on the tablet on the home network.


 
Posted : 16/12/2013 6:57 pm
Posts: 476
Full Member
 

Also been getting the same combo as scuzz on a nexus 4 running the latest 4.4.2 update, only seems to happen on the phone network (giffgaff btw) never seem it at home on the tablet either


 
Posted : 16/12/2013 8:58 pm
Page 1 / 3