Forum menu
Admin: Malicious Ad...
 

[Closed] Admin: Malicious Advert

Posts: 43955
Full Member
 

In-built browser on HTC phone (i.e. not Chrome) for me.


 
Posted : 10/12/2013 2:46 pm
Posts: 1048
Free Member
 

I'll get some stuff together when I get a moment, but if it helps, one of the pop-ups originated from ib.adnxs.com

Edit: Chrome on a Nexus 4

Further Edit: ib.adnxs.com does indeed set a cookie in Chrome - Settings > Content Settings > Website Settings, you may see it in there. Which could be a clue. I haven't had an ad for a while, but I am going to bin the cookie as a first step.


 
Posted : 10/12/2013 3:00 pm
Posts: 251
Full Member
 

[i]ib.adnxs.com[/i]

quick google implies that's a malware site...


 
Posted : 10/12/2013 3:03 pm
Posts: 78484
Full Member
 

quick google implies that's a malware site...

It's not a malware site in and of itself I don't think, however some browser redirect malware uses that site to generate click-through revenue.


 
Posted : 10/12/2013 3:13 pm
 Mark
Posts: 4437
 

Appnexus is a legitimate ad network. We are looking into what is going on but I learned quite a lot by googling the OP's pop up message text "Virus affecting your android ? Turn on Virus scanner Now!".. This issue is not restricted to our site users it seems. It does look like it's a virus that causes a popup to appear encouraging you to download AV software. It seems to be triggered by opening a browser.
I've found the ad campaigns on our sysetm that are being delivered via the Appnexus network. Like I said, it's a legit ad network but I'm about to turn it off and see what happens.

Thanks to all those sending us specifics via email - It's helping.


 
Posted : 10/12/2013 3:23 pm
Posts: 78484
Full Member
 

Flashed to downgrade back to 4.3 Jellybean.

With an official RUU or a homebrew ROM? Check the thread on XDA for that ROM, see if there's any known issues?

Only re-installed a few apps after reading the latest reviews on Play store,

Try flashing again and testing it before installing any other apps.


 
Posted : 10/12/2013 3:27 pm
Posts: 0
Free Member
 

Just a thought, had you all turned on "Block pop-ups" in your Chrome or Android Browser settings?

Caveat: As this appears to be a virus, blocking pop-ups after the virus has installed on your device may not help as the virus could overcome browser settings.


 
Posted : 10/12/2013 4:13 pm
Posts: 0
Free Member
Topic starter
 

Ey up Cougar,
Sorry for the confusion, I was downgrading (official build) as a result of other unrelated issues, I just thought I'd add some additional information.
Thanks for the assistance mind, may give that a go tonight.

Block popups is ticked in Chrome, I haven't ticked it since the reflash - unsure what the default behaviour is or whether this is synced to my account. Closing the settings page and refreshing Singletrack and it appeared again!


 
Posted : 10/12/2013 4:15 pm
Posts: 0
Free Member
Topic starter
 

Out of edit-time update:
Popup does not appear every time.
When pop up does appear, it is when the banner at the top of the home page displays an Android Virus Scan advert.
The popup appears 7/8ths of the way through loading the page, pausing the page load. After dismissing the popup, the banner at the top loads immediately (showing the virus scan ad). This banner ad then changes, cycling through new ads for other products.
Haven't managed to catch the banner and find its link, each new ad has a new link...


 
Posted : 10/12/2013 4:40 pm
Posts: 0
Free Member
 

Scuzz: forum home page or site home page?
ie
http://singletrackworld.com/
or
http://singletrackworld.com/forum/


 
Posted : 10/12/2013 4:54 pm
Posts: 0
Free Member
Topic starter
 

Forum, there's a mainsite?! ๐Ÿ˜‰


 
Posted : 10/12/2013 4:59 pm
Posts: 621
Free Member
 

Only seen it in Chrome, not the native browser.

[URL= http://i.imgur.com/EE2jsIMl.pn g" target="_blank">http://i.imgur.com/EE2jsIMl.pn g"/> [/IMG][/URL]

Looks like it's from yahoo?

Edit: this is a freshly flashed (Google official) build of 4.1.2 on a GNex, only a few apps installed and they are all mainstream, such as Chrome, BBC news etc. No shitty games or anything. Also not appearing on any other sites.


 
Posted : 10/12/2013 5:02 pm
 cp
Posts: 8970
Full Member
 

that's reminded me, mine was ads.yahoo.com too


 
Posted : 10/12/2013 5:19 pm
Posts: 0
Free Member
 

Also had this. But only once. Then installed avg and not seen it since


 
Posted : 10/12/2013 5:30 pm
 Mark
Posts: 4437
 

Thanks for all those details. That's a great help. The hunt is on.


 
Posted : 10/12/2013 5:56 pm
Posts: 0
Free Member
 

Yes I've experienced this too. Have had a few times exactly what Retro83 has pictured above. Also use Chrome.


 
Posted : 10/12/2013 7:03 pm
Posts: 0
Free Member
Posts: 93
Free Member
 

Just got it from that ad up there as well. Brand new nexus 7, fully updated, no dodgy software or apps installed.


 
Posted : 11/12/2013 7:53 pm
Posts: 0
Free Member
Topic starter
 

Oh come off it.
[img] [/img]
Sorry chaps, adblock's going on now ๐Ÿ™


 
Posted : 11/12/2013 8:08 pm
Posts: 1048
Free Member
 

Just got exactly the same ad and pop-up combination as scuzz.


 
Posted : 12/12/2013 12:35 am
Posts: 251
Full Member
 

*is beginning to reconsider previous view that it was the phones causing the problem*


 
Posted : 12/12/2013 9:08 am
Posts: 1375
Full Member
 

Just to add my experience- running a Nexus 4 and a 7, no AV installed, and have never had a pop up from the site.

Bog standard 4.4 on the 7, and 4.4.2 on the 4.


 
Posted : 12/12/2013 9:13 am
Posts: 0
Free Member
 

"Just got exactly the same ad and pop-up combination as scuzz."

Same here on my tablet constantly, seems to want me to download
app Mobogenie.


 
Posted : 12/12/2013 9:43 am
Posts: 1048
Free Member
 Drac
Posts: 50607
 

They're on looking into they were discussing what to do this am until they can find the problem of the cause. Sorry it's causing some of you issues folks.


 
Posted : 12/12/2013 3:09 pm
Posts: 3149
Free Member
 

I am having exactly the same problem - lovelinks "your APP store need update immediately" routing to the play store. Very odd - Please post up a solution when it arises.

Only happens when not on Wi-Fi and only with STW web site.


 
Posted : 15/12/2013 5:09 pm
Posts: 78484
Full Member
 

Who's your service provider? Is everyone affected on the same network?

Anyone get the issue when on a wifi connection?


 
Posted : 15/12/2013 5:14 pm
Posts: 3149
Free Member
 

O2.


 
Posted : 15/12/2013 5:22 pm
Posts: 78484
Full Member
 

Hm. Probably not a provider issue then, as I'm on O2 and I've never seen it. Just a thought.


 
Posted : 15/12/2013 5:36 pm
Posts: 357
Free Member
 

Just seen this thread and I am having the same issues with my android phone(Samsung S4) when browsing this site (Chrome). I also keep getting that lovelinks message. Happens when I use the wifi connection or mobile network (I am based in Germany).


 
Posted : 15/12/2013 5:46 pm
Posts: 0
Free Member
 

I'm in Germany too.

Refresh happening constantly....

Getting sick of it. Close to not using the site anymore & moving on...

Maybe time to get the Web site sorted by pro puter geeks.


 
Posted : 15/12/2013 6:24 pm
 pk13
Posts: 2734
Full Member
 

Just so folks know this is happening on other sites as well it's not just an issue on singletrack. It's very annoying though.


 
Posted : 15/12/2013 6:30 pm
Posts: 0
Free Member
 

Been getting the scuzz posted combo on phone and now a love links popup that downloads some crap no matter what you press. Not happy.


 
Posted : 16/12/2013 7:06 pm
Posts: 0
Free Member
 

I was at a hotel on Saturday night and accessed the forum on my tablet through the hotel wifi, and was getting these popups.

Back home and no popups on the tablet on the home network.


 
Posted : 16/12/2013 7:57 pm
Posts: 476
Full Member
 

Also been getting the same combo as scuzz on a nexus 4 running the latest 4.4.2 update, only seems to happen on the phone network (giffgaff btw) never seem it at home on the tablet either


 
Posted : 16/12/2013 9:58 pm
Posts: 0
Free Member
 

Gonna try a different browser...

I'll see if Opera is pron resistant ๐Ÿ˜€


 
Posted : 17/12/2013 12:36 am
Posts: 0
Free Member
 

Getting the same popup: in France, WiFi only, Android and Dolphin mini browser.

Only way out seems to be to force close the browser. AVG free seems to stop it happening (there's a message about an invalid security certificate) but the installation is a bit big for my old phone!


 
Posted : 17/12/2013 10:46 am
 Mark
Posts: 4437
 

Hi Guys,

Could I ask the guys in France and Germany if the banner text of the popup was in English? French or German?

Cheers
Mark


 
Posted : 17/12/2013 11:04 am
Posts: 0
Free Member
 

I got it in Belgium too (Nexus7 on wifi)

It was written in English...


 
Posted : 17/12/2013 11:33 am
 Mark
Posts: 4437
 

This does seem to be a wider issue than just our site. There are many reports of an Android based issue on the web. I'm not distancing ourselves from the problem as it's something we and other sites need to try and track down. As soon as we can track the ad down we will be able to stop it.

Thanks for all the info you've sent to us so far.


 
Posted : 17/12/2013 2:11 pm
Posts: 357
Free Member
 

[i]Hi Guys,

Could I ask the guys in France and Germany if the banner text of the popup was in English? French or German?

Cheers
Mark[/i]

For me in Germany the banner was also in English


 
Posted : 17/12/2013 2:18 pm
Posts: 4892
Free Member
 

This does seem to be a wider issue than just our site. There are many reports of an Android based issue on the web.

Concur, looks like an advert that contains JS has been hacked and is being served by one of the networks.

Not a STW isolated issue


 
Posted : 17/12/2013 4:37 pm
 Mark
Posts: 4437
 

If we catch the actual ad itself when it occurs we will be able to block it and so we will keep hunting for it.


 
Posted : 17/12/2013 5:33 pm
Posts: 0
Free Member
Topic starter
 

Mark,
What information exactly do you need?


 
Posted : 17/12/2013 5:54 pm
 Mark
Posts: 4437
 

We need the html code from within the page that will contain the source of the ad including which ad network it is coming from. For example, right clicking it and selecting 'inspect element' in Chrome.


 
Posted : 17/12/2013 6:18 pm
Page 2 / 6