Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

SEM Tycoon


You are currently viewing our SEM Tycoon as a guest. Please register to participate.
Login



Reply
Embedded virus hyjack in advertising banner through networks - Winfixer
Old 08-05-2007, 07:52 PM Embedded virus hyjack in advertising banner through networks - Winfixer
Frito Pie's Avatar
Webmaster Talker

Posts: 662
Trades: 0
I am running Tribal Fusion on my site on first tier with Burst media on second tier. I have both ad networks set to NO popups. Ultra conservative with the choices of the ads I allow on my site.

Starting a few days ago I visited my site, beginning of my first session of the day, and was greeted with a pop up telling me that a virus was detected on my PC and to click here to download Winfixer.

Now before anyone tells me I have a virus, I'm on a Mac. OSX. No way I have a virus that was sent to this company by a bad exe file on my computer. I don't have exe files.

I logged into TF and Burst and double checked my settings. I even added a block on the domain for amaena.com in my TF manage block domains.

Still I have complaints from members/staff they are receiving popups on their first session of the day, telling them about winfixer. For those on a PC, it takes over things for a while.

I've contacted TF and Burst and of course both say it wasn't them.

To add to the mystery, I have google ads set to text only. But sometimes, upon opening of my site first thing in the morning, there is an image ad in the google leaderboard space. (I don't use TF or Burst for leaderboard there)

So I'm wondering, is it possible someone is hiding winfix/amaena.com ads in google text ads that launch popups? Or is this a hidden ad in a legit campaign on tf or burst?

Ideas?
Attached Images
File Type: jpg amaena.jpg (30.7 KB, 9 views)
File Type: jpg amaema.jpg (28.2 KB, 6 views)
__________________
Its not really about the money,
Frito
Frito Pie is offline
Reply With Quote
View Public Profile
 
 
Register now for full access!
Old 08-06-2007, 01:06 AM
nwingate's Avatar
Novice Talker

Posts: 5
Trades: 0
I thought I read somewhere that a few viruses had recently made there way onto Adsense. Don't remember the source though. Maybe TWIT.
nwingate is offline
Reply With Quote
View Public Profile
 
Old 08-06-2007, 11:20 AM
skyhawk133's Avatar
Extreme Talker

Posts: 154
Trades: 0
Do you have a stray default (i.e. a different second/third tier) set some place?
__________________

Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE
skyhawk133 is offline
Reply With Quote
View Public Profile Visit skyhawk133's homepage!
 
Old 08-06-2007, 11:21 AM
Frito Pie's Avatar
Webmaster Talker

Posts: 662
Trades: 0
I'm going to document my finds here as I think it will help others looking for help as they search/google for an answer.

In addition to the ad code for tribal fusion and burst, I have a main account with gorilla nation with no campaigns at the moment. Therefore, in my leaderboard space which usually is 90% adsense, I use gorilla nation code with my own phpadsnew code as default (which then runs my own direct sales ads and google adsense.) I know it sounds complicated but it isn't to me as GN sells direct sales, non-exclusive, to my site. Supposedly none at the moment.

As these popups started and continued, I removed the GN code and inserted my own phpadsnew code in its place, removing GN from the mix with the intent of eliminating all except what I knew I could control. I removed/blocked ads from Burst and TF.

The pop-ups stopped. Of course I had no way of knowing what I had done to stop the ads. I needed to stop them immediately first so as not to confuse or (worse) infect my members.

This morning I started at the top. Adding only the GN code back in the place of my own code and Wah-la. There it was.

A careerbuilder ad in the leaderboard, delivered by Gorilla nation (leaking? I don't have any active ads right now) and an amaena.com popup as shown above. This time with another landing page as I clicked CANCEL and was taken to a download page.

I immediately removed the GN code, looked in my GN control panel and see that starting August 1 I have been sent careerbuilder leaderboard ads. So, this means that whether on purpose or in a leaking, careerbuilder ads are being documented on my site through GN code.

I've contacted GN with the evidence, screenshots, urls, etc.

This means that the careerbuilder ads, run through GN (and other networks) are infected with this hyjack ad for amaena.com winfixer.
__________________
Its not really about the money,
Frito
Frito Pie is offline
Reply With Quote
View Public Profile
 
Old 08-06-2007, 05:03 PM
Frito Pie's Avatar
Webmaster Talker

Posts: 662
Trades: 0
FYI:

Hackers Can Now Deliver Viruses via Web Ads - WSJ.com
__________________
Its not really about the money,
Frito
Frito Pie is offline
Reply With Quote
View Public Profile
 
Old 08-07-2007, 05:30 AM
imported_Dave Hybrid's Avatar
Junior Talker

Posts: 16
Trades: 0
Been getting the exact same thing and I'm with TF and Burst.

I'm 99% it's TF as i have had it happen to me on other sites using TF.

Contacted them also, they made me take screen shots and document everything and in the end they said it was nothing to do with them.
imported_Dave Hybrid is offline
Reply With Quote
View Public Profile
 
Old 08-07-2007, 09:51 AM
Frito Pie's Avatar
Webmaster Talker

Posts: 662
Trades: 0
Are you getting the winfix popup with a careerbuilder ad?

Once I removed the GN code, the ads stopped. I also put back the burst and TF code and the ads have not continued.

Is it happening in your computer forums? I'd like to take a look?
__________________
Its not really about the money,
Frito
Frito Pie is offline
Reply With Quote
View Public Profile
 
Old 08-07-2007, 09:56 AM
imported_Dave Hybrid's Avatar
Junior Talker

Posts: 16
Trades: 0
Yeah, it is my forum.

I was getting drivecleaner.com and reghelper.com

Both spyware crap.

I haven't managed to track them down but the only explanation is TF really as it only happens on my site or other sites running TF.
imported_Dave Hybrid is offline
Reply With Quote
View Public Profile
 
Reply     « Reply to Embedded virus hyjack in advertising banner through networks - Winfixer
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.26201 seconds with 13 queries