My phone has a virus?

Thread Tools
 
Search this Thread
 
  #46  
Old 11-29-2016, 08:19 AM
johndeerefarmer's Avatar
johndeerefarmer
johndeerefarmer is offline
Cargo Master
Join Date: Feb 2005
Posts: 2,661
Received 74 Likes on 56 Posts
Originally Posted by 05MilMachine
HiJack ads... - CorvetteForum - Chevrolet Corvette Forum Discussion

Hijack Ads while Browsing via Mobile? Report Details Here! - LS1TECH

Here are some links here to other IB forums with threads covering this recently if anyone cares to read further or just suffer along with other gearheads. I also agree with the mod above that:

"No legitimate, reputable company that hopes to compete in the marketplace and stay in business operates under such a premise."

Ultimately, this is going to be the truth.
Probably why the Administrator can't "find" the problem. It maybe time to move on over to the Dieselstop, or Powerstroke hub and stay there. Regular ads are ok as they do have to pay for the site but ones that lock up the phone, or require the browser to have to be shut down are not cool
 
  #47  
Old 11-29-2016, 09:01 AM
05MilMachine's Avatar
05MilMachine
05MilMachine is offline
Cargo Master
Join Date: Mar 2011
Location: North Texas
Posts: 2,066
Likes: 0
Received 4 Likes on 4 Posts
Originally Posted by johndeerefarmer
Probably why the Administrator can't "find" the problem. It maybe time to move on over to the Dieselstop, or Powerstroke hub and stay there. Regular ads are ok as they do have to pay for the site but ones that lock up the phone, or require the browser to have to be shut down are not cool
I'm not giving up on FTE just yet as there is no better forum out there. It also is worth the subscription to make the ads stop. I only get the redirects when I don't log in. I do fear that new people won't get much past one or two redirects without ever signing up for an account. I know it would have deterred me.
 
  #48  
Old 11-29-2016, 12:40 PM
ctubutis's Avatar
ctubutis
ctubutis is offline
Moderator
Join Date: Nov 2007
Location: Denver Metro Area, CO
Posts: 22,405
Received 72 Likes on 56 Posts
It is extremely time-consuming & difficult to remotely diagnose problems located on somebody else's servers, the IB admins have access to & control of their own infrastructure only.

Legitimate business partners don't operate in an intentionally-malicious fashion, and any partner-owned, server-related problems are generally corrected pretty quickly. But compromised servers belonging to others surely still exist out there on the 'net (some even intentionally malicious) which compromised client devices can still make use of.

Try and access this site from a (uninfected) demo phone in any random cellphone store and I'll bet the results will be different.
 
  #49  
Old 11-29-2016, 06:07 PM
05MilMachine's Avatar
05MilMachine
05MilMachine is offline
Cargo Master
Join Date: Mar 2011
Location: North Texas
Posts: 2,066
Likes: 0
Received 4 Likes on 4 Posts
I was with you until that last sentence. 6 Android devices in my family, and two friends devices all had this same redirect issue on this forum with zero issues elsewhere. I know for a fact that my phone is not infected, nor are my family's devices. I doubt all 8 devices have an undetectable phone virus across two platforms that only activates on IB forums. I do know how to make it stop though...use ad block browser and it will never happen again. I don't condone that approach with a legitimate website as I know they have bills to pay and the overhead to load some banner ads is small. But any site that continues to have issues like redirects or hijacks gets put on that browser.
 
  #50  
Old 11-29-2016, 06:37 PM
mattdoc88's Avatar
mattdoc88
mattdoc88 is offline
Elder User
Join Date: Oct 2013
Posts: 814
Likes: 0
Received 4 Likes on 4 Posts
I deleted the bookmark to FTE on my phone. If I ever hear this issue has been fixed, I'll add it again. Until then, I'm done with using this forum on my phone. It's fine on my laptop with an ad blocker. Having "F*** local single MILFs" pop up and vibrate my phone (plus make it hard to close) while I'm sitting next to my wife or I'm at work on lunch break is unacceptable.
 
  #51  
Old 12-03-2016, 01:55 PM
ctubutis's Avatar
ctubutis
ctubutis is offline
Moderator
Join Date: Nov 2007
Location: Denver Metro Area, CO
Posts: 22,405
Received 72 Likes on 56 Posts
Yes, staying off the FTE mobile site is a good workaround to avoid that crap.

None of the sites you guys show in your screenshots look legitimate - well, I should say the *content* coming from such sites doesn't look legit as a few of the sites look like they could have legitimate intentions but got compromised at one time.

But look at some of that crap....

For example, the one in Post #11 trying to look like Google... when it's in fact apparently coming from sstam.com and is ony impersonating Google.

And Post #20 that shows stuff like "data:/text/html; base64 PC" in the URL bar... that base64 stuff displayed in normal browsing is almost always something evil.

Sites being compromised (to serve up dangerous content) combined with unscrupulous web site owners (sending traffic to said infected sites) brings on this kind of crap, FTE nor IB willingly engage in this kind of behavior.

The **** industry has been known to host (or lead to) this kind of crap for decades; for example, (before mobile smartphones, think normal desktop computers) trying to kill a window by clicking on an X in a corner results in 20 new windows opening up. Or a poisoned cache or cookie that can be accessed via legit sites with the result being redirected to a compromised site; there are lots of mischievous & devious things that can be done to phuque with people. Again, the **** industry has been a gateway to this kind of crap for decades.

Best thing I can suggest is to clear all cookies & cache, run one or more malware detectors (no single product can catch everything in existence), delete browsing history, delete any unfamiliar user accounts that may have been created, possibly uninstall & reinstall the browser software, a last-ditch effort would be to reimage the device.

It is unfortunate that this stuff is being tickled by FTE somehow, but, again, FTE nor IB engage in deceptive, unscrupulous or pornographic advertising (which I would consider stuff like F*** local single MILFs" pop up and vibrate my phone and everything else shown in this thread to be).

~~

Somebody is sure to say they've never been to any **** sites and so that can't be the cause... this kind of crap can come from other sites, too, it's just that the **** industry is a well-known host of this kind of thing.
 
  #52  
Old 12-03-2016, 03:59 PM
05MilMachine's Avatar
05MilMachine
05MilMachine is offline
Cargo Master
Join Date: Mar 2011
Location: North Texas
Posts: 2,066
Likes: 0
Received 4 Likes on 4 Posts
I have narrowed it down to an ad JavaScript that is tickled again by the ad itself. Clearing cache somehow doesn't get rid of it. I had to use "clean master" to remove it. It isn't a virus so nothing of that sort will detect it. It is originated from an ad that stores the script, then activated by another ad that executes it. At best it is a vulnerability in Chrome on Android, but is hardly a virus so nothing detects it. It does nothing but redirect you to the junk seen in the screenshots and freeze your device so you can't back out of it. I believe going further is what would fill your device with viruses. This is just a way to direct the traffic. I found three more IB sites all complaining of this same thing and one of those where a moderator admitted they were battling something suggested the clean master ap. It worked.I feel bad that the IB network is suffering this. I hope the ad partners get a grip on it soon.
 
  #53  
Old 12-03-2016, 09:46 PM
ctubutis's Avatar
ctubutis
ctubutis is offline
Moderator
Join Date: Nov 2007
Location: Denver Metro Area, CO
Posts: 22,405
Received 72 Likes on 56 Posts
Originally Posted by 05MilMachine
It isn't a virus so nothing of that sort will detect it.
Right, and therein lies a big issue with this kind of stuff - as you said, it's not really a virus per se and so old-fashioned virus removal tools won't usually find that kind of thing.

This is one reason why crapware is sometimes base64-encoded, many utilities won't decode that stuff to analyze it.

But there are certain variants of (or artifacts of) this kind of thing that can be (although not necessarily will be) detected by what today are called anti-malware tools & vulnerability scanners. But just like old-fashioned anti-virus scanners, no single product will be able to detect every possible variant.

~~

The advertising space on these sites is sometimes auctioned off to the highest bidder, sometimes with no planning or lead time and ads can be short-lived, making compromised ad partner sites harder to find & block.

What's more obnoxious is, there are sites/software out there that purposely take advantage of certain vulnerabilities in browsers & devices, and sometimes these sites all operate together in unison (and are oftentimes distributed throughout the world). It's a lot of work to try and keep ahead of/secured from this stuff but people (sysadmins) do the best they can.

~~

I have never heard of "clean master," what is it? Can you give a link to it?
 
  #54  
Old 12-03-2016, 10:07 PM
05MilMachine's Avatar
05MilMachine
05MilMachine is offline
Cargo Master
Join Date: Mar 2011
Location: North Texas
Posts: 2,066
Likes: 0
Received 4 Likes on 4 Posts
Search for "clean master" on the Android play store. It is the first ap shown with a broom head for the icon. I would normally never install or allow an ap like that on my phone but it has a lot of feedback, so I tried it. It found quite a few ad based scripts that were resilient to cache and history cleaning, but it was able to delete them. It is an intrusive ap though, so it did its job and got deleted yesterday when it started giving me notifications about ram usage. I can always download it again if I need to clear this stuff. It might be easier to plug into a USB on a computer and navigate to the junk direct, but if you don't know what to look for, this can be dangerous.
 
  #55  
Old 12-04-2016, 01:03 PM
ctubutis's Avatar
ctubutis
ctubutis is offline
Moderator
Join Date: Nov 2007
Location: Denver Metro Area, CO
Posts: 22,405
Received 72 Likes on 56 Posts
Originally Posted by 05MilMachine
Search for "clean master" on the Android play store. It is the first ap shown with a broom head for the icon.
Thank you for posting the name of the cleanup utility that helped you, reps for that; it looks to be this one from the Google Play store, maybe it will help others, too:

https://play.google.com/store/apps/d...r.mguard&hl=en
 
  #56  
Old 12-04-2016, 01:09 PM
05MilMachine's Avatar
05MilMachine
05MilMachine is offline
Cargo Master
Join Date: Mar 2011
Location: North Texas
Posts: 2,066
Likes: 0
Received 4 Likes on 4 Posts
That's the one. It is the Junk files function that does the job.
 
  #57  
Old 12-06-2016, 03:42 PM
IB Tim's Avatar
IB Tim
IB Tim is offline
Site Administrator
Join Date: Jan 2003
Location: 3rd Rock
Posts: 161,998
Received 58 Likes on 30 Posts
So not from FTE
Originally Posted by ctubutis
Thank you for posting the name of the cleanup utility that helped you, reps for that; it looks to be this one from the Google Play store, maybe it will help others, too:

https://play.google.com/store/apps/d...r.mguard&hl=en
 
  #58  
Old 12-06-2016, 08:52 PM
ctubutis's Avatar
ctubutis
ctubutis is offline
Moderator
Join Date: Nov 2007
Location: Denver Metro Area, CO
Posts: 22,405
Received 72 Likes on 56 Posts
Originally Posted by IB Tim
So not from FTE
Correct, it is an app for Android devices that one can download from the Google Play store that will scrub an Android device of malware & related cruft.
 
  #59  
Old 12-07-2016, 08:19 PM
johndeerefarmer's Avatar
johndeerefarmer
johndeerefarmer is offline
Cargo Master
Join Date: Feb 2005
Posts: 2,661
Received 74 Likes on 56 Posts
Originally Posted by ctubutis
Thank you for posting the name of the cleanup utility that helped you, reps for that; it looks to be this one from the Google Play store, maybe it will help others, too:

https://play.google.com/store/apps/d...r.mguard&hl=en
that app happens to be from a Russian company which are known to spy on the United States so I'm sure not going to download and use it!
you are trying to avoid problems on this site and going to create more for yourself. You have to watch what you download
 
  #60  
Old 12-07-2016, 10:08 PM
05MilMachine's Avatar
05MilMachine
05MilMachine is offline
Cargo Master
Join Date: Mar 2011
Location: North Texas
Posts: 2,066
Likes: 0
Received 4 Likes on 4 Posts
The company is known to spy or the Russians? Hundreds of thousands of downloads and plenty of online reviews for it. It is in the Google play store and virusy rouge apps don't get on there very often anymore. Most reviews agree with my opinion that you don't want to leave it installed. You are probably safe to remove the tinfoil hat on this ap. Besides, FTE didn't recommend it, I did. Use whatever works for you, but if you are getting the pop ups, you already have undesirable things residing on your device.
 


Quick Reply: My phone has a virus?



All times are GMT -5. The time now is 03:30 PM.