Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

AVG disguises fake traffic as IE6
The Register ^ | 6/26/08 | Cade Metz

Posted on 06/27/2008 12:05:44 PM PDT by LibWhacker

Exclusive AVG has rejiggered the fake traffic it's spewing across the internet, causing new headaches for the world's webmasters.

In late February, AVG paired its updated anti-virus engine with a real-time malware scanner that vets search engine results before you click on them. If you search Google, for instance, this LinkScanner automatically visits each address that turns up on Google's results page.

According to the company, more than 20 million people have downloaded the new AVG 8, and this has caused a huge up-tick in traffic on sites across the web, including The Register. Because the scanner attempts to disguise itself as a real live human click, webmasters who rely on log files for their traffic numbers may be unaware their stats are skewed. And others complain that LinkScanner has added extra dollars to their bandwidth bill.

Daniel Brandt, who runs Wikipedia Watch (http://www.wikipedia-watch.org/), estimates that LinkScanner traffic to the site has outstripped legitimate clicks by nearly ten times. In this graph, the pink line represents suspected LinkScanner scans, the blue line legitimate clicks:


LinkScanner meets Wikipedia Watch

When we first told the tale (http://www.theregister.co.uk/2008/06/13/avg_scanner_skews_web_traffic_numbers/) of AVG's fake traffic earlier this month, we pointed out that if webmasters were wise to the problem, they could filter LinkScanner visits from their log files. Each scan left a unique user agent: "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;1813)."

But over the weekend, the company changed this user agent on the for-pay version of AVG 8. It appears that scans now use these agents as well:

Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)

User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)

User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;1813)

Judging from the log files of two separate web sites, including Wikipedia Watch, the first agent is by far the most common. Which is bad news for webmasters. That's also the Internet Explorer 6 user agent. Unlike the other two - and the original "1813" agent - it's a perfectly valid agent that may turn up with real clicks.

AVG's chief of research Roger Thompson says the for-pay LinkScanner is only using the IE6 user agent. Presumably, the company believes this is more likely to fool malware exploits. "There are still ways for concerned web masters to filter LinkScanner requests out of their statistics," he told us over email. But he did not acknowledge that this could clip legitimate traffic as well.

Many webmasters may have no choice but to abandon log file analysis, adopting alternative tools from companies like Google, Yahoo!, comScore, or Nielsen NetRatings. And these tools have their drawbacks. comScore's service tends to underestimate traffic from daytime work machines. And if you go with Google Analytics, you have to tag your pages with JavaScript - and share your traffic numbers with Google.

Plus, these tools won't solve the bandwidth issue.

In an effort to fix this problem, one web master advocates redirecting AVG scans back to AVG's site. "Many webmasters simply tell LinkScanner to scan AVG's site instead, so their site gets marked as malware free every time - while AVG gets handed the extra bandwidth cost," says the webmaster of TheSilhouettes.org (http://www.TheSilhouettes.org/).

But this assumes that AVG is using a unique agent. And at the moment, it's not. The send-it-back-to-AVG method may redirect legitimate clicks as well.

Which gets to the heart of the matter: AVG's security philosophy is fundamentally at odds with webmaster peace of mind. The company wants to scan search results, and it wants to scan them in a way that's difficult to distinguish from real traffic. "In order to detect the really tricky - and by association, the most important - malicious content, we need to look just like a browser driven by a human being," AVG chief of research Roger Thompson has told us.

And if that causes problems for webmasters, Thompson says, so be it. "I don't want to sound flip about this, but if you want to make omelets, you have to break some eggs."

Clearly, the company doesn't fully realize the importance of web analytics. "Web analytics is about finding trends which can help online marketers/webmasters improve things for their visitors and their businesses," says Steve Jackson, co-chair of the International Web Analytics Association. "It's a big part of the whole online ecosystem in a fast growing up industry.

"No-one wants spyware or viruses, and AVG does provide a useful service which is getting better all the time. I wish, however, they would take business needs into account before launching software that makes life even more difficult for the people trying to do the analytics. Web analytics is not easy at the best of times, and this kind of thing from AVG just compounded the problem.

"In order to make an omelet you have to crack some eggs. But a good omelet has cheese, ham, peppers, mushrooms and all sorts of other ingredients which AVG seem to have forgotten about."

But AVG continues to say it's working to solve the problem - including the bandwidth issue. Referring to LinkScanner's new IE6-like user agent, Thompson told us, "We intend to leave those in place until we can find the right balance point which will allow us to continue to provide the best possible protection for our customers, without imposing too much extra bandwidth on websites." ®


TOPICS: Computers/Internet
KEYWORDS: antivirus; avg; bandwidthhog; fake; linkscanner; traffic
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-71 last
To: rabscuttle385
Please list for us the "in the wild" viruses that run on Linux.

Oh...that's right...there aren't any.

Nothing is 100% secure if it is used.

But there is a vast difference between Linux and Windows when it comes to vulnerabilities from viruses.

61 posted on 06/27/2008 6:45:09 PM PDT by B Knotts (Calvin Coolidge Republican)
[ Post Reply | Private Reply | To 24 | View Replies]

To: LibWhacker
Okay, thanks to all of you again! I am now a proud user of AVG Free v8.0. I disabled LinkScanner and the increase in speed was quite noticeable on this machine.

I haven't downloaded AVG Free v8.0 yet. Is it easy to disable LinkScanner on the free edition?

62 posted on 06/30/2008 11:03:21 AM PDT by CedarDave
[ Post Reply | Private Reply | To 50 | View Replies]

To: papasmurf
And, BTW, even if you turn it off, it [linkscanner?] still goes out and scans and connects to akamai.

Bummer... Think I'll try something else.

63 posted on 06/30/2008 11:09:04 AM PDT by CedarDave
[ Post Reply | Private Reply | To 53 | View Replies]

To: CedarDave

It still tries to connect, my zonealarm pops up, but I don’t see the AVG stuff on google.

I’m looking for deal on Kapersky, which is a better AV, IMO, for my Network.


64 posted on 06/30/2008 11:16:44 AM PDT by papasmurf
[ Post Reply | Private Reply | To 63 | View Replies]

To: CedarDave
Is it easy to disable LinkScanner on the free edition?

I just did on mine, not two minutes ago after reading the thread....I hope it improves the sluggishness during the 3 hours it takes for the daily scan.

65 posted on 06/30/2008 11:34:59 AM PDT by ErnBatavia (...forward this to your 10 very best friends....)
[ Post Reply | Private Reply | To 62 | View Replies]

To: weef

I’ve been using Avast! on my home machines. Turn off the voice that tells you each time the database was updated and it is very unobtrusive and works well.


66 posted on 06/30/2008 11:45:07 AM PDT by listenhillary (There's more people in the wagon, than there is pushin')
[ Post Reply | Private Reply | To 20 | View Replies]

To: ErnBatavia

Let us know so we can decide whether to avoid another piece of bloatware.


67 posted on 06/30/2008 11:50:01 AM PDT by CedarDave
[ Post Reply | Private Reply | To 65 | View Replies]

To: LibWhacker

Yep - sad news on AVG, and I found out early because I use the full commercial edition. It’s bloatware now. Used to be so nice and clean... :-(


68 posted on 06/30/2008 11:52:00 AM PDT by Billthedrill
[ Post Reply | Private Reply | To 1 | View Replies]

To: listenhillary
Turn off the voice that tells you each time the database was updated and it is very unobtrusive and works well.

Scared the hell out of me one time when I was sleeping.

69 posted on 06/30/2008 11:57:10 AM PDT by Stentor (Obama supporters. Letting the little void do the thinking for the big void.)
[ Post Reply | Private Reply | To 66 | View Replies]

To: CedarDave
I'm the furthest possible from knowing anything about computers! Anyhow, since my scan runs from 10am until around 1pm, I did this in mid-scan, and my machine is still running slower than before 8.0.

I think I'm going to re-enable the link scan, since AVG keeps flashing that I'm at risk for everything short of HIV if I don't.....

70 posted on 06/30/2008 12:05:08 PM PDT by ErnBatavia (...forward this to your 10 very best friends....)
[ Post Reply | Private Reply | To 67 | View Replies]

To: CedarDave
Very easy. It asks you during installation whether you want to enable or disable it.

After it's installed... I'm not so sure. Sounds pretty easy though.

71 posted on 07/01/2008 10:41:03 AM PDT by LibWhacker
[ Post Reply | Private Reply | To 62 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-71 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson