Monthly Archives: December 2016

“Vitaly Rules Google” – Twitter Referrer Spam in Google Analytics – How To Remove

I recently released a new version of FreeFixer, and as usual after a new release I spend too much time looking at Google Analytics Real-Time stats to check out what my visitors are doing on the web site.

While doing this I noticed traffic with Twitter as the referrer under “Top Social Traffic”:

twitter-referer-spam-google-adsense

Happy times, the users are talking about the new FreeFixer release on Twitter, I thought.

The traffic appeared to be to be originating from Russia and Google Analytics claimed that the page title was:

“Vitaly rules google”

vitaly-rules-google-analytics

I have no such title anywhere on my site. So, this is obviously spam 🙁

So, how can the Twitter referral spam be stopped?

There are a bunch of methods to remove Analytics referer spam such as this one. One way  is to add the spammer’s IP address in the web server’s .htaccess file.

If you don’t have access to the spammers IP or the .htaccess file, you can filter out Twitter referrals in Google Analytics, with these steps:

  1. Click on the Admin tab.admin-tab-google-adsense
  2. Click All Filters in the Account column to the left.all-filters
  3. Click the ADD FILTER button to create a new filter. This filter can be used for all your sites that you have hooked up on Analytics.add-filter
  4. Give the filter a name, set Custom as the filter type and select Campaign Sourcefilter-name-custom-campain-source
  5. Now we need write a regular expression to block the unwanted referrers. In this example, I’ve blocked two sites, twitter.com and motherboard.vice.com. As you can see, each site is separated by the | character. twitter-com-filter
  6. Add the filter to the view where you are experiencing the referrer spam problem, and click Save.apply-filter-and-save

And that’s it. The Twitter.com referrer spam should now disappear from the Google Analytics Real-Time stats, and all the other statistics pages that can be shown.

In my case, I had to wait for a few minutes in order for the filter to take effect.

Did this help you remove the “Vitaly Rules Google” Twitter referral spam?

Did the spam you were getting also originate from Russia?

Thank you for reading!

WMI Commandline Utility Malware Pop Ups – Click NO!

I was helping out a FreeFixer user this morning, trying to track down some malware in his FreeFixer log that he sent me.

While searching for information about a .DLL file, I found a spam post on imgur.com, which linked to another web page that started a download of an executable file.

And this one is pretty nasty. Look at the executable file. As you can see the file is digitally signed by Free Sky Business LP.

exe-free-sky-business-lp

Typically, when you double-click on a file like this, Windows pops up an User Account Control dialog asking if you trust “Free Sky Business LP”. However, this one manage to pop-up and UAC for Microsoft’s WMI Commandline Utility.

wmi-commandline-utility-pop-up

If you click no, the UAC dialog will pop-up again and again and again…

Until you click Yes, which starts the installation of FileFinder.exe.

filefinder

So watch out! Don’t click Yes if the Microsoft’s WMI Commandline Utility UAC dialog pops up.