Go Back  FlyerTalk Forums > Support&Services > Technical Support and Feedback
Reload this Page >

Possible virus in content on front page

Community
Wiki Posts
Search

Possible virus in content on front page

Thread Tools
 
Search this Thread
 
Old Apr 3, 2012 | 6:14 am
  #1  
Original Poster
10 Countries Visited
100k
All eyes on you!
15 Years on Site
 
Join Date: Apr 2007
Location: SEA
Programs: AS MVPG, MGM Rewards Gold, Hhonors ???, National Executive
Posts: 2,708
Possible virus in content on front page

I've hit it multiple times last night and now again today, only on www.flyertalk.com (just the front page). I'm using IE9 on Win7 SP1 X64 with the Fanboy & EasyPrivacy TPL's/ad-blockers.

Microsoft Forefront Endpoint Protection 2010 is flagging something as "Trojan:JS/IframeRef". That doesn't appear to be a recent threat, and fortunately the software removes it. But you might want to have a look.
OverThereTooMuch is offline  
Old Apr 11, 2012 | 3:40 pm
  #2  
10 Years on Site
 
Join Date: Jan 2012
Programs: AA EP; HH Diamond; Marriott Plat; IHG Plat; National EE
Posts: 349
Same issue

Win 7 Professional 32-bit. Getting same trojan hit only on front page from Forefront Client Security with definitions 1.123.1537.0. IT reimaged machine and it still happens.
mwk190 is offline  
Old Apr 15, 2012 | 12:06 pm
  #3  
10 Countries Visited
20 Countries Visited
30 Countries Visited
20 Years on Site
 
Join Date: Jan 2006
Posts: 58
I am having the same issue with MSE flagging JS/iframeref on the www.flyertalk.com home page. Is anything being done about this?
soupcxan is offline  
Old Apr 16, 2012 | 9:38 am
  #4  
 
Join Date: May 2003
Location: Des Moines, IA, United States
Posts: 246
Same here, with Forefront Security as well. My corporate IT guys are going to block this site now. What is going on?
jeffcarp is offline  
Old Apr 16, 2012 | 11:18 am
  #5  
No longer with Internet Brands
10 Years on Site
 
Join Date: Mar 2011
Location: Los Angeles, CA
Programs: DL DM 1.6MM, Marriott LT Plat
Posts: 5,343
Originally Posted by jeffcarp
Same here, with Forefront Security as well. My corporate IT guys are going to block this site now. What is going on?
Originally Posted by soupcxan
I am having the same issue with MSE flagging JS/iframeref on the www.flyertalk.com home page. Is anything being done about this?
Could those who are seeing this warning refresh their browsers and see if it's something cached locally? CTRL-F5. We're seeing so few reports of this I'm loathe to think it's something on our home page, but we'll look again. Tech hasn't seen anything over the last couple of weeks.
IBobi is offline  
Old Apr 16, 2012 | 2:19 pm
  #6  
 
Join Date: May 2003
Location: Des Moines, IA, United States
Posts: 246
I just completely deleted my all temporary Internet files and cookies, closed my browser, rebooted and went back to Flytalk's main page. Boom. I immediately got a warning from Microsoft Forefront Endpoint Protection for Trojan:JS/IframeRef.

If I enter the site through a URL that takes me directly to a specific forum, I do NOT get the warning. There is something on the main page that is happening.
jeffcarp is offline  
Old Apr 16, 2012 | 2:28 pm
  #7  
 
Join Date: May 2003
Location: Des Moines, IA, United States
Posts: 246
Here is the technical commentary for this:

Technical Information (Analysis)

Exploit:HTML/IframeRef.gen is generic detection for specially formed IFrame tags that point to remote Web sites containing malicious content, for example malicious Javascript containing an exploit for a specific vulnerability.

Installation

An IFRAME is a valid HTML element which allows content from a separate page or Web site to be embedded in other Web site pages. In the case of Exploit:HTML/IframeRef.gen, a malicious IFrame is appended at the end of local html files. The rendered IFrame may be only one pixel in length to avoid being spotted by the user.

Exploit:HTML/IframeRef.gen requires that a user view or visit the Web sites or open the HTML page in order for malicious action to occur.
jeffcarp is offline  
Old Apr 28, 2012 | 8:16 pm
  #8  
 
Join Date: Jul 2007
Location: NYC & Delhi
Programs: CO Pres. Plat, SPG
Posts: 546
I'm seeing it on several brand new computers that have nebver visited flyertalk.

AVG Reports:

Threat Blocked
powerpint.net/in.cgi?2
Virus identified, HTML/Framer.FM (more)
marklyon is offline  
Old Apr 29, 2012 | 7:27 am
  #9  
Flyertalk Evangelist and Moderator: Coupon Connection and Travel Products
30 Countries Visited
1M
Conversation Starter
25 Years on Site
 
Join Date: Jul 2000
Location: Milton, GA USA
Programs: Hilton Diamond, IHG Platinum Elite, Hyatt Discoverist, Radisson Elite
Posts: 19,217
My computer has never been the same since I started having the powerpint.net errors.

I have tried several programs to try and eradicate the problem... but my computer will not return to its former speed. Not sure what to do... very disappointed.
wharvey is offline  
Old Apr 29, 2012 | 4:16 pm
  #10  
FlyerTalk Evangelist
All eyes on you!
20 Years on Site
 
Join Date: Sep 2001
Location: FW, TX, USA, Earth, Milky Way
Programs: 2008 FT1 Fantasy Football Champion
Posts: 10,858
I'm getting a hit on the front page this weekend. Avast reports the URL as (spaces added):
Code:
http:// ui.ibsrv.net /ibsrv /res /src:www.flyertalk.com /get /js /nav.js
empedocles is offline  
Old May 1, 2012 | 1:31 am
  #11  
30 Countries Visited
Community Builder
All eyes on you!
15 Years on Site
 
Join Date: Jul 2007
Location: Sydney (for now), GVA (only in my memories)
Programs: QF Lifetime Silver (big whoop)
Posts: 9,287
Originally Posted by IBobi
Could those who are seeing this warning refresh their browsers and see if it's something cached locally? CTRL-F5. We're seeing so few reports of this I'm loathe to think it's something on our home page, but we'll look again. Tech hasn't seen anything over the last couple of weeks.
Anything happening to fix this? Other people (at other sites) are reporting getting malware warnings when they come to FT.
RadioGirl is online now  
Old May 1, 2012 | 11:49 am
  #12  
No longer with Internet Brands
10 Years on Site
 
Join Date: Mar 2011
Location: Los Angeles, CA
Programs: DL DM 1.6MM, Marriott LT Plat
Posts: 5,343
Tech is still looking into this; we are not seeing the warnings on our end, so they're trying to get as much info on browser type/version and which page(s) on FT you're seeing the warning?
IBobi is offline  
Old May 1, 2012 | 4:55 pm
  #13  
No longer with Internet Brands
10 Years on Site
 
Join Date: Mar 2011
Location: Los Angeles, CA
Programs: DL DM 1.6MM, Marriott LT Plat
Posts: 5,343
It looks like some users' browsers cached an infected file: nav.js.

Please purge your cache. We will do the same on our end. If this does not cause the warning to disappear, let me know and we'll dig deeper.
IBobi is offline  
Old May 2, 2012 | 11:36 am
  #14  
No longer with Internet Brands
10 Years on Site
 
Join Date: Mar 2011
Location: Los Angeles, CA
Programs: DL DM 1.6MM, Marriott LT Plat
Posts: 5,343
Any new warning messages? Did we lick it?
IBobi is offline  
Old May 3, 2012 | 6:18 pm
  #15  
30 Countries Visited
Community Builder
All eyes on you!
15 Years on Site
 
Join Date: Jul 2007
Location: Sydney (for now), GVA (only in my memories)
Programs: QF Lifetime Silver (big whoop)
Posts: 9,287
I had a super-nasty virus infection in March (not, AFAIK, from FT) which required reimaging and reinstalling huge amounts of software and data, twice. I'm not risking another virus to check whether this works. Surely there are other ways to check rather than asking FTers to take the risk.
RadioGirl is online now  


Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.