Go Back  FlyerTalk Forums > Support&Services > Technical Support and Feedback
Reload this Page >

FALSE Virus alert [there is NO malware on your computer]

Community
Wiki Posts
Search

FALSE Virus alert [there is NO malware on your computer]

Thread Tools
 
Search this Thread
 
Old Aug 1, 2012, 10:17 am
  #241  
No longer at Internet Brands
 
Join Date: Oct 2007
Location: El Segundo CA
Programs: America Advantage
Posts: 150
We just blocked that url from all channels but it may take a few minutes to process. Please let me know if you keep seeing it.
bconver is offline  
Old Aug 1, 2012, 10:26 am
  #242  
 
Join Date: Aug 2010
Posts: 154
Originally Posted by Doug_1970
^ Good job.

Just for my academic interest, how hard was this to work out? Was it something that any competent IT person could work out, or was it more specialised?
Thanks

I have no formal IT training, but have always been fairly competent/keen to learn when it comes to IT. I have had some spare time this week and spent a while on this case. I cannot stress how much Google is your friend though.

Anyone with basic website (HTML/java) knowledge could have worked it out, the key though was being able to replicate the problem with a logger tracking all the traffic (the redirect happens within a split second). I found a logger (HTML Analyzer) last night which does exactly that, but couldn't replicate the problem. However, it happened today and I was able look through the history (which is quite in depth) and work back from the redirect site with the malware back to the FT forums.

I think the key thing I missed was the fact that the redirects were intermittent. Initially I mistakenly thought there was an exploit in the forum software as there have been problems previously on other forums being exploited. But the intermittent nature shows it was coming from something on the site that rotates (i.e. a banner/advert).

I would be interested to know how the bogus site was able to operate a banner here. There appears to be no track record of the company/site and the domain name owners have a whois block service so you don't know where they are from.
MoneyBagger is offline  
Old Aug 1, 2012, 11:07 am
  #243  
 
Join Date: May 2005
Posts: 3,944
Good work, MoneyBagger! ^

Any ideas on the purpose of the redirect? Is the purpose likely just to "sell" bogus virus-removal programs?
SkeptiCallie is offline  
Old Aug 1, 2012, 11:34 am
  #244  
 
Join Date: Aug 2010
Posts: 154
Originally Posted by SkeptiCallie
Good work, MoneyBagger! ^

Any ideas on the purpose of the redirect? Is the purpose likely just to "sell" bogus virus-removal programs?
Essentially yes. Here's how it works:

http://www.f-secure.com/weblog/archives/00002053.html
http://www.pcworld.com/businesscente...ssentials.html
http://blogs.technet.com/b/mmpc/arch...ake-innit.aspx

There are some good online sites which you can use to check if a site is legitimate or infected:

http://www.virustotal.com/ - Online virus scanner/site checker
http://urlquery.net/ - Site Scanner
http://www.unmaskparasites.com/ - Site Scanner
http://zulu.zscaler.com/ - Site scanner/inspector
http://www.avgthreatlabs.com/sitereports/ - Site scanner (part of AVG)
MoneyBagger is offline  
Old Aug 1, 2012, 12:06 pm
  #245  
 
Join Date: Aug 2010
Location: LGA - JFK
Programs: UA, AA, DL, B6, CX, KE, Latitude, VIFP, Crown & Anchor, etc.
Posts: 2,589
Originally Posted by MoneyBagger
Essentially yes ... There are some good online sites which you can use to check if a site is legitimate or infected:
Bravo, kudos & thanks to MoneyBagger for helping FT and rest of us - some of us knew something just isn't right ... Using Firefox on my own laptop now but when on the road, it isn't a matter of choice to avoid or not use IE 8 or 9.

When we had similar issues & popups randomly over at Cruisecritic dot com, it drove some of us nuts for weeks - and it was tracked down only a few weeks ago (the details & threads/links are mostly gone/deleted & no longer available to members) - my best recollection of the summary finding was that it was malware codes/scripts hidden in graphics/logos commonly used by CC members, and it got in & launched itself - very similiar MSE phony threat reports and offering to fix it (as we've saw them here on FT.)

Furthermore, the danger and risks pose is that, one's credit card/names & other personal info were exposed in the course of purchasing/authorizing/downloading the said "fixes" in solving the security problem - escalating and potential risking hundreds if not thousands in charges to one's CC account.

The practice goes back to the 1980's when we're surfing AOL and bragging about 56K modems - we've come a long way but the bad apples are still out there, and getting more sophisticated. My firewall, antivirus & spyware logs and reports all looked clean, deep & full scanning sweeps done showing no harm inflicted thus far, yet (fingers crossed )

Last edited by Letitride3c; Aug 2, 2012 at 10:51 pm
Letitride3c is offline  
Old Aug 1, 2012, 12:39 pm
  #246  
 
Join Date: May 2005
Posts: 3,944
Originally Posted by MoneyBagger
Essentially yes. Here's how it works:

http://www.f-secure.com/weblog/archives/00002053.html
http://www.pcworld.com/businesscente...ssentials.html
http://blogs.technet.com/b/mmpc/arch...ake-innit.aspx

There are some good online sites which you can use to check if a site is legitimate or infected:

http://www.virustotal.com/ - Online virus scanner/site checker
http://urlquery.net/ - Site Scanner
http://www.unmaskparasites.com/ - Site Scanner
http://zulu.zscaler.com/ - Site scanner/inspector
http://www.avgthreatlabs.com/sitereports/ - Site scanner (part of AVG)
Thanks for the answer.

This whole matter did get me to download the real MSE yesterday. A quick scan shows no problem. Also, Malwarebytes' Anti-Malware shows no problem.
SkeptiCallie is offline  
Old Aug 1, 2012, 8:47 pm
  #247  
 
Join Date: Apr 2007
Location: SEA
Programs: AS MVP, Hhonors Gold, National Executive, Identity Gold, MLife Gold
Posts: 2,687
Originally Posted by Letitride3c
Bravo, kudos & thanks to MoneyBagger for helping FT and rest of us
^^^^^
OverThereTooMuch is offline  
Old Aug 2, 2012, 12:41 am
  #248  
Community Director Emerita
 
Join Date: Oct 2000
Location: Anywhere warm
Posts: 33,742
Thank you, MoneyBagger.
SanDiego1K is offline  
Old Aug 2, 2012, 2:45 am
  #249  
uk1
Suspended
 
Join Date: Jan 2004
Location: UK
Posts: 11,969
Well done. ^
uk1 is offline  
Old Aug 2, 2012, 4:57 am
  #250  
 
Join Date: Jul 2012
Posts: 21
Well done MoneyBagger!! :0) As someone else said IT should have picked up on this ages ago!
Jay2261 is offline  
Old Aug 2, 2012, 8:12 am
  #251  
 
Join Date: Jun 2003
Location: Denver CO
Programs: HHonors Gold, National Emerald Club, no airline affinity status
Posts: 3,349
Moneybagger, thanks for the information. Job well done. Hopefully FT recognizes you appropriately.
HawaiiTrvlr is offline  
Old Aug 2, 2012, 4:39 pm
  #252  
No longer with Internet Brands
 
Join Date: Mar 2011
Location: Los Angeles, CA
Programs: DL DM 1.6MM, Marriott LT Plat
Posts: 5,343
Thumbs up

Originally Posted by HawaiiTrvlr
Moneybagger, thanks for the information. Job well done. Hopefully FT recognizes you appropriately.
Indeed
IBobi is offline  
Old Aug 3, 2012, 3:46 pm
  #253  
 
Join Date: Jun 2012
Location: England
Programs: Executive Club Silver
Posts: 711
The warning hasn't appeared so far so it looks like Money has solved the mystery.

If it weren't for you I doubt this issue would have ever been resolved. I hope too many people weren't put off visiting the site because of it.
PotNoodle is offline  
Old Aug 3, 2012, 4:07 pm
  #254  
 
Join Date: Apr 2009
Posts: 85
Have not had a recurrence today yet....
g-didi is offline  
Old Aug 3, 2012, 6:18 pm
  #255  
 
Join Date: Mar 2010
Programs: AA Plat, Marriott Plat
Posts: 736
Finally, someone with mad skillz. Now if you could only become a moderator to help us out...
living near shamu is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.