FlyerTalk Forums

FlyerTalk Forums (https://www.flyertalk.com/forum/index.php)
-   Technical Support and Feedback (https://www.flyertalk.com/forum/technical-support-feedback-386/)
-   -   FALSE Virus alert [there is NO malware on your computer] (https://www.flyertalk.com/forum/technical-support-feedback/1368367-false-virus-alert-there-no-malware-your-computer.html)

Polar Man Jul 19, 2012 9:37 pm

FALSE Virus alert [there is NO malware on your computer]
 
For those just coming to this thread for the first time, I have taken the liberty of pre-pending IBobi's answer from downstream here. cblaisd, Senior Moderator:


Originally Posted by IBobi (Post 19008579)
Hi everyone,

Once again, there is *no* malware on FlyerTalk.

We are working to determine which advertisement is causing this messaging to occur.

This kind of advertising is *not* approved by FT, and will immediately be blocked when it is located. Meanwhile, be assured that despite the message it shows you, you do not have a virus (from this) and FT is not infected. This is an advertisement that appears to be exploiting a hole in *Internet Explorer* to show a *false* virus alert.

One way to avoid it is to switch browsers to Chrome or Firefox.

I'll update as soon as I have new information; thank you for your continued patience while we work to block this ad.

Paul

Twice in the last two days while using FT i have had a pop up appear. It is designed to make it look like MS security essentials notice.

http://i5.photobucket.com/albums/y193/Braybuddy/MS.jpg

ExitRowAisle Jul 19, 2012 10:14 pm

While I didn't get the specific virus alert that Polar Man mentions, I also noticed unusual virus alert messages while accessing FT the last couple of days, both on my home and work computers.

Michilander Jul 20, 2012 7:48 am

I, too, have gotten these alerts the past two days. Norton says

Category: Intrusion Prevention
7/20/2012 9:34 AM,High,An intrusion attempt by 173.254.192.44 was blocked.,Blocked,No Action Required,Fake App Attack: Fake AV Website

SkeptiCallie Jul 20, 2012 10:35 am

I got them on FT website (only) for 2-3 days, with wording:


Message from webpage

Viruses were found on your computer. You need to clean your computer to prevent the system crash. [OK]
When I tried to close the browser, I couldn't. Had to shut the computer down and restart.

Wilbur Jul 20, 2012 11:51 am

I am also getting the MSE look-alike virus warning, but only with IE, not chrome.

IBobi Jul 20, 2012 1:31 pm

Thank you all, we're looking into this, but FT appears to be clean. No virus found at all.

If someone can post a screen shot, we'll look into whether this is ad-related, or some other possibility?

Thank you!

Paul

HNLbasedFlyer Jul 20, 2012 2:09 pm

I'll remember to grab a screenshot - but I've gotten this virus warning today on separate computers - it just seems to happen randomly but always on the flyertalk site.

mcgahat Jul 20, 2012 2:50 pm

I got the pop up yesterday and this morning. I will try to grab a screenshot if I get it again. I wonder if it really came from a banner?

TravellerFrequently Jul 20, 2012 3:29 pm

+1 to Polar Man's experience.

Michilander Jul 20, 2012 5:48 pm

I got a different pop-up than Polar Man got. If I get it again, I will post a screen shot.

I also only got this once yesterday and once today, despite numerous visits to FT. Have just assumed it was ad based. Did you check out the IP I posted earlier?

g-didi Jul 20, 2012 8:23 pm

+1 to Polar Man

wrp96 Jul 20, 2012 8:29 pm

I got the same message as Skepticallie yesterday. Had to into my task manager to shut it down.

McCoy Jul 21, 2012 3:05 am

Just got the same.
Have emailed you, IBobi. - I have a screenshot I can send you.

Was going to http://www.flyertalk.com/forum/usercp.php, but the address bar changed, pop-up appeared and Norton antivirus blocked a Fake App attack...

Closed it all, and worked fine this time.

Polar Man Jul 21, 2012 10:02 am

here is the screen shot.

http://i71.photobucket.com/albums/i1..._man/virus.jpg

If you click on the x to close the popup then the " microsoft" warning pops up on a blank screen.

MR_MAMA Jul 21, 2012 11:03 am

I also received it, I looked at the address bar at the top and this is where it is coming from..but only when I come to flyertalk

http://guarantorqueerprocessinspecti...84cb2/pr2/196/

spd476 Jul 21, 2012 1:24 pm


Originally Posted by Polar Man (Post 18974472)
here is the screen shot.

http://i71.photobucket.com/albums/i1..._man/virus.jpg

If you click on the x to close the popup then the " microsoft" warning pops up on a blank screen.

I've got the same thing in the last couple of days on different computers.

SkeptiCallie Jul 21, 2012 3:15 pm

This last time, a few minutes ago, the address bar changed to:

[deleted, per ff post]

A Google search produced nothing for that entire string, though there is evidently an "onlinecleancustodian.pl" but with other numbers in the last part of the string, and even then only one hit on Google.

Michilander Jul 21, 2012 5:03 pm


Originally Posted by SkeptiCallie (Post 18976047)
This last time, a few minutes ago, the address bar changed to:

http://onlinecleancustodian.pl/550r1...84cb2/pr2/196/

A Google search produced nothing for that entire string, though there is evidently an "onlinecleancustodian.pl" but with other numbers in the last part of the string, and even then only one hit on Google.

Just got another hit. Pop-up looked the same as the one Polar Man posted earlier today.

Norton reported

Category: Intrusion Prevention
An intrusion attempt by delivereravshield.pl was blocked.,Blocked,No Action Required,Fake App Attack: Fake AV Website 20,No Action Required,No Action Required,"delivereravshield.pl (96.44.155.85, 80)”

SkeptiCallie, clicking on the link you posted gets you another hit from the fake virus website. Maybe you could remove the hyperlink in the future? Thanks.

SkeptiCallie Jul 21, 2012 5:07 pm


Originally Posted by Michilander (Post 18976490)
Just got another hit. Pop-up looked the same as the one Polar Man posted earlier today.

Norton reported

Category: Intrusion Prevention
An intrusion attempt by delivereravshield.pl was blocked.,Blocked,No Action Required,Fake App Attack: Fake AV Website 20,No Action Required,No Action Required,"delivereravshield.pl (96.44.155.85, 80)”

SkeptiCallie, clicking on the link you posted gets you another hit from the fake virus website. Maybe you could remove the hyperlink in the future? Thanks.

Thanks, glad to do so. I hadn't noticed that that was a hyperlink, just thought I was giving the address for IDing it. If mods need the link again, just PM me and I'll supply it to you. (Michelander, just to be thorough, could you also delete it in your quote of my post, and TIA.)

Flyingmama Jul 21, 2012 5:17 pm

I got the same message earlier today as well as yesterday. But it didn't come as a small message box - rather it took over the entire FT page. When I x out, the whole browser window closes and I have to re-open the browser.

It certainly is annoying.

Vulcan Jul 21, 2012 6:31 pm

I received the same message about 2 hours ago. I closed it and ran SuperAntiSpyware and it came up clean.

HawaiiTrvlr Jul 21, 2012 8:36 pm

I had similar notice when I have clicked on FT lately. It sets off my Norton saying they blocked an intrusion by "dangerdefenderdata.pl" at the IP address of 96.44.155.85, 80. I see that is the same IP address as previously posted but a different name.

I tried googling dangerdefenderdata.pl but doesn't bring up anything. I was able to trace the IP address to someplace in California.

Djlawman Jul 21, 2012 9:27 pm

Same experience as Vulcan. There's no virus of any kind on my machine, but they are somehow taking over and redirecting traffic from the FT site. Redirects the entire page away to a pseudo-virus message, wanting you to clean your computer (and no doubt buy their bogus anti-virus product).

duluthDL Jul 21, 2012 11:21 pm

I've been seeing the same problem for several days, only when I visit FT.

Jaimito Cartero Jul 21, 2012 11:35 pm

I don't get it in Safari or Chrome.

Paddlenpedal Jul 22, 2012 7:03 am


Originally Posted by duluthDL (Post 18977717)
I've been seeing the same problem for several days, only when I visit FT.

Me too, only on Flyertalk. Can browse for hours, the minute I come here it sticks on the virus warning. Only on PC, I'm using my iPad now with no problem.

Flyingmama Jul 22, 2012 7:16 am

Just happened again. Whatever the issue is, it hasn't been fixed.

Wilbur Jul 22, 2012 10:30 am


Originally Posted by Flyingmama (Post 18976553)
I got the same message earlier today as well as yesterday. But it didn't come as a small message box - rather it took over the entire FT page. When I x out, the whole browser window closes and I have to re-open the browser.

It certainly is annoying.

I have now had this exact same experience on three separate computers in three separate locations.

XP - IE
Vista - IE
W7 - IE

Each of the computers is clean of virus problems. In each instance, the web page is redirected.

This would appear to be an IBB issue.

xenole Jul 22, 2012 2:14 pm

Same here. Once a day, last time about a minute ago.

tcook052 Jul 22, 2012 2:28 pm


Originally Posted by xenole (Post 18980719)
Same here. Once a day, last time about a minute ago.

Me too and that's now 3 or 4 times on different computers at home & work.

SkiAdcock Jul 22, 2012 2:47 pm

I've encountered it as well.

g-didi Jul 22, 2012 3:55 pm

http://i1053.photobucket.com/albums/...di/FTVirus.jpg

Second time I have got this warning when opening my bookmark to Flyertalk Forums.

(Hopefully the pic posts.... I really have no clue)

SkeptiCallie Jul 22, 2012 4:00 pm

It has happened again, just now. This time the address was changed to (partial listing, to avoid the hyperlink), "http://" followed by the words

utilitywarderdefender.pl \

followed by numbers.

Interesting thing, however, about the numbers in the string. From "/ss/" on--i.e., "/ss/78dee9e271084" (etc.), the numbers are identical as to what they were before.

I.e., what changes now in the address bar are, first, the words, "utilitywarderdefender," and secondly, the numbers following those words, up to the "/ss/--etc," at which point the numbers are the same as in the earlier hyperlink.

SkeptiCallie Jul 22, 2012 4:03 pm

[deleted]

GRALISTAIR Jul 22, 2012 4:09 pm


Originally Posted by Polar Man (Post 18966223)
Twice in the last two days while using FT i have had a pop up appear. It is designed to make it look like MS security essentials notice.

http://i5.photobucket.com/albums/y193/Braybuddy/MS.jpg

Yes I keep getting "Norton has blocked an attack" - seems to have a PL domain - Poland?

HokieEngineer Jul 22, 2012 7:36 pm

So is flyertalk going to do something about this? I'm pretty sure its a rogue banner ad script. They need to alert whoever provides their banner ads that there is a bogus ad causing malware popups. Looks like doubleclick.net to me.

SkeptiCallie Jul 22, 2012 8:16 pm

Would that cause the screen to freeze? I have to turn my laptop off whenever the pop-up appears, as nothing works any longer, can't even exit the screen with Ctrl Alt Del.

TULOKCICT Jul 22, 2012 8:53 pm

I'm getting the same thing on two computers. Both running IE on Win7 and as with others only when I visit FT.

Djlawman Jul 22, 2012 9:49 pm

I'm at least able to run task manager and then close out the IE windows which are causing the problems.

Running Windows 7

ADLFO Jul 22, 2012 10:37 pm

Just happened to me as well.


All times are GMT -6. The time now is 8:06 am.


This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.