FlyerTalk Forums

FlyerTalk Forums (https://www.flyertalk.com/forum/index.php)
-   Technical Support and Feedback (https://www.flyertalk.com/forum/technical-support-feedback-386/)
-   -   Virus on FT? (https://www.flyertalk.com/forum/technical-support-feedback/743635-virus-ft.html)

cfischer Oct 6, 2007 6:35 pm

Virus on FT?
 
I know this sounds strange, but I only had one browser open with FT and my virus scan was going crazy ... took me a couple of minutes to clean the mess. I was in the NW forum and it found Exploit MS06-006 in a file movie[1].qtl

I am right now using the wireless network @ PDX airport, which might be part of the issue, but I thought I better post this ...

Oxb Oct 6, 2007 9:46 pm

yes, I have received a virus warning from FT using two different computers, One with McAfee and the other with NortonAV.

outoftown Oct 6, 2007 11:24 pm

FT opened with Avast! finding a virus. Annoying.

SEA-Flyer Oct 6, 2007 11:37 pm

Just today I've started encounter viruses targetting the MS06-014 vulnerability on Flyertalk. Seems to be coming from the bottom of page adds.

cfischer Oct 7, 2007 5:27 am

happening again to me now in MSP .... someone needs to fix this

empedocles Oct 7, 2007 8:07 am

Sounds like one of the ad purveyors got infected. I've got FF + ......., so I'm not having the issue.

I would bet the latest posts in this thread ate the same issue.

swag Oct 7, 2007 9:06 am

I just got an attack (Sun 10/07 10:00 am CDT). IE7 showed a warning bar that the page was trying to run an add-on Microsoft Outlook, and a popup prompt to install an ActiveX.

Here's what Norton AntiVirus reported.

Details: Attempted Intrusion "HTTP Quicktime RTSP URI BO" against your machine was detected and blocked.
Intruder: 80.93.56.229(http(80)).
Risk Level: High.
Protocol: TCP.
Attacked IP: <my manchine name>.
Attacked Port: 1640.

UALOneKPlus Oct 7, 2007 11:14 am

here's what my Avast reported when I opened Flyertalk with Firefox:

Virus Source: [urld]http://80.93.48.89/weriyuicewrtret/[/urld]
Malware: JS:Agent-Q [Trj]
Type: Trojan Horse
Avast VPS database: 000778-5, 10/06/2007

philemer Oct 7, 2007 12:25 pm

I git infected with "Internet Speed Monitor" yesterday & again today. This is with only FT open. Can somebody get to the root of this?

Also, Randy, can you dump the annoying "you're the xxxx winner" banner ads? Very annoying!

Mary2e Oct 7, 2007 1:12 pm


Originally Posted by philemer (Post 8523424)
I git infected with "Internet Speed Monitor" yesterday & again today. This is with only FT open. Can somebody get to the root of this?

Alter your hosts file to add the following lines and you'll get rid of 99% of the ads...

127.0.0.1 tribalfusion.com
127.0.0.1 a.tribalfusion.com
127.0.0.1 speedera.net
127.0.0.1 tribalfusion.speedera.net
127.0.0.1 pagead2.googlesyndication.com


Also, Randy, can you dump the annoying "you're the xxxx winner" banner ads? Very annoying!
Randy no longer has control of the FT ad... Internet Brands does :td: :td: :td:

mikey1003 Oct 7, 2007 5:20 pm


Originally Posted by UALOneKPlus (Post 8523186)
here's what my Avast reported when I opened Flyertalk with Firefox:

Virus Source: [urld]http://80.93.48.89/weriyuicewrtret/[/urld]
Malware: JS:Agent-Q [Trj]
Type: Trojan Horse
Avast VPS database: 000778-5, 10/06/2007

This is the same one that my AV and Webroot found.......This sucks big time:mad:

The porn pop-ups are bad enough....but a virus is something else.

Please get this crap off FT!!!:td:

cfischer Oct 7, 2007 7:12 pm


Originally Posted by Mary2e (Post 8523643)

Randy no longer has control of the FT ad... Internet Brands does :td: :td: :td:

:rolleyes: I hope he has some say when it gets to virus attacks on FT members :rolleyes:

WIRunner Oct 7, 2007 8:10 pm

I'm getting intrusion attempts too. Getting prompts to allow an active x to run to allow remote control.

jbatl Oct 7, 2007 8:30 pm

Likewise with the add on. Could this have something to do with why the site is running REALLY slow?

Mikel at Webflyer Oct 8, 2007 10:02 am

We just wanted to chime in here and thank you all for the tremendous information you've been providing. We're obviously intently focused at the moment on finding out what is causing this issue and expect to have it resolved as quickly as possible.


All times are GMT -6. The time now is 4:38 am.


This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.