Go Back  FlyerTalk Forums > Support&Services > Technical Support and Feedback
Reload this Page >

Malware ad on FT are very bad form

Community
Wiki Posts
Search

Malware ad on FT are very bad form

Thread Tools
 
Search this Thread
 
Old Oct 13, 2007 | 8:14 am
  #1  
Original Poster
 
Join Date: Sep 2004
Location: MSP (and will only fly NWA in re-routes if I HAVE to)
Programs: AA EXP (4.5MM), hotel programs as needed
Posts: 5,800
Malware ad on FT are very bad form

I have been in FT for about an hour this morning.

TWICE I have returned from a thread .. and at least once (I do not recall the first time) gotten a brand new page (not FT) from a company called Malware.

It ran a scan and told me my PC was infected.

It definately was the same window as my FT session had been in since FT was now gone.

Came up with errors (and wanting me to give it ActiveX authority).

The first program came back with several message boxes asking me to load their software to protect my computer. It was VERY HARD to get this thing to stop.

PLEASE PLEASE resolve this.

If the site has been hijacked by ads .. you have issues with your ad provider.

If the site has been hijacked by others .. you have a more serious problem....
JGR01 is offline  
Old Oct 13, 2007 | 8:34 am
  #2  
FlyerTalk Evangelist, Ambassador: World of Hyatt
All eyes on you!
20 Years on Site
 
Join Date: Jul 2001
Location: New Jersey
Programs: Hyatt Globalist, Fairmont Lifetime Plat, UA Silver, dirt elsewhere
Posts: 47,405
I got the same this morning.

Seems these infected ads show up on the weekends.

Really Really bad form.
Mary2e is offline  
Old Oct 13, 2007 | 10:51 am
  #3  
FlyerTalk Evangelist
All eyes on you!
20 Years on Site
 
Join Date: Mar 2002
Location: An NPR mind living in a Fox News world
Posts: 14,343
Exclamation

Same thing happened to me this morning. I

've been nailed with these Trojans twice in the last couple of years and they are a pain to clean up. ON both occasions, it took me the better part of a half day to do a Google search on the Trojan name and find a website that has removal instructions. You have to boot up in Safe Mode and run a registry cleaner that you download from the website. I'm not an IT person so I was winging it all the way.

I got the window wanting me to click on it. These types of Trojans will try to download even if you hit "cancel" or close the window with the upper right "x".

The best thing to do is to hit ctrl-alt-del to bring up Task Manager. Go to the applications tab and you'll see Flyer Talk identified as a running program. Highlight it and click "End Program". Then, shut down and do a reboot. Run your anti-spyware application (your real one!) and your anti-virus program. Then, take a deep breath and say, "WHEW!"

Please download Firefox and use it as your default browser. It's much more secure than IE. If you don't have an anti-spyware program, there are several good ones out there. Windows Defender is free from the Microsoft website and is also very good.

Today's Trojan got blocked by my Firefox because FF doesn't allow ActiveX unless you specifically allow it in.

WHEW!
FliesWay2Much is offline  
Old Oct 14, 2007 | 1:31 am
  #4  
 
Join Date: Mar 2003
Posts: 4,800
Really sad

So my subscription expired yesterday so I'm looking at ads. I don't mind the subscription, just hadn't gotten around to resubscribing yet.

So all the sudden a pop up dialog box pushes my browser off screen and suggests I let them run a malware scan... when I close the pop up it redirects me to their site and maximizes the browser.

Does Flyertalk condone this?

I know this can be expected at many sites, porn sites, sports sites, porn sites, etc... but Flyertalk? Really? Sad.
BuddyBird is offline  
Old Oct 14, 2007 | 6:37 am
  #5  
FlyerTalk Evangelist, Ambassador: World of Hyatt
All eyes on you!
20 Years on Site
 
Join Date: Jul 2001
Location: New Jersey
Programs: Hyatt Globalist, Fairmont Lifetime Plat, UA Silver, dirt elsewhere
Posts: 47,405
I just looked at my logs because this morning I kept on getting messages that IE wanted to accept a connection from the internet...

Here is the information:

blocked an incoming data packet that was addressed to port 1082 on another computer. The packet was either mistakenly or intentionally routed through your computer. The data packet was sent from port 80 on a computer whose IP address is 67.201.16.68.
The source DNS for this is listed as flyertalk.com.
Mary2e is offline  
Old Oct 14, 2007 | 8:51 am
  #6  
15 Years on Site
 
Join Date: Oct 2005
Location: Washington, DC
Posts: 338
I got the same ad, although it only popped up after I logged into Flyertalk. I didn't get any warning, but perhaps my software missed it. Can those types of trojans affect Macs?

FliesWay2Much, how do you do know the name of the Trojan you're searching for in this case? The supposed name of the company "Malware", brought up articles about malware.
Socaflyer is offline  
Old Oct 14, 2007 | 11:48 am
  #7  
FlyerTalk Evangelist
All eyes on you!
20 Years on Site
 
Join Date: Mar 2002
Location: An NPR mind living in a Fox News world
Posts: 14,343
Originally Posted by Socaflyer
I got the same ad, although it only popped up after I logged into Flyertalk. I didn't get any warning, but perhaps my software missed it. Can those types of trojans affect Macs?

FliesWay2Much, how do you do know the name of the Trojan you're searching for in this case? The supposed name of the company "Malware", brought up articles about malware.
I think the name of the Trojan was longer. I think it was something like "Malware-Scam" or "Malware-Scrub" or something like that. The Trojan I got hit with a couple of weeks ago was called "AntiVirGear" and loaded itself the same way that the FT Trojan tried to load. (I was using IE instead of Firefox because my work on-line calendar won't work on Firefox.) I did a search on the Trojan name and eventually wound up on http://www.bleeping computer.com. I wound up in the Forums section and someone had published detailed instruction about how to remove this Trojan.

I'd recommend downloading "bleeping computer" and setting up a free account. They have lots of free downloads and tutorials.
FliesWay2Much is offline  
Old Oct 14, 2007 | 5:50 pm
  #8  
ed1
 
Join Date: Jul 2002
Location: TPA, PHL
Programs: NW: SE & WC
Posts: 2,136
Originally Posted by FliesWay2Much
I think the name of the Trojan was longer. I think it was something like "Malware-Scam" or "Malware-Scrub" or something like that. The Trojan I got hit with a couple of weeks ago was called "AntiVirGear" and loaded itself the same way that the FT Trojan tried to load. (I was using IE instead of Firefox because my work on-line calendar won't work on Firefox.) I did a search on the Trojan name and eventually wound up on http://www.bleeping computer.com. I wound up in the Forums section and someone had published detailed instruction about how to remove this Trojan.

I'd recommend downloading "bleeping computer" and setting up a free account. They have lots of free downloads and tutorials.
Have you tried the IE rendering engine for Firefox for your online calendar? Everything I've tried so far that doesn't work in Ff has been okay when I just open it in an IE tab in Ff.

It's the IE tab add-on/extension for Firefox.
ed1 is offline  
Old Oct 14, 2007 | 10:07 pm
  #9  
abk
10 Countries Visited
20 Countries Visited
30 Countries Visited
15 Years on Site
 
Join Date: Sep 2007
Location: stl
Programs: AA LT Ex Plat/8.1mm. WN companion pass. SPG LT Titanium.
Posts: 3,181
i use firefox and i am getting the same issue. if i close and reopen then i am fine but one i get the pop up i am finished on that session.
abk is offline  
Old Oct 15, 2007 | 1:34 am
  #10  
ed1
 
Join Date: Jul 2002
Location: TPA, PHL
Programs: NW: SE & WC
Posts: 2,136
Originally Posted by abk
i use firefox and i am getting the same issue. if i close and reopen then i am fine but one i get the pop up i am finished on that session.
Are they flash ads? If so I use FlashBlock extension for Firefox. If not, I don't know why I'm not seeing them at all, unless my WindowsLiveOneCare or Vista is blocking them out.
ed1 is offline  
Old Oct 15, 2007 | 5:19 am
  #11  
20 Years on Site
 
Join Date: Apr 2005
Location: Mid-Atlantic
Programs: AA Plat, UA Silver, DL Silver, Marriott Titanium, etc.
Posts: 4,214
This is Really Bad Form!!

It's there, and its from flyertalk.com .

I do not know if this program will do any damage to the overall functionality of one's computer, but it is already doing damage by its deceptive and hyper-aggressive nature and the wasting one's time dealing with it (and its aborting of Flyertalk browsing sessions).

It is loaded only during Flyertalk browsing sessions.

It will minimize your Flyertalk session and force you to deal with it.

You cannot get rid of it except through Task Manager - DO NOT click on the "x" in the popup window!

You can find it and end it through Windows Task Manager:

Commonly as scanner.malware-sc***
(I don't want to give the complete url, in order to encourage you NOT to go to their website.); however, other urls may appear as well.

It is identified as a Trojan Horse by at least one of my anti-virus programs, still investigating this.

Be very careful doing a Google search for information on the program, you may get attacked again.

SHAME, SHAME on you Flyertalk!
GrizShel is offline  
Old Oct 15, 2007 | 6:08 pm
  #12  
FlyerTalk Evangelist
30 Countries Visited
2M
100 Nights
20 Years on Site
 
Join Date: Jul 2003
Location: BOS, PVG
Programs: United Global Services and 1MM, Marriott Titanium, Hyatt Globalist
Posts: 10,299
My laptop has been infected by trojans supplied by FT.

Apparently during the last 10 days or so, when I was reading FT, various pop-ups started to show up, such as Malware-Scan and TripMania.

As the result, I was forced to shut down IE and made firefox default.

Even so, pop ups still show up from time to time with firefox when am on FT.

Everyone should know that when you visit an internet site, there is always a risk with Trojans and viruses. But I would never expect that it would happen on FT because we trust FT so much.

Now the confidence has been greatly shaken. A big to FT.
kb1992 is offline  
Old Oct 15, 2007 | 6:17 pm
  #13  
FlyerTalk Evangelist
30 Countries Visited
2M
100 Nights
20 Years on Site
 
Join Date: Jul 2003
Location: BOS, PVG
Programs: United Global Services and 1MM, Marriott Titanium, Hyatt Globalist
Posts: 10,299
In addition, it seems that FT downloaded a program called "BestsellerAntivirus" to my laptop, and I could not get rid of it.

Even after I did "regedit" to delete it from my register key, it still shows up after the computer is restarted.

The location is

HKEY_LOCAL_MACHINE/SOFTWARE/BestsellerAntivirus
kb1992 is offline  
Old Oct 15, 2007 | 7:16 pm
  #14  
In Memoriam, FlyerTalk Evangelist
 
Join Date: Jun 2000
Location: Benicia CA
Programs: Alaska MVP Gold 75K, AA 3.8MM, UA 1.1MM, enjoying the retired life
Posts: 31,849
I'm surprised no one from FT management has been along to comment about these reports.
tom911 is offline  
Old Oct 15, 2007 | 10:44 pm
  #15  
brp
FlyerTalk Evangelist
All eyes on you!
20 Years on Site
 
Join Date: Mar 2004
Location: SJC
Programs: AA EXP, BA Silver, Hyatt Globalist, Hilton diamond, Marriott Platinum
Posts: 34,038
Originally Posted by tom911
I'm surprised no one from FT management has been along to comment about these reports.
I'm not.

Cheers.
brp is offline  


Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.