PDA

View Full Version : IMPORTANT - Trojan Horse on this forum??


Nicodemus
12-04-2006, 03:25 PM
Hey guys,

I was looking at the Handsome Boy/Glamour Girl thread in the Hot Tub, and while I was on the second-to-last page (currently), my antivirus kept catching a trojan horse. I'd delete it, and it'd pop right back up. I navigated away from the page, and it stopped. I've sent a PM to moog, but you guys may want to avoid that page until we know what's going on with it.

Lewiji
12-04-2006, 03:40 PM
It's likely you have some sort of redundant trojan sitting in your temporary files, and going to that thread reads from that part of the cache, thus the antivirus is scanning it and finding a trojan. Also, if you're using Norton, it tends to randomly spaz anyway.

Nicodemus
12-04-2006, 03:43 PM
I'm not using Norton. It just happened again in Debates in the Chav thread while I was voting in the poll.

Plus, I've told my antivirus to delete it... how do I make sure it's gone, delete my temporary internet files?

sirch
12-04-2006, 03:53 PM
Thats a start. As all the latest windows have System restore which will restore files if thought the right thing to do! To find out how to turn it off Click Here. (http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&src=sec_doc_nam)

Then if you know where the file is located either run anouther virus scan or delete it manually!

Nicodemus
12-04-2006, 04:32 PM
Okay, I found it and had to rename it, move it, quarantine it, THEN delete it. It was recurring because, like a good little virus, it was write-protected. It seems that a picture on this site may have been linked from a site containing the trojan and that's how it got on my system. It was in my temp files, then installed itself into my application data folder. I'm running a scan now, and it's finding more instances of it...

weebl
12-04-2006, 06:04 PM
unlikely

Lewiji
12-04-2006, 06:44 PM
unlikely
Impossible in fact.

Basically, the picture's been cached in a part of your hard drive infected with a trojan.

By viewing the picture therefore, your AV scans that part, finds the virus, you get the pop up.

It could actually be from anywhere at any time :(

Nicodemus
12-04-2006, 07:49 PM
When Timmeh checked it out, that particular page was doing an abnormally high amount of traffic.

Yes, it could be from anywhere, but I still suspect it originated from a site from which a picture on that page was linked.

I dunno. Seems I've got it sorted now, anyway.

Timmeh
12-04-2006, 09:45 PM
Tis not from the forum, I've pulled that page to bits, there was one angelfire picture on there which I had a look at but it's all clean. Funny enough, that page did actually crash my browser once, I found out why in the end, it was a simple overflow, but that was just horrible coincidence, though it did worry me a smidge to start with :p.

Fear not everyone, it's all clean.

MrJoe2006
12-04-2006, 09:59 PM
Hi all :)

On a simmilar subject this forum is very slow on my computer where as most others just load instantly. I have noticed that my firewall costantly reports 'Tribal Fusion Inc' Is this a risk ? can i block this without blocking weebls stuff ? and is there a way I can speed up the connection to this site ? incase its required I have 2MB Broadband / 3.2GHz Processor / 2GB RAM

any advice would be appreciated :) thanks

Timmeh
12-04-2006, 10:01 PM
Tribal fusion is "targeted advertising" spyware. I'd run a spyware scan if I were yoooou.

It's certainly not on this website anyway...

MrJoe2006
12-04-2006, 10:08 PM
Hi there is also this add.fluent.ltd.uk but this is when I am going between pages (see link)
http://img456.imageshack.us/my.php?image=trackingsmallwince8qa.png

Is this from this forum or is it spyware or something logging on ad sites while I am online ?
Does this happen with anyone else ?

Edit: heres a close up
http://img357.imageshack.us/my.php?image=proof8hb.png

Nicodemus
12-04-2006, 10:24 PM
Ah, well, good then. If I do happen to pinpoint where it came from (since now I have no idea), I'll let you guys know.

DarkTrojan
13-04-2006, 12:44 AM
unlikely
hello \o.

The Grim Reaper
13-04-2006, 04:39 AM
Fluent was what was used for the ads(im sure), and its blocking it because its an ad blocker.
Not spyware, just ads.

MrJoe2006
13-04-2006, 03:13 PM
Fluent was what was used for the ads(im sure), and its blocking it because its an ad blocker.
Not spyware, just ads.


Yes it was stating

add.fluent then a.tribalfusion

It is still showing up Tribal Fusion however the pages are loading OK at the moment. Does anyone else see 'a.tribalfusion' on the bottom left hand side of Firefox (when its loading) ?

Lewiji
13-04-2006, 04:03 PM
I often do, I think it's just for some kind of statistical logging.

sirch
13-04-2006, 04:39 PM
I think it is loading the adverts in the top corner! I traced the link and it goes to the Adsmart website. Nothing to worry about :eng101: