Buy Sell Discuss UK Domain Names at AcornDomains.co.uk Free Virtual Servers

Today's Drop Dates are: 19-02-2012 or 26-02-2012   All times are GMT. The time now is 04:56:33 AM.
Domain Name Sales Domain Software Calculate UK Domain Drop Dates Domain Registration NameDrive Domain Parking Subscribe to our Domains For Sale newsletter
Go Back   Domain Forum Acorn Domains Buy Sell Auction UK Domains > General and Domain News > Forum News & Feedback
Connect with Facebook

Forum News & Feedback Updates and news for the forum will be post here. Let us know of any issues you have using the site.

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 23-02-2010, 12:01:57 PM     #1 (permalink)

 
retired_member12's Avatar
 
Join Date: Aug 2006
Posts: 1,510
retired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond repute

Something amiss, or is Kaspersky being too keen?

Almost every page load at Acorn has started flagging this message up in Kaspersky over the past 30 mins or so:

Quote:
Loading object http://mmfav.servehttp.com//ml.php//ml, containing virus HEUR:Trojan.Script.Iframer. detected.
Anyone know what the problem might be? It's only happening at Acorn.
retired_member12 is offline  
Old 23-02-2010, 12:22:50 PM     #2 (permalink)
rob
Founding Member
 
rob's Avatar
 
Join Date: Jan 2005
Posts: 5,977
rob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond reputerob has a reputation beyond repute

could be a ropey ad or some code injection somewhere along the line

Heur Trojan.script.iframe is a prolific Trojan Horse with several variants. Its primary function is to serve as a downloader. Once inside your PC, it contacts a unknown list of websites without the user knowing. From there it downloads a number of other programs, most of which are Spyware agents, viruses, and keyloggers (programs that record your keystrokes and save the information to a remote server). These viruses are responsible for annoying pop-up advertisements on the desktop and interfering with [Internet Explorer|IE|the internet browser}.

sounds nice
rob is offline  
Old 23-02-2010, 12:27:29 PM     #3 (permalink)

 
retired_member12's Avatar
 
Join Date: Aug 2006
Posts: 1,510
retired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond reputeretired_member12 has a reputation beyond repute

Quote:
Originally Posted by rob View Post
could be a ropey ad or some code injection somewhere along the line

Heur Trojan.script.iframe is a prolific Trojan Horse with several variants. Its primary function is to serve as a downloader. Once inside your PC, it contacts a unknown list of websites without the user knowing. From there it downloads a number of other programs, most of which are Spyware agents, viruses, and keyloggers (programs that record your keystrokes and save the information to a remote server). These viruses are responsible for annoying pop-up advertisements on the desktop and interfering with [Internet Explorer|IE|the internet browser}.

sounds nice
It's only happening at Acorn though.
retired_member12 is offline  
Old 23-02-2010, 01:28:10 PM     #4 (permalink)

 
Join Date: Feb 2005
Posts: 273
mofo has a reputation beyond reputemofo has a reputation beyond reputemofo has a reputation beyond reputemofo has a reputation beyond reputemofo has a reputation beyond reputemofo has a reputation beyond reputemofo has a reputation beyond reputemofo has a reputation beyond reputemofo has a reputation beyond reputemofo has a reputation beyond reputemofo has a reputation beyond repute

Same here .. just started.
mofo is offline  
Old 23-02-2010, 01:46:46 PM     #5 (permalink)

 
Systreg's Avatar
 
Join Date: Oct 2008
Location: County Cork Republic of Ireland
Posts: 4,181
Systreg has a reputation beyond reputeSystreg has a reputation beyond reputeSystreg has a reputation beyond reputeSystreg has a reputation beyond reputeSystreg has a reputation beyond reputeSystreg has a reputation beyond reputeSystreg has a reputation beyond reputeSystreg has a reputation beyond reputeSystreg has a reputation beyond reputeSystreg has a reputation beyond reputeSystreg has a reputation beyond repute

Domain Trader Rating:
(100% / 106)
The other topic about this is on Acorn here:

http://www.acorndomains.co.uk/forum-...mpromised.html

Other vBulletin sites are reporting the same issue.
Systreg is offline  
Old 23-02-2010, 01:50:31 PM     #6 (permalink)

 
SecNam's Avatar
 
Join Date: Jul 2004
Posts: 4,206
SecNam has a reputation beyond reputeSecNam has a reputation beyond reputeSecNam has a reputation beyond reputeSecNam has a reputation beyond reputeSecNam has a reputation beyond reputeSecNam has a reputation beyond reputeSecNam has a reputation beyond reputeSecNam has a reputation beyond reputeSecNam has a reputation beyond reputeSecNam has a reputation beyond reputeSecNam has a reputation beyond repute
Classified Rating: 100% (1)

ive sent admin a text so hopefully he will be along soon to look.
SecNam is offline  
Old 23-02-2010, 01:52:35 PM     #7 (permalink)

 
Edwin's Avatar
 
Join Date: Apr 2005
Location: Cambridge, UK
Posts: 4,165
Edwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond reputeEdwin has a reputation beyond repute

A large vBulletin site I run, which uses an up to date version of the software, doesn't seem to have any problems, so it's not a "global" problem. Similarly, there are no issues on *******.com or DomainState.com, both vBulletin sites.
__________________
Memorable Domains Ltd - Over 7,000 descriptive, generic .co.uk domains for sale
Please note: All sale prices over a week old are automatically invalid. No exceptions. Thanks!
Edwin is offline  
Old 23-02-2010, 01:53:59 PM     #8 (permalink)

 
Join Date: Mar 2006
Posts: 643
TinkyWinky has a reputation beyond reputeTinkyWinky has a reputation beyond reputeTinkyWinky has a reputation beyond reputeTinkyWinky has a reputation beyond reputeTinkyWinky has a reputation beyond reputeTinkyWinky has a reputation beyond reputeTinkyWinky has a reputation beyond reputeTinkyWinky has a reputation beyond reputeTinkyWinky has a reputation beyond reputeTinkyWinky has a reputation beyond reputeTinkyWinky has a reputation beyond repute

it is either an iframe reference that's been bot-placed within the .js file or a document.write on template that references a certain .ru site

Likely engineered from a VB exploit or open PORT

Apparently....

__________________
- - - - - - - - - - - - - - - - - - - - - - - - - - -
Lifestyle Magazine - Gym Equipment
TinkyWinky is offline  
Closed Thread



Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Domain Name Community Replies Last Post
Russians Not Keen on IDN Top Level Domain - Domain Name Wire (blog) RSS Domain Name News 0 22-12-2009 05:59:01 PM
Kaspersky impressed with Conficker botnet's slickness - ZDNet RSS Domain Name News 0 21-05-2009 02:59:16 PM
Kaspersky impressed by botnet slickness - ZDNet.com.au RSS Domain Name News 0 21-05-2009 05:00:30 AM
Kaspersky, OpenDNS Collaborate to Slow Conficker Worm - PC World RSS Domain Name News 0 09-02-2009 11:59:04 AM
Foreign firms keen for Chinese domains - Xinhua RSS Domain Name News 0 22-04-2006 02:02:39 AM

Domain Sponsor 2


All times are GMT. The time now is 04:56:33 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.6.0 RC 2
All content on Acorn Domains is member generated and is not moderated before posting. All content is viewed and used by you at your own risk and AD does not warrant the accuracy or reliability of any of the information. The views expressed are those of the individual contributors and not necessarily those of AD. Please contact us to report any issues or send a PM to "Admin".