Author |
Topic Search Topic Options
|
Neil
Forum Senior Member
Joined: October 04 2006
Location: United Kingdom
Status: Offline
Points: 1497
|
Topic: Virus on front page Posted: June 07 2007 at 04:29 |
Just picked up this when loading the front page of the forum.
pay[1].mid Exploit-ANIfile.c Trojan
Has PA been hacked?
|
When people get lost in thought it's often because it's unfamiliar territory.
|
|
Easy Livin
Special Collaborator
Honorary Collaborator / Retired Admin
Joined: February 21 2004
Location: Scotland
Status: Offline
Points: 15585
|
Posted: June 07 2007 at 04:32 |
Could be in one of the ads, I'll ask the webmasters to check it out.
|
|
PROGMAN
Forum Senior Member
VIP Member
Joined: February 03 2004
Location: Wales
Status: Offline
Points: 2664
|
Posted: June 07 2007 at 05:07 |
Same problem, seems to be everywhere here, maybe Bob is right, it could be the adverts.
Trojan virus is showing on the anti virus as a list, so there might be more than one virus.
|
CYMRU AM BYTH
|
|
avestin
Special Collaborator
Honorary Collaborator
Joined: September 18 2005
Status: Offline
Points: 12625
|
Posted: June 07 2007 at 10:26 |
I have it as well, it pops up in the main page and in the main forum page as well.
|
|
|
Easy Livin
Special Collaborator
Honorary Collaborator / Retired Admin
Joined: February 21 2004
Location: Scotland
Status: Offline
Points: 15585
|
Posted: June 07 2007 at 11:40 |
More details if possible please.
Which virus checker is it which is reporting the virus? Is there any more information available about exactly where on the page the virus is, a specific ad or programme perhaps?
Thanks
|
|
avestin
Special Collaborator
Honorary Collaborator
Joined: September 18 2005
Status: Offline
Points: 12625
|
Posted: June 07 2007 at 11:52 |
Mine is a McAfee (Enterprise 8.0).
Exploit-ANIfile.c (Trojan) - a file called Pay(2).Mid
That's about all
|
|
|
Neil
Forum Senior Member
Joined: October 04 2006
Location: United Kingdom
Status: Offline
Points: 1497
|
Posted: June 07 2007 at 11:55 |
Mine's McAfee Enterprise 8.
The file it detects is:
\\user\Local Settings\Temporary Internet Files\Content.IE5\BSW01ARR\pay[1].mid
It's a Trojan and is detected as the virus named in my first post.
It tries to launch a pop up in IE as well.
Edited by Heavyfreight - June 07 2007 at 11:56
|
When people get lost in thought it's often because it's unfamiliar territory.
|
|
Easy Livin
Special Collaborator
Honorary Collaborator / Retired Admin
Joined: February 21 2004
Location: Scotland
Status: Offline
Points: 15585
|
Posted: June 07 2007 at 13:26 |
Cheers guys.
|
|
Proletariat
Forum Senior Member
Joined: March 30 2007
Location: United States
Status: Offline
Points: 1882
|
Posted: June 07 2007 at 13:30 |
Yup my anti virus keeps popping up, I ignore it though
|
who hiccuped endlessly trying to giggle but wound up with a sob
|
|
PROGMAN
Forum Senior Member
VIP Member
Joined: February 03 2004
Location: Wales
Status: Offline
Points: 2664
|
Posted: June 07 2007 at 15:09 |
Yes, it was McAfee showing it on the college computer I used this morning using IE6....
....just logged in to PA on my home PC and there are no problems...Avast has not detected any virus, but I have used firefox this time.
|
CYMRU AM BYTH
|
|
Tony R
Special Collaborator
Honorary Collaborator / Retired Admin
Joined: July 16 2004
Location: UK
Status: Offline
Points: 11979
|
Posted: June 07 2007 at 19:54 |
I've picked it up to.
Everyone needs to update then run their antivirus software.
|
|
Dean
Special Collaborator
Retired Admin and Amateur Layabout
Joined: May 13 2007
Location: Europe
Status: Offline
Points: 37575
|
Posted: June 07 2007 at 20:15 |
and set your browsers to block unsigned ActiveX commands (for IE7 users that's Security Tab under Internet Options)
|
What?
|
|
avestin
Special Collaborator
Honorary Collaborator
Joined: September 18 2005
Status: Offline
Points: 12625
|
Posted: June 07 2007 at 20:26 |
Tony and Dean, I've done what you say, however, it still pops up.
|
|
|
Tony R
Special Collaborator
Honorary Collaborator / Retired Admin
Joined: July 16 2004
Location: UK
Status: Offline
Points: 11979
|
Posted: June 07 2007 at 20:28 |
Have you done a virus scan?
This is what turned up on mine:
|
|
The Doctor
Special Collaborator
Honorary Collaborator
Joined: June 23 2005
Location: The Tardis
Status: Offline
Points: 8543
|
Posted: June 07 2007 at 20:30 |
Uh oh. Have I been infected? I wasn't practicing safe PA surfing.
Is it going to start burning everytime I reboot now?
|
I can understand your anger at me, but what did the horse I rode in on ever do to you?
|
|
Tony R
Special Collaborator
Honorary Collaborator / Retired Admin
Joined: July 16 2004
Location: UK
Status: Offline
Points: 11979
|
Posted: June 07 2007 at 20:32 |
Just use your sonic screwdriver....
|
|
Dean
Special Collaborator
Retired Admin and Amateur Layabout
Joined: May 13 2007
Location: Europe
Status: Offline
Points: 37575
|
Posted: June 07 2007 at 20:45 |
The virus is concidered by McAfie to be a low threat.
This is only true if your virus checker catches and removes the virus.
Turning off the unsigned ActiveX installer does nothing to this virus, but it can (can not will) stop the virus downloading another virus.
Edited by darqdean - June 07 2007 at 20:48
|
What?
|
|
avestin
Special Collaborator
Honorary Collaborator
Joined: September 18 2005
Status: Offline
Points: 12625
|
Posted: June 07 2007 at 21:10 |
Well, I keep scanning but nothing shows in the scan. It keeps saying that it finds nothing and yet when I come back here, there's that damn virus appearing.
|
|
|
Dean
Special Collaborator
Retired Admin and Amateur Layabout
Joined: May 13 2007
Location: Europe
Status: Offline
Points: 37575
|
Posted: June 07 2007 at 21:13 |
^ what "pops-up" exactly
|
What?
|
|
avestin
Special Collaborator
Honorary Collaborator
Joined: September 18 2005
Status: Offline
Points: 12625
|
Posted: June 07 2007 at 21:21 |
The McAfee virus scan message telling me it has found a virus - Exploit-ANIfile.c and where it is.
But for some reason the Virus Scan doesn't find it...
|
|
|
Donate monthly and keep PA fast-loading and ad-free forever.