Announcement

Collapse
No announcement yet.

Virus on EQ Traders?

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Virus on EQ Traders?

    Malicious code found in file D:\TEMPORARY INTERNET FILES\CONTENT.IE5\KPQBA5EV\INDEX[2].HTM.
    Infection: Trojan-Clicker.JS.Agent.d

    I'm getting the above virus alert whenever I access pages on this board. As far as I can make out, I dont get the message from any other site than this one (I've checked about 10 other sites I regularly access) and I get it consistantly when I open a thread. I don't wish to insult the reputation of this site, esp if my alert is misleading me, and its actually something entirely unrelated to the site, but any chance you could check there isnt a problem?
    Ysall - EMarr - lvl 70 Ench
    2400+54 Club (7 x Core Tradeskills + Research)
    Max Tradeskills AA + Max Salvage - When I combine something, it stays combined, except when it doesn't.

  • #2
    I wonder if it's something embedded in someone's avatar or sig?
    Master Artisan Maevenniia the Springy Sprocket Stockpiler of the really long name
    Silky Moderator Lady
    Beneath the silk, lies a will of steel.

    Comment


    • #3
      I'm inclined to agree with Maev. Is it every single page on the board, including those that don't have individual posts? (Do you get it when looking at your Profile Settings, the list of forums, etc, or only when looking at actual posts?) Is it every page with posts or can you identify any particular poster it always happens with? (Which of course wouldn't mean that poster was doing it intentionally or even knowingly.)
      Retiree of EQ Traders...
      Venerable Heyokah Verdandi Snowblood
      Barbarian Prophet & Hierophant of Cabilis
      Journeyman Artisan & Blessed of Brell
      EQ Players Profile ~ Magelo Profile


      Smith Dandi wipes her sooty hands on her apron and smiles at you.

      Comment


      • #4
        it is also "possible" it is a false positive.

        one thing to try is to delete all files in that temporary folder and see if you still get it afterwords.

        I have two different anti virus and I am not seeing it. (two different computers)
        Ngreth Thergn

        Ngreth nice Ogre. Ngreth not eat you. Well.... Ngreth not eat you if you still wiggle!
        Grandmaster Smith 250
        Master Tailor 200
        Ogres not dumb - we not lose entire city to froggies

        Comment


        • #5
          On my home PC that uses Norton Antivirus I don't see it either. Very strange.
          Ysall - EMarr - lvl 70 Ench
          2400+54 Club (7 x Core Tradeskills + Research)
          Max Tradeskills AA + Max Salvage - When I combine something, it stays combined, except when it doesn't.

          Comment


          • #6
            It's also possible you've gotten something else which is either cross-linked or has infected multiple files.

            Your best bet... destroy/quarentine the infected file(s), clear your browser cache, cookies and scan for spyware.
            Lothay retired from EQ in 2003
            EQ Traders - Moderator - MySpace or LiveJournal

            Comment


            • #7
              The "content.ie5 folder" is also a hidden subfolder. Even with folder settings set to not hide anything, it remains hidden, and you generally need to delete anything there manually. Antivirus/spyware software that I've seen detect an issue there usually will do nothing to help remove it.
              Master Artisan Hidron
              Veritable Quandary
              Drinal

              Comment


            • #8
              Could be within the ads?

              2 of my guildies had mjor computer trouble because of virus or trojan horses sneaking in through the ads (pop up usually)

              I use Mozilla with Ad-block extension installed to kill all ads (including flash ads) and Mozila (and Firefox) also blocks pop up as well.

              Viruses tended to get worse in January and Feburary as many people would have gotten new computer the past Christmas but no antivirus program installed. Also dump IE it's riddled with security holes.

              Comment


              • #9
                ad.3ad has a new tool that is trying to use other programs to access its site over and over on my system.
                None of the 5 maleware, spyware, 2 online AV tools nor my AV on my system can find it.
                I used Rootkit Revealer and nothing yet either.
                So somehow Ad.3ad (Fastclick) keeps trying to hijack my programs to contact servers I've blocked. Servedby.advertising.com is another that's suddenly doing this in the last 3 months. (also see cdn.fastclick.com using other programs to access internet other than normal IE method.

                This one has me perplexed. Unless these companies are paying everyone to ignore their cookies and proggies, I can't see what's doing it.
                Yes I am He!
                EQ's Very own Beer God!
                The Vicar of Liquor! Baron in a Barrel!
                The Priest of Yeast! Wielder of Brell's BattleMug

                sigpic

                Comment

                • Working...
                  X