Forex



Go Back   Forex Trading > Non Related Discussions
Forex Forum Register More recent Blogs Calendar Advertising Others Help






Register
Welcome to Forex-TSD!, one of the largest Forex forums worldwide, where you will be able to find the most complete and reliable Forex information imaginable.

From the list below, select the forum that you want to visit and register to post, as many times you want. It’s absolutely free. Click here for registering on Forex-TSD.

Exclusive Forum
The Exclusive Forum is the only paid section. Once you subscribe, you will get free access to real cutting-edge Trading Systems (automated and not), Indicators, Signals, Articles, etc., that will help and guide you, in ways that you could only imagine, with your Forex trading.
  • Elite Section
    Get access to private discussions, specialized support, indicators and trading systems reported every week.
  • Advanced Elite Section
    For professional traders, trading system developers and any other member who may need to use and/or convert, the most cutting-edge exclusive indicators and trading systems for MT4 and MT5.
See more

Reply
 
Thread Tools Display Modes
  #1 (permalink)  
Old 04-16-2007, 10:37 AM
mart-hart's Avatar
Senior Member
 
Join Date: Oct 2005
Posts: 452
mart-hart is on a distinguished road
Virus on forexfactory website

I just logged onto ForexFacory forum and got a load of Virus alerts.

I thought they had sorted the problem.

That was at 10.30 uk time.

Just tried again got a Trojan-Downloader-VBS-Agent-U

Mart
__________________
----o00o--°(_)°--o00o----

Last edited by mart-hart; 04-16-2007 at 10:59 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!StumbleUpon this Post!Reddit this Post!Facebook this Post!BlinkList this Post!Google Bookmarks this Post!Yahoo! My Web this Post!
Reply With Quote
  #2 (permalink)  
Old 04-16-2007, 11:22 AM
Administrator
 
Join Date: Sep 2005
Posts: 20,079
Blog Entries: 241
newdigital has much to be proud ofnewdigital has much to be proud ofnewdigital has much to be proud ofnewdigital has much to be proud ofnewdigital has much to be proud ofnewdigital has much to be proud ofnewdigital has much to be proud ofnewdigital has much to be proud of
Quote:
Originally Posted by mart-hart
I just logged onto ForexFacory forum and got a load of Virus alerts.

I thought they had sorted the problem.

That was at 10.30 uk time.

Just tried again got a Trojan-Downloader-VBS-Agent-U

Mart
yes, the same with me.
3 viruses.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!StumbleUpon this Post!Reddit this Post!Facebook this Post!BlinkList this Post!Google Bookmarks this Post!Yahoo! My Web this Post!
Reply With Quote
  #3 (permalink)  
Old 04-16-2007, 11:36 AM
fxtrader625's Avatar
Senior Member
 
Join Date: Nov 2006
Posts: 134
fxtrader625 is on a distinguished road
I got a virus alert with Trend Micro Office Scan and a link to this:

http://www.trendmicro.com/vinfo/viru...PL_ANICMOO.GEN
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!StumbleUpon this Post!Reddit this Post!Facebook this Post!BlinkList this Post!Google Bookmarks this Post!Yahoo! My Web this Post!
Reply With Quote
  #4 (permalink)  
Old 04-16-2007, 11:50 AM
MiniMe's Avatar
Senior Member
 
Join Date: Nov 2006
Location: Montréal
Posts: 1,451
MiniMe is an unknown quantity at this point
delete the internet temp files
__________________

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!StumbleUpon this Post!Reddit this Post!Facebook this Post!BlinkList this Post!Google Bookmarks this Post!Yahoo! My Web this Post!
Reply With Quote
  #5 (permalink)  
Old 04-16-2007, 07:40 PM
mart-hart's Avatar
Senior Member
 
Join Date: Oct 2005
Posts: 452
mart-hart is on a distinguished road
> UPDATE: Based on the reports we have been receiving,
> AGV antivirus software
> did not block the Trojan Horse. If you are using
> AGV, we highly recommend
> installing an alternate antivirus software.
>
> UPDATE: We have determined that the Trojan Horse
> virus is called
> "Exploit.ANI" , which is a recent virus discovered in
> late March.
>
> UPDATE: On Monday, around 7:00am ET, the attackers
> regained entry into one
> of our servers. Although our team was there to
> immediately defend against
> this, a virus went live for a short period. We are
> working extremely hard to
> defend against another attack. We will update this
> announcement with our
> progress.
>

Mart
__________________
----o00o--°(_)°--o00o----
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!StumbleUpon this Post!Reddit this Post!Facebook this Post!BlinkList this Post!Google Bookmarks this Post!Yahoo! My Web this Post!
Reply With Quote
  #6 (permalink)  
Old 04-16-2007, 08:01 PM
MiniMe's Avatar
Senior Member
 
Join Date: Nov 2006
Location: Montréal
Posts: 1,451
MiniMe is an unknown quantity at this point
I just switched off my news idicators, it crash the MT4 whenever forexfactory site has a porblem
__________________

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!StumbleUpon this Post!Reddit this Post!Facebook this Post!BlinkList this Post!Google Bookmarks this Post!Yahoo! My Web this Post!
Reply With Quote
  #7 (permalink)  
Old 04-17-2007, 10:03 AM
mart-hart's Avatar
Senior Member
 
Join Date: Oct 2005
Posts: 452
mart-hart is on a distinguished road
They are back,

Got 6 alerts at 10 am (UK) Tue.

Mart
__________________
----o00o--°(_)°--o00o----
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!StumbleUpon this Post!Reddit this Post!Facebook this Post!BlinkList this Post!Google Bookmarks this Post!Yahoo! My Web this Post!
Reply With Quote
  #8 (permalink)  
Old 04-17-2007, 12:31 PM
goldenequity's Avatar
Member
 
Join Date: Feb 2006
Location: Arizona, USA
Posts: 40
goldenequity is on a distinguished road
Anybody else getting a "Virus Detected!" on ForexFactory site?

Yesterday, I tried to log in, and got a "password req." site-generated popup all day...so I assumed site was down for maintenance or whatever.

Today, I logged in to the FF Calendar, and immediately got a "threat detected!!" pop-up from MY AVG 7.5 virus program identifying EXPLOIT.ani was imbedded in about 8-10 .html files , which I manually moved to the virus vault and closed the site!!

Tried this twice with the same result.

Anybody else aware of this?
__________________

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!StumbleUpon this Post!Reddit this Post!Facebook this Post!BlinkList this Post!Google Bookmarks this Post!Yahoo! My Web this Post!
Reply With Quote
  #9 (permalink)  
Old 04-17-2007, 12:46 PM
Member
 
Join Date: Dec 2006
Posts: 77
marcf is on a distinguished road
Yeah...there is some type of virus over there. I think they are trying to clean it all up, but don't think they got everything.

Quote:
Originally Posted by goldenequity
Yesterday, I tried to log in, and got a "password req." site-generated popup all day...so I assumed site was down for maintenance or whatever.

Today, I logged in to the FF Calendar, and immediately got a "threat detected!!" pop-up from MY AVG 7.5 virus program identifying EXPLOIT.ani was imbedded in about 8-10 .html files , which I manually moved to the virus vault and closed the site!!

Tried this twice with the same result.

Anybody else aware of this?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!StumbleUpon this Post!Reddit this Post!Facebook this Post!BlinkList this Post!Google Bookmarks this Post!Yahoo! My Web this Post!
Reply With Quote
  #10 (permalink)  
Old 04-17-2007, 12:49 PM
goldenequity's Avatar
Member
 
Join Date: Feb 2006
Location: Arizona, USA
Posts: 40
goldenequity is on a distinguished road
Exploit.ani

This is what I'm finding regarding exploit.ani explanation:

Dated April 10, 2007

San Francisco (IDGNS) - More than 2,000 unique Web sites have been rigged to exploit the animated cursor security flaw in Microsoft's software, according to security vendor Websense Inc.

Those Web sites are either hosting exploit code or are redirecting Internet users to sites with bad code, Websense's blog reported Monday.

The number of Web sites engineered to exploit the problem has jumped considerably since the vulnerability was publicly disclosed by Microsoft on March 29. It will likely continue to rise until patches are applied across corporate and consumer PCs, said Ross Paul, senior product manager for Websense.

Hackers are hoping to catch some of the millions of unpatched machines.

"What we've seen is that exploits tend to be used as long as they are effective," Paul said.

Last week, Microsoft broke from its regular patching routine and issued an off-schedule fix due to the danger of the vulnerability, which occurs in the way Windows processes .ani or Animated Cursor files, which allow Web sites to replace the regular cursor with cartoonish alternatives.

The flaw affects nearly all versions of Microsoft's Windows OS and is the third zero-day flaw that Microsoft has patched out of schedule since January 2006.

Companies tend to patch their machines on fixed schedules and may not immediately apply a patch when it's released, Paul said. Home users may automatically receive the patch if they are using Windows XP Service Pack 2, but users of older Windows OSes will not.

That's especially dangerous since the .ani problem doesn't require user interaction for a machine to be infected, said Graham Cluley, senior technology consultant at Sophos PLC. Merely viewing a Web site engineered to exploit the vulnerability with an unpatched machine can result in an infection.

As a result, security analysts are generally recommending to apply the patch, even though Microsoft said Friday they were fixing compatibility problems with some applications.

"We are recommending this is a patch you really need to install now," Cluley said.

Websense said that attackers from Eastern Europe and China appear to be at the heart of the efforts. Groups in the Asia-Pacific region and China are exploiting the vulnerability, mainly on machines located in Asia, in order to gain credentials for popular online games such as Lineage, Websense said.

A second group in Eastern Europe, which has been known to use other vulnernabilities in Microsoft's software to install malicious software on machines, "have also added the .ani attacks to their arsenal," Websense said. Those attacks are directed at servers and users in the U.S.

The motivation of the Eastern European group appears to be collecting banking details using form-grabbing software or keyloggers, Websense said. The group has also been known to try to use exploits to install bogus anti-spyware programs.

One technique used by the hackers is to find a vulnerable Web server and cause its viewers to be redirected to another Web site that will exploit their machine using the .ani problem, Paul said.

The hackers are also planting iframes -- hidden windows that can allow code such as JavaScript to run -- to activate an exploit. Paul predicts there may be more to come: "I don't think we've seen the last of this."
__________________

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!StumbleUpon this Post!Reddit this Post!Facebook this Post!BlinkList this Post!Google Bookmarks this Post!Yahoo! My Web this Post!
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Virus ?? image3022 Metatrader 4 14 04-05-2009 03:14 PM
Another website selling EA babarmughal Expert Advisors - Metatrader 4 51 12-02-2007 04:36 PM
Forexfactory and News indicator MiniMe General Discussion 8 05-22-2007 01:42 PM
Virus? nito2721 Metatrader 4 2 01-13-2007 03:18 AM


All times are GMT. The time now is 05:08 AM.



Search Engine Friendly URLs by vBSEO 3.2.0 ©2008, Crawlability, Inc.