Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.

View this topic in a long page with up to 500 replies per page Create new topic
Prev1 | 2 | 3 | 4 | 5 | 6 | 7 | 8Next
961 posts

Ultimate Geek

Trusted

  Reply # 507887 17-Aug-2011 13:16 Send private message

Ragnor: So it sounds like the ad server got compromised which led to a java (not javascript) applet being served to the browser in the metservice pages, the applet used an exploit the java vm to install personal shield pro on the machine.

Nasty.?

Might pay to update java http://www.java.com/en/download/?


well, javascript injected at metservice, lead browsers to java applet.

anyone know which OSes could be infected with the final virus? How cross platform was the payload?

BDFL
43728 posts

Uber Geek

Administrator
Trusted
Geekzone
Subscriber

  Reply # 507888 17-Aug-2011 13:17 Send private message

The payload is Windows only.

I didn't see anything because I don't have Java installed on my system ;)






wjw

150 posts

Master Geek


  Reply # 507890 17-Aug-2011 13:19 Send private message

From another website I'm on:

http://deletemalware.blogspot.com/2011/07/how-to-remove-personal-shield-pro.html

Two people so far have said this removal process works

447 posts

Ultimate Geek


  Reply # 507906 17-Aug-2011 13:39 Send private message

freitasm: The payload is Windows only.

I didn't see anything because I don't have Java installed on my system ;)




Interesting. We got a new laptop last month and haven't yet installed java on it either - there seems to be less and less reason for a consumer pc to have java installed anymore?  My reason was mainly to not have those annoying java updates every few weeks, but if there's security issues aswell then that's another reason.

I need it on my work computer, but for home use, it seems like we don't. (btw, we don't play minecraft..)

780 posts

Ultimate Geek
Inactive user


  Reply # 507912 17-Aug-2011 13:45 Send private message

I use an adblocker, would this have stopped the metservice virus?

My machine is fully patched and Microsoft security essentials up to date. Does this protect too?

If not, how do I know if my machine has this metservice virus? I've not noticed any strange behaviour yet.


[edit] And metservice should warn people on their main webpage, including a link to removal instructions. 

don@i.am.a.can.do.kiwi.nz
3132 posts

Uber Geek

Subscriber

  Reply # 507928 17-Aug-2011 13:53 Send private message

wreck90: [edit] And metservice should warn people on their main webpage, including a link to removal instructions. 


+1 Did you email them and suggest that?





Promote New Zealand - Get yourself a .kiwi.nz domain name!!!

Check out mine - i.am.a.can.do.kiwi.nz


780 posts

Ultimate Geek
Inactive user


  Reply # 507937 17-Aug-2011 14:09 Send private message

DonGould:
wreck90: [edit] And metservice should warn people on their main webpage, including a link to removal instructions. 


+1 Did you email them and suggest that?



Nope. However,  I'd feel negligent if my website spread a virus and I didn't warn people .  Thats just me though.  

 

BDFL
43728 posts

Uber Geek

Administrator
Trusted
Geekzone
Subscriber

  Reply # 507941 17-Aug-2011 14:14 Send private message

I wonder if we could have here a quick poll with people's replies: "Which OS were you using when your PC got infected?"

Somehow I'm inclined to think this was all on Windows XP/2003...





80 posts

Master Geek


  Reply # 508019 17-Aug-2011 15:57 Send private message

johnr: Give me one good reason why TM / NZherald / Met service would spread a virus?

You emailed them they must be rolling around on the floor laughing


Not laughing now, ay?



19 posts

Geek

Trusted

  Reply # 508020 17-Aug-2011 15:57 Send private message

freitasm: I wonder if we could have here a quick poll with people's replies: "Which OS were you using when your PC got infected?"

Somehow I'm inclined to think this was all on Windows XP/2003...



Windows XP

don@i.am.a.can.do.kiwi.nz
3132 posts

Uber Geek

Subscriber

  Reply # 508031 17-Aug-2011 16:04 Send private message

freitasm: I wonder if we could have here a quick poll with people's replies: "Which OS were you using when your PC got infected?"

Somehow I'm inclined to think this was all on Windows XP/2003...



Can we start with - how do you detect it and how to you fix it?

What do I need to do to confirm that my users don't have it?  So far I've read that AVG and MSE aren't stopping it.

D




Promote New Zealand - Get yourself a .kiwi.nz domain name!!!

Check out mine - i.am.a.can.do.kiwi.nz


803 posts

Ultimate Geek


  Reply # 508036 17-Aug-2011 16:07 Send private message

my sisters laptop was running WinVista Firefox an AVG managed to stop the infection.






11 posts

Geek


  Reply # 508037 17-Aug-2011 16:07 Send private message

Debian Linux 6.0 :)

BDFL
43728 posts

Uber Geek

Administrator
Trusted
Geekzone
Subscriber

  Reply # 508038 17-Aug-2011 16:07 Send private message

If we know what exploit was used, perhaps you can focus your efforts? If you know it's not affecting IE9 on Windows 7 then you know you don't have to spend time on that...





don@i.am.a.can.do.kiwi.nz
3132 posts

Uber Geek

Subscriber

  Reply # 508046 17-Aug-2011 16:12 Send private message





Promote New Zealand - Get yourself a .kiwi.nz domain name!!!

Check out mine - i.am.a.can.do.kiwi.nz


Prev1 | 2 | 3 | 4 | 5 | 6 | 7 | 8Next
View this topic in a long page with up to 500 replies per page Create new topic
Twitter »
Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when new jobs are posted to our jobs board:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:




News »

Trending now »
Hot discussions in our forums right now:

Xbox One
Created by DjShadow, last reply by merve0o0 on 22-May-2013 18:27 (37 replies)
Pages... 2 3


Cannabis is illegal yet we have really strong 'legal highs' ?
Created by qwerty7, last reply by P1n3apqlExpr3ss on 22-May-2013 21:44 (59 replies)
Pages... 2 3 4


Changeover issue: dial up
Created by Zigg, last reply by robjg63 on 21-May-2013 22:02 (17 replies)
Pages... 2


A new project coming to Geekzone
Created by freitasm, last reply by freitasm on 23-May-2013 08:10 (247 replies)
Pages... 15 16 17


HTC One (2013) owners' discussion
Created by Dingbatt, last reply by psychrn on 22-May-2013 23:46 (1532 replies)
Pages... 101 102 103


"igov" online passport renewals
Created by Linuxluver, last reply by profrink on 22-May-2013 22:22 (29 replies)
Pages... 2


Orcon, Is this for real or a scam??
Created by old3eyes, last reply by DarthKermit on 22-May-2013 19:12 (29 replies)
Pages... 2


Vodafone Naked Broadband Speeds (Auckland CBD)
Created by wscalioni, last reply by grkiwi on 20-May-2013 21:13 (14 replies)


Geekzone Jobs »
Most recent NZ jobs in technology:

Intermediate Project Manager
Posted 22-May-2013 22:27

Project Manager - Data Centre
Posted 22-May-2013 22:27

Senior Embedded Software Engineer
Posted 22-May-2013 22:27

Senior Business Analyst
Posted 22-May-2013 22:27

Systems Support Administrator
Posted 22-May-2013 19:27

Senior Technical Business Analyst
Posted 22-May-2013 19:27

Network Reporting Engineer
Posted 22-May-2013 19:27


Geekzone Live »
Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.

Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.