Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8
taniwha
961 posts

Ultimate Geek

Trusted

  #507887 17-Aug-2011 13:16
Send private message

Ragnor: So it sounds like the ad server got compromised which led to a java (not javascript) applet being served to the browser in the metservice pages, the applet used an exploit the java vm to install personal shield pro on the machine.

Nasty.?

Might pay to update java http://www.java.com/en/download/?


well, javascript injected at metservice, lead browsers to java applet.

anyone know which OSes could be infected with the final virus? How cross platform was the payload?



freitasm
BDFL - Memuneh
79250 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #507888 17-Aug-2011 13:17
Send private message

The payload is Windows only.

I didn't see anything because I don't have Java installed on my system ;)






Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


wjw

wjw
162 posts

Master Geek


  #507890 17-Aug-2011 13:19
Send private message

From another website I'm on:

http://deletemalware.blogspot.com/2011/07/how-to-remove-personal-shield-pro.html

Two people so far have said this removal process works



jonb
1771 posts

Uber Geek

Trusted

  #507906 17-Aug-2011 13:39
Send private message

freitasm: The payload is Windows only.

I didn't see anything because I don't have Java installed on my system ;)




Interesting. We got a new laptop last month and haven't yet installed java on it either - there seems to be less and less reason for a consumer pc to have java installed anymore?  My reason was mainly to not have those annoying java updates every few weeks, but if there's security issues aswell then that's another reason.

I need it on my work computer, but for home use, it seems like we don't. (btw, we don't play minecraft..)

wreck90
780 posts

Ultimate Geek
Inactive user


  #507912 17-Aug-2011 13:45
Send private message

I use an adblocker, would this have stopped the metservice virus?

My machine is fully patched and Microsoft security essentials up to date. Does this protect too?

If not, how do I know if my machine has this metservice virus? I've not noticed any strange behaviour yet.


[edit] And metservice should warn people on their main webpage, including a link to removal instructions. 

DonGould
3892 posts

Uber Geek


  #507928 17-Aug-2011 13:53
Send private message

wreck90: [edit] And metservice should warn people on their main webpage, including a link to removal instructions. 


+1 Did you email them and suggest that?





Promote New Zealand - Get yourself a .kiwi.nz domain name!!!

Check out mine - i.am.a.can.do.kiwi.nz - don@i.am.a.can.do.kiwi.nz


wreck90
780 posts

Ultimate Geek
Inactive user


  #507937 17-Aug-2011 14:09
Send private message

DonGould:
wreck90: [edit] And metservice should warn people on their main webpage, including a link to removal instructions. 


+1 Did you email them and suggest that?



Nope. However,  I'd feel negligent if my website spread a virus and I didn't warn people .  Thats just me though.  

 

 
 
 

Cloud spending continues to surge globally, but most organisations haven’t made the changes necessary to maximise the value and cost-efficiency benefits of their cloud investments. Download the whitepaper From Overspend to Advantage now.
freitasm
BDFL - Memuneh
79250 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #507941 17-Aug-2011 14:14
Send private message

I wonder if we could have here a quick poll with people's replies: "Which OS were you using when your PC got infected?"

Somehow I'm inclined to think this was all on Windows XP/2003...





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


McNulty
152 posts

Master Geek


  #508019 17-Aug-2011 15:57
Send private message

johnr: Give me one good reason why TM / NZherald / Met service would spread a virus?

You emailed them they must be rolling around on the floor laughing


Not laughing now, ay?

graciem

32 posts

Geek

Trusted

  #508020 17-Aug-2011 15:57
Send private message

freitasm: I wonder if we could have here a quick poll with people's replies: "Which OS were you using when your PC got infected?"

Somehow I'm inclined to think this was all on Windows XP/2003...



Windows XP

DonGould
3892 posts

Uber Geek


  #508031 17-Aug-2011 16:04
Send private message

freitasm: I wonder if we could have here a quick poll with people's replies: "Which OS were you using when your PC got infected?"

Somehow I'm inclined to think this was all on Windows XP/2003...



Can we start with - how do you detect it and how to you fix it?

What do I need to do to confirm that my users don't have it?  So far I've read that AVG and MSE aren't stopping it.

D




Promote New Zealand - Get yourself a .kiwi.nz domain name!!!

Check out mine - i.am.a.can.do.kiwi.nz - don@i.am.a.can.do.kiwi.nz


l43a2
1779 posts

Uber Geek

ID Verified
Trusted

  #508036 17-Aug-2011 16:07
Send private message

my sisters laptop was running WinVista Firefox an AVG managed to stop the infection.





Lifejockey
11 posts

Geek


  #508037 17-Aug-2011 16:07
Send private message

Debian Linux 6.0 :)

freitasm
BDFL - Memuneh
79250 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #508038 17-Aug-2011 16:07
Send private message

If we know what exploit was used, perhaps you can focus your efforts? If you know it's not affecting IE9 on Windows 7 then you know you don't have to spend time on that...





Please support Geekzone by subscribing, or using one of our referral links: Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSyncBackblaze backup


DonGould
3892 posts

Uber Geek


  #508046 17-Aug-2011 16:12
Send private message




Promote New Zealand - Get yourself a .kiwi.nz domain name!!!

Check out mine - i.am.a.can.do.kiwi.nz - don@i.am.a.can.do.kiwi.nz


1 | 2 | 3 | 4 | 5 | 6 | 7 | 8
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.