Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 | 3 | 4 | 5 | 6 | 7 | 8
BDFL - Memuneh
61764 posts

Uber Geek
+1 received by user: 12426

Administrator
Trusted
Geekzone
Lifetime subscriber

  Reply # 506419 14-Aug-2011 20:00
Send private message

And you checked the hosts files (run notepad \windows\system32\drivers\etc\hosts) to see if there's anything left over from the infection?







30 posts

Geek

Trusted

  Reply # 506424 14-Aug-2011 20:05
Send private message

freitasm: And you checked the hosts files (run notepad \windows\system32\drivers\etc\hosts) to see if there's anything left over from the infection?



no .txt files in there.  There are: hosts, Imhosts.sam, networks, protocal, services.

now googling google URL hijacking.  luckily i got this good laptop to use.

 
 
 
 


cisconz
1194 posts

Uber Geek
+1 received by user: 80

Trusted
Lifetime subscriber

  Reply # 506429 14-Aug-2011 20:09
Send private message

graciem:
freitasm: And you checked the hosts files (run notepad \windows\system32\drivers\etc\hosts) to see if there's anything left over from the infection?

no .txt files in there.  There are: hosts, Imhosts.sam, networks, protocal, services.
now googling google URL hijacking.  luckily i got this good laptop to use.

Yes open the "hosts" file in notepad.




Hmmmm




30 posts

Geek

Trusted

  Reply # 506433 14-Aug-2011 20:13
Send private message

cisconz:
Yes open the "hosts" file in notepad.


oh i see.  there's:
127.0.0.1   localhost

8027 posts

Uber Geek
+1 received by user: 387

Trusted
Subscriber

  Reply # 506468 14-Aug-2011 21:19
Send private message

graciem:
cisconz:
Yes open the "hosts" file in notepad.


oh i see.  there's:
127.0.0.1   localhost


That's normal.

What OS, browser and browser version are on this laptop? 

Most browsers have an option to startup with addons/extensions disabled., try that. 

675 posts

Ultimate Geek
+1 received by user: 53


  Reply # 506476 14-Aug-2011 21:40
Send private message

One of my family members also called me up about a virus they recently got,  they swore all they were doing was surfing trademe and such, I didn't really believe them but this makes me wonder, they have an older windows xp machine. Interesting.

2477 posts

Uber Geek
+1 received by user: 885

Trusted
Lifetime subscriber

  Reply # 506495 14-Aug-2011 22:23
Send private message

My wife somehow managed to get a variant of TDSS on her laptop.  The only way we noticed was random sound kept only playing when we weren't doing anything.  Symantec didn't pick it up, neither did AVG, it was only Mcafee did, but couldn't remove it.  Windows Personal Firewall did nothing too.  TDSSKiller from kaspersky was the only thing that cleaned it.

Doesn't surf anything weird basically tm/stuff/facebook etc.  It could have been my daughter accidentally clicking on something, but she is only 6 so not exactly a dodgy site.

TDSS was one nasty piece of malware and I found it very had to remove.  A bit of googling picked up these interesting site about it.

http://www.securelist.com/en/analysis/204792131/TDSS

http://support.kaspersky.com/viruses/solutions?qid=208280684

Nasty stuff....

My bet is it was delivered via an add.





27268 posts

Uber Geek
+1 received by user: 6695

Moderator
Trusted
Biddle Corp
Lifetime subscriber

  Reply # 507564 16-Aug-2011 21:12
Send private message

I've just picked this up this evening as well on one of my older machines running server 2003 with IE8 and up to date MS security essentials. It's definately come from a legit site, presumably from an ad.

29k

6 posts

Wannabe Geek


  Reply # 507608 16-Aug-2011 22:15
Send private message

I'm in the process of finally removing 'Personal Shield Pro' from my PC right now (Vista). I've been on things like Stuff, FB, Twitter and Metservice all day, so I've picked it up from a legit site somewhere. I did notice loading issues with Metservice tonight and then once it did load suddenly I had issues...but as I had other sites open too, no way of proving it.

35 posts

Geek
+1 received by user: 1

Trusted

  Reply # 507731 17-Aug-2011 10:00
Send private message

My work PC Antivirus alerted a virus yesterday afternoon whilst browsing the MetService site around 4pm yesterday.  I would highly suspect it was Ad related as others have mentioned.  McAfee stated it was some kind of Trojan (can't find the full details in the quarantine logs). 

I have droped some of the guys there a line to get them to check it out from their end.



30 posts

Geek

Trusted

  Reply # 507782 17-Aug-2011 10:53
Send private message

freitasm: It was the metservice website: http://twitter.com/#!/MetService/statuses/103597899644026880



legend!  I hope they have a cure for me, my old laptop is still infected with the google url hijacking :(

8027 posts

Uber Geek
+1 received by user: 387

Trusted
Subscriber

  Reply # 507790 17-Aug-2011 11:05
Send private message

graciem:
freitasm: It was the metservice website: http://twitter.com/#!/MetService/statuses/103597899644026880



legend!  I hope they have a cure for me, my old laptop is still infected with the google url hijacking :(



Have you tried closing all programs and running a scan with malwarebytes?

Also start your web browser in it's safe mode with addon's disabled if the hijack is being done by browser addon, or use a different browser (Firefox, Google Chrome) until you can fix IE (presuming you are using IE).

8027 posts

Uber Geek
+1 received by user: 387

Trusted
Subscriber

  Reply # 507792 17-Aug-2011 11:08
Send private message

freitasm: It was the metservice website: http://twitter.com/#!/MetService/statuses/103597899644026880




Anyone know the specifics of how the infection worked and what it infected, seems to be another IE only exploit on unpatched Windows XP and 2003...

6362 posts

Uber Geek
+1 received by user: 317

Trusted
Subscriber

  Reply # 507796 17-Aug-2011 11:11
Send private message

Hi, we have no twitter access here at work, could someone kindly post the guts of the Metservice notice, I see they have plucked their syndicated ad roll.

Cyril

1 | 2 | 3 | 4 | 5 | 6 | 7 | 8
View this topic in a long page with up to 500 replies per page Create new topic



Twitter »

Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.