Just got hit by nasty virus!

What browser were you using?
Is it patched and up to date?

What programs require java, any updated versions of them that can run within a secure environment?

It is possible you have been hit by something close to zero day which is exploiting
http://arstechnica.com/security/2012/08/critical-java-exploit-spreads/
a mess within java even while up to date.
Unsure if Java has been patched in last couple of days, but exploits for this flaw are out there.

There are also some issues with disabling java
http://www.informationweek.com/secu...va-zero-day-attack-second-bug-found/240006431
have a good read at that for some tips.
 
thx to this thread, i am just creating a system image, just done a fresh install 2 weeks ago, pc is running as i want it, so better to be safe than sorry
 
What browser were you using?
Is it patched and up to date?

What programs require java, any updated versions of them that can run within a secure environment?

It is possible you have been hit by something close to zero day which is exploiting
http://arstechnica.com/security/2012/08/critical-java-exploit-spreads/
a mess within java even while up to date.
Unsure if Java has been patched in last couple of days, but exploits for this flaw are out there.

There are also some issues with disabling java
http://www.informationweek.com/secu...va-zero-day-attack-second-bug-found/240006431
have a good read at that for some tips.

Everything was patched and fully uptodate. I was and still am running Firefox.

I have ditched AVG and gone with MSE and comodo personal firewall.

Oracle have released a patch for the latest java. I have since disable java in the broswer and left UAC on default, where before I used to turn it off!!
 
Personal opinion, but AVG sucks! AFAIK the definition updates are delayed for the free version. It's got (or had last time I looked at it) very little in the way of options to change, not that you should need to from an AV program.

I personally use Nod32, but I do keep hearing good things about MSE and have it installed on one of my machines (that doesn't get switched on very often ;))

Don't know why you'd disable UAC either! There's no good reasons to, and many reasons not to!
 
Do you run Java? Before last night, being up-to-date wasn't good enough. Do you run Win7 with UAC enabled?

You should definitely consider enabling interactive plug-in mode.

Chrome: Settings > Advanced settings > Content settings > Plug-ins > Click to play
Firefox: about:config in your URL bar and then search for and enable the plugins.click_to_play

Great protection against Drive-by malware attacks.

That is seriously buggy in Firefox 15. Blank plugin squares even when launching Firefox on it's main page.
 
Had you UAC off?
Where did it install to?
If it was a main folder then one would suspect it would have been stopped.
Main issues arise now on now 7 machines and those without UAC.
 
I run firefox with noscripts and MSE. Have spybot S&D with updated blacklists of sites and the usual array of stuff on standby (Malware bytes, hijack this etc), UAC enabled. Yet to have an issue. I'm sure it will happen but things seem pretty tight at the moment.

I think the next major issue I get I'll bite the bullet and run web browser etc from a virtual machine :p
 
I got this the other day, no idea where from using Firefox. I don't have UAC enabled because I just find it a pain in the ass most of the time.


Safe mode w/networking and malwarebytes sorted it out though. First time I've ever had a virus but it was easy to sort out.
 
I got this the other day, no idea where from using Firefox. I don't have UAC enabled because I just find it a pain in the ass most of the time.

Really? I only ever really see it if I'm installing something? Doesn't bother me in the slightest. It's not like it's there in my face the whole time I'm on the PC.
 
Would UAC have stopped the trojan horse from installing tho?

It managed to escape AVG, even tho AVG detected it, and said it quarantined the file.

It might have done, it might not. It depends on how how your system was exploited. It's worth pointing out though that there are two people in this thread who got infected by this and both had UAC disabled.

Security isn't just one thing, it's a system of best practices and not running as full administrator all the time is just bread & butter policy and it's as old as the hills.
 
Back
Top Bottom