I'm getting virus alerts on PH - anyone else getting them?
Discussion
My Panda Antivirus has just started to kick up a fuss about a virus on PH.
http://cdn.code.haymarket.com/injector/deliver/pis...
It's reporting the virus as "JS/Agent.MZT".
Only just started, and is happening on every page.
http://cdn.code.haymarket.com/injector/deliver/pis...
It's reporting the virus as "JS/Agent.MZT".
Only just started, and is happening on every page.
Are you using Panda as well? I did a bit of digging, and it appears to be a virus that only Panda spots, and it was found two days ago.
I think it's a false positive (I had a look at the JS code that is downloaded).
As a temporary measure, I've modified my Windows' hosts file so that the domain is effectively blocked.
To do this, you need to edit C:\Windows\System32\drivers\etc\hosts in notepad, and change the line that starts:
127.0.0.1 localhost
To:
127.0.0.1 localhost cdn.code.haymarket.com
Save that, and restart the browser. Note that this works in XP; not sure about Vista and above.
The only slight downside that I've seen is that you don't get adverts.

I think it's a false positive (I had a look at the JS code that is downloaded).
As a temporary measure, I've modified my Windows' hosts file so that the domain is effectively blocked.
To do this, you need to edit C:\Windows\System32\drivers\etc\hosts in notepad, and change the line that starts:
127.0.0.1 localhost
To:
127.0.0.1 localhost cdn.code.haymarket.com
Save that, and restart the browser. Note that this works in XP; not sure about Vista and above.
The only slight downside that I've seen is that you don't get adverts.

tribbles said:
Are you using Panda as well? I did a bit of digging, and it appears to be a virus that only Panda spots, and it was found two days ago.
I think it's a false positive (I had a look at the JS code that is downloaded).
As a temporary measure, I've modified my Windows' hosts file so that the domain is effectively blocked.
To do this, you need to edit C:\Windows\System32\drivers\etc\hosts in notepad, and change the line that starts:
127.0.0.1 localhost
To:
127.0.0.1 localhost cdn.code.haymarket.com
Save that, and restart the browser. Note that this works in XP; not sure about Vista and above.
The only slight downside that I've seen is that you don't get adverts.

I've just done that and I'm not getting a mental panda now, thanks very much! I think it's a false positive (I had a look at the JS code that is downloaded).
As a temporary measure, I've modified my Windows' hosts file so that the domain is effectively blocked.
To do this, you need to edit C:\Windows\System32\drivers\etc\hosts in notepad, and change the line that starts:
127.0.0.1 localhost
To:
127.0.0.1 localhost cdn.code.haymarket.com
Save that, and restart the browser. Note that this works in XP; not sure about Vista and above.
The only slight downside that I've seen is that you don't get adverts.

from a total technophobe, that was very easy to follow

The link in the first post is the javascript code we use to run all the display adverts, site statistics and other little things so is something we have developed in-house and the javascript is well known to us. So I would be surprised if it has an infection and thus think it is a false positive too. Particularly as one virus scanner has picked it up.
RacingPete said:
The link in the first post is the javascript code we use to run all the display adverts, site statistics and other little things so is something we have developed in-house and the javascript is well known to us. So I would be surprised if it has an infection and thus think it is a false positive too. Particularly as one virus scanner has picked it up.
I read the Javascript and I couldn't see anything that leapt out at me as being a virus. I also worked out that the adverts would be affected from that too 
The odd thing was that I didn't appear to get any adverts on my Mac last night at home (which worried me a bit). I'll have another go with that.
Gassing Station | Website Feedback | Top of Page | What's New | My Stuff



