Cable Forum

Cable Forum (https://www.cableforum.uk/board/index.php)
-   Security & Virus Discussion (https://www.cableforum.uk/board/forumdisplay.php?f=38)
-   -   Fake AV masquerading as Java Update (https://www.cableforum.uk/board/showthread.php?t=33675423)

Zing 27-02-2011 18:17

Fake AV masquerading as Java Update
 
IE appears to allow automatic install. Firefox blocks it. Pop up shows the Java mug and on next boot PC Tools is installed and blocking some usage.

Its a typical program of this type easily cleaned using Rkill and Malwarebytes but still a pain in the botton

Web-Junkie 27-02-2011 18:27

Re: Fake AV masquerading as Java Update
 
So, how did you let yourself get infected in the first place, dodgy websites again :D

Zing 27-02-2011 18:42

Re: Fake AV masquerading as Java Update
 
not me ;)

Matty_ 27-02-2011 18:58

Re: Fake AV masquerading as Java Update
 
This is one of the reasons i dislike Java, it is becoming more and more of an infection vector (allthough it`s not really in this case).
Where`s your botton? Sounds like a place up north :p:

Security Shield seems to be the one doing the rounds at the moment, one in a lovely pink

Web-Junkie 27-02-2011 19:31

Re: Fake AV masquerading as Java Update
 
The ones that change the explorer shell are pain too, Thinkpoint being one:

https://www.cableforum.co.uk/images/local/2011/02/2.jpg

Stops you going into safe mode, doesn't stop taskmanager though ;)

dragon 27-02-2011 20:33

Re: Fake AV masquerading as Java Update
 
I've had success using the Bit-defender rescue CD in the past to remove infections from a machine, It's a linux based live CD with the Bit-defender AV built in which means you're booting from a clean environment which should in theory help where a rootkit is suspected. (As you are booted from the CD instead of into the compromised OS on your hard-drive)

If it detects a usable network connection it will download the latest definitions before starting to scan the system.

http://download.bitdefender.com/resc...-rescue-cd.iso

Zing 27-02-2011 20:37

Re: Fake AV masquerading as Java Update
 
Quote:

Originally Posted by Web-Junkie (Post 35183280)
The ones that change the explorer shell are pain too, Thinkpoint being one:

https://www.cableforum.co.uk/images/local/2011/02/2.jpg

Stops you going into safe mode, doesn't stop taskmanager though ;)

safe mode with command promt no shell launched then just run explorer.exe . only had to do it once though

Dai 27-02-2011 20:40

Re: Fake AV masquerading as Java Update
 
Thanks for that Dragon. I've used Avira rescue cd many times in the past which works rather well but I'll have to give the Bit-Defender version a try as well. One can never have too many good tools.

Scrubbs 28-02-2011 18:16

Re: Fake AV masquerading as Java Update
 
Quote:

Originally Posted by Matty_ (Post 35183256)
Th
Where`s your botton? Sounds like a place up north :p:


I think it's a place for special boys and girls
http://www.cvt.org.uk/our-communities/botton-village-north-yorkshire

Welshchris 03-03-2011 06:54

Re: Fake AV masquerading as Java Update
 
yep 2 of my mates got the PC Tools virus.

This has been around since about 2007 under various different names but all looks roughly the same and do roughly the same thing.

haydnwalker 03-03-2011 11:37

Re: Fake AV masquerading as Java Update
 
Quote:

Originally Posted by Scrubbs (Post 35183884)
I think it's a place for special boys and girls
http://www.cvt.org.uk/our-communities/botton-village-north-yorkshire

That was a bit uncalled for...they can't help how they were born :(

Zing 03-03-2011 11:39

Re: Fake AV masquerading as Java Update
 
Quote:

Originally Posted by Welshchris (Post 35185730)
yep 2 of my mates got the PC Tools virus.

This has been around since about 2007 under various different names but all looks roughly the same and do roughly the same thing.

its not a virus its malware aimed at getting your credit card details for nefarious purposes

the-cable-guy 09-03-2011 20:09

Re: Fake AV masquerading as Java Update
 
Quote:

Originally Posted by Scrubbs (Post 35183884)
I think it's a place for special boys and girls
http://www.cvt.org.uk/our-communities/botton-village-north-yorkshire

:mad: your sick mate

Stephen 09-03-2011 20:22

Re: Fake AV masquerading as Java Update
 
I know the VM DHS team have been getting inundated with calls about this. Seems a lot of people fall for it.

Scrubbs 10-03-2011 00:09

Re: Fake AV masquerading as Java Update
 
Quote:

Originally Posted by haydnwalker (Post 35185804)
That was a bit uncalled for...they can't help how they were born :(



How is it uncalled for?? they are special , I didn't put any smileys or winking or any other symbols or jokes. I mentioned it because there is a place called Botton and it's a lovely place to visit and any advertising for their site can't be a bad thing.

It all depends on which way your mind works.


All times are GMT +1. The time now is 22:09.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum