Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Urgent Help I think I have been hacked

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion
Register FAQ Community Calendar

Anyone running Avast alongside Jetico ?
Reply
 
Thread Tools
Old 07-09-2006, 21:13   #1
pedantic
Inactive
 
Join Date: Mar 2004
Location: Swinton
Services: O2 standard
Posts: 2,499
pedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronze
pedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronze
Send a message via Yahoo to pedantic
Exclamation Anyone running Avast alongside Jetico ?

I've just ran a weekly scan of my drive, with avast AV. It picked up Win32:Rbot-CCS in my Jetico Personal Firewall directory. According to Avast bcfgenv.dll was infected, can any Jetico users confirm that they have this file in the Jetico directory ?

I tried to move the file to chest, but was informed that, because it was in memory, a boot scan was required. Which I did. I moved it to the chest from there, however on restart, Jetico is asking for permissions all over again, for everything that needs access. I'm pretty sure the infected file, must be the configuration file for Jetico.

I made an image of my drive before doing anything, so can restore again, if I made any rash errors on my part. Can anyone confirm this file exists on their machine ? Or maybe this has happened to someone else too ?
pedantic is offline   Reply With Quote
Advertisement
Old 07-09-2006, 22:20   #2
homealone
Guest
 
Posts: n/a
Re: Anyone running Avast alongside Jetico ?



I don't run Jetico, sorry
  Reply With Quote
Old 07-09-2006, 22:31   #3
SnoopZ
CF Resident Dog
 
SnoopZ's Avatar
 
Join Date: Mar 2005
Posts: 15,385
SnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny stars
SnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny stars
Re: Anyone running Avast alongside Jetico ?

According to this, that file isn't a pest and it's correct that you have it in your Jetico folder.

Quote:
programfilesdir+\jetico\jetico personal firewall\bcfgenv.dll
SnoopZ is online now   Reply With Quote
Old 07-09-2006, 23:07   #4
pedantic
Inactive
 
Join Date: Mar 2004
Location: Swinton
Services: O2 standard
Posts: 2,499
pedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronze
pedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronze
Send a message via Yahoo to pedantic
Re: Anyone running Avast alongside Jetico ?

Quote:
Originally Posted by homealone View Post


I don't run Jetico, sorry
No probs ! Thanks for the bump anyway

Quote:
Originally Posted by SnoopZ View Post
According to this, that file isn't a pest and it's correct that you have it in your Jetico folder.
I googled that before snoopz ! Am not sure what to make of it though. It says it's not a pest, but does that mean it still maybe not infected.

I hope it's only a false positive.
pedantic is offline   Reply With Quote
Old 07-09-2006, 23:09   #5
SnoopZ
CF Resident Dog
 
SnoopZ's Avatar
 
Join Date: Mar 2005
Posts: 15,385
SnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny stars
SnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny stars
Re: Anyone running Avast alongside Jetico ?

Quote:
Originally Posted by pedantic View Post
No probs ! Thanks for the bump anyway



I googled that before snoopz ! Am not sure what to make of it though. It says it's not a pest, but does that mean it still maybe not infected.

I hope it's only a false positive.
Email me the file and ill scan it with nod32 if you like.

[edit]

Try scanning the file http://www.kaspersky.com/scanforvirus.html
SnoopZ is online now   Reply With Quote
Old 07-09-2006, 23:12   #6
pedantic
Inactive
 
Join Date: Mar 2004
Location: Swinton
Services: O2 standard
Posts: 2,499
pedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronze
pedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronze
Send a message via Yahoo to pedantic
Re: Anyone running Avast alongside Jetico ?

Quote:
Originally Posted by SnoopZ View Post
Email me the file and ill scan it with nod32 if you like.
pm the addy, thanks.
pedantic is offline   Reply With Quote
Old 07-09-2006, 23:13   #7
Down the Pub
Inactive
 
Down the Pub's Avatar
 
Join Date: Jan 2006
Location: Widnes
Services: Phone/TV/50meg
Posts: 794
Down the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond repute
Re: Anyone running Avast alongside Jetico ?


i use jetico, and that file is presant and correct in the root folder, and just scanned with nod32 and it's not in any way a naughty file that i can see.....

used to use avast and used to get a few false positives with it, not all bad but more of a pain in the **** at times.
Down the Pub is offline   Reply With Quote
Old 07-09-2006, 23:14   #8
pedantic
Inactive
 
Join Date: Mar 2004
Location: Swinton
Services: O2 standard
Posts: 2,499
pedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronze
pedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronze
Send a message via Yahoo to pedantic
Re: Anyone running Avast alongside Jetico ?

Quote:
Originally Posted by Down the Pub View Post

i use jetico, and that file is presant and correct in the root folder, and just scanned with nod32 and it's not in any way a naughty file that i can see.....

used to use avast and used to get a few false positives with it, not all bad but more of a pain in the **** at times.
Thanks for the heads up, I hope this is such a false positive.
pedantic is offline   Reply With Quote
Old 07-09-2006, 23:17   #9
Down the Pub
Inactive
 
Down the Pub's Avatar
 
Join Date: Jan 2006
Location: Widnes
Services: Phone/TV/50meg
Posts: 794
Down the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond reputeDown the Pub has a reputation beyond repute
Re: Anyone running Avast alongside Jetico ?

Quote:
Originally Posted by pedantic View Post
I'm pretty sure the infected file, must be the configuration file for Jetico.
the file description is 'configuration Enviroment Support' so says to me that it should be there.
Down the Pub is offline   Reply With Quote
Old 07-09-2006, 23:33   #10
pedantic
Inactive
 
Join Date: Mar 2004
Location: Swinton
Services: O2 standard
Posts: 2,499
pedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronze
pedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronze
Send a message via Yahoo to pedantic
Re: Anyone running Avast alongside Jetico ?

Quote:
Originally Posted by Down the Pub View Post
the file description is 'configuration Enviroment Support' so says to me that it should be there.
I'm sure it's a valid file, but not sure if it's borked or not lol

---------- Post added at 22:33 ---------- Previous post was at 22:23 ----------

Good news ! I hope

It's looking like a false positive, I submitted the file here which tests it with 27 other Av's, and Avast was the only one that picked it up.
pedantic is offline   Reply With Quote
Old 07-09-2006, 23:35   #11
SnoopZ
CF Resident Dog
 
SnoopZ's Avatar
 
Join Date: Mar 2005
Posts: 15,385
SnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny stars
SnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny starsSnoopZ has a pair of shiny stars
Re: Anyone running Avast alongside Jetico ?

Yep sounds like good news.
SnoopZ is online now   Reply With Quote
Old 07-09-2006, 23:37   #12
ADd
Inactive
 
ADd's Avatar
 
Join Date: Apr 2006
Location: Land of the free
Posts: 308
ADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond repute
Re: Anyone running Avast alongside Jetico ?

I have just tested this for you, it seems that it is a false positive, here is the Jotti online scan results of the dll:

Quote:
File: bcfgenv.dll
Status:
POSSIBLY INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) (Note: this file was only classified as malware by scanners known to generate more false positives than the average scanner. Do not consider these results definately accurate. Also, because of this, results of this scan will not be recorded in the database.)
MD5 2e62fe89d1928829ef72429d13067e4f
Packers detected:
-
Scanner results
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found Win32:Rbot-CCS
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
UNA
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing
I got the same alert after a scan, and from the above results it is definately a false positive. I have emailed avast customer service to alert them to this error. BTW there was a definitions update today, so I think this may have been the problem.
ADd is offline   Reply With Quote
Old 07-09-2006, 23:40   #13
pedantic
Inactive
 
Join Date: Mar 2004
Location: Swinton
Services: O2 standard
Posts: 2,499
pedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronze
pedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronzepedantic is cast in bronze
Send a message via Yahoo to pedantic
Re: Anyone running Avast alongside Jetico ?

Thanks for all the help ! Looks like a falsey lol

---------- Post added at 22:40 ---------- Previous post was at 22:38 ----------

Quote:
Originally Posted by ADd View Post
I got the same alert after a scan, and from the above results it is definately a false positive. I have emailed avast customer service to alert them to this error. BTW there was a definitions update today, so I think this may have been the problem.
Thanks for that info, peace of mind at last
pedantic is offline   Reply With Quote
Old 08-09-2006, 00:03   #14
AntiSilence
Inactive
 
AntiSilence's Avatar
 
Join Date: Jul 2006
Location: Sutton-In-Ashfield
Age: 47
Services: C#/ASP.NET Web Development
Posts: 3,580
AntiSilence is cast in bronzeAntiSilence is cast in bronzeAntiSilence is cast in bronzeAntiSilence is cast in bronze
AntiSilence is cast in bronzeAntiSilence is cast in bronzeAntiSilence is cast in bronzeAntiSilence is cast in bronzeAntiSilence is cast in bronzeAntiSilence is cast in bronzeAntiSilence is cast in bronzeAntiSilence is cast in bronzeAntiSilence is cast in bronzeAntiSilence is cast in bronzeAntiSilence is cast in bronzeAntiSilence is cast in bronze
Re: Anyone running Avast alongside Jetico ?

I had a similar thing with AvG and a file in the Java runtime folder a while back. I use Avast now though! lol
AntiSilence is offline   Reply With Quote
Old 08-09-2006, 00:16   #15
ADd
Inactive
 
ADd's Avatar
 
Join Date: Apr 2006
Location: Land of the free
Posts: 308
ADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond reputeADd has a reputation beyond repute
Re: Anyone running Avast alongside Jetico ?

Thing with definitions, sometimes the guys/gals get them wrong - this has been known to happen with Kaspersky, Symantec amoung many others. Sometimes the mistakes are very serious:

http://news.com.com/CA+antivirus+del...ht&tag=nl.e433

For a server, but you can see the problems it can create. My advice would be to quarantine files and not delete until you are sure they are infected. This way if it is a mistake you can replace the file, incidentally quarantined files are completely safe.

If you come across FP, best thing is to report to the program makers, that way they can get the problem fixed, helping them, you and others users - either do this by email or use their forums (if they have one).
ADd is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 23:43.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum