Fake AV masquerading as Java Update
27-02-2011, 17:17
|
#1
|
Guest
|
Fake AV masquerading as Java Update
IE appears to allow automatic install. Firefox blocks it. Pop up shows the Java mug and on next boot PC Tools is installed and blocking some usage.
Its a typical program of this type easily cleaned using Rkill and Malwarebytes but still a pain in the botton
|
|
|
27-02-2011, 17:27
|
#2
|
Inactive
Join Date: Aug 2004
Services: 30mb BB
Posts: 1,556
|
Re: Fake AV masquerading as Java Update
So, how did you let yourself get infected in the first place, dodgy websites again
|
|
|
27-02-2011, 17:42
|
#3
|
Guest
|
Re: Fake AV masquerading as Java Update
not me
|
|
|
27-02-2011, 17:58
|
#4
|
cf.geek
Join Date: May 2008
Location: Wherever i lay my hat!
Age: 54
Posts: 736
|
Re: Fake AV masquerading as Java Update
This is one of the reasons i dislike Java, it is becoming more and more of an infection vector (allthough it`s not really in this case).
Where`s your botton? Sounds like a place up north
Security Shield seems to be the one doing the rounds at the moment, one in a lovely pink
|
|
|
27-02-2011, 18:31
|
#5
|
Inactive
Join Date: Aug 2004
Services: 30mb BB
Posts: 1,556
|
Re: Fake AV masquerading as Java Update
The ones that change the explorer shell are pain too, Thinkpoint being one:
Stops you going into safe mode, doesn't stop taskmanager though
|
|
|
27-02-2011, 19:33
|
#6
|
Inactive
Join Date: Jan 2004
Posts: 3,898
|
Re: Fake AV masquerading as Java Update
I've had success using the Bit-defender rescue CD in the past to remove infections from a machine, It's a linux based live CD with the Bit-defender AV built in which means you're booting from a clean environment which should in theory help where a rootkit is suspected. (As you are booted from the CD instead of into the compromised OS on your hard-drive)
If it detects a usable network connection it will download the latest definitions before starting to scan the system.
http://download.bitdefender.com/resc...-rescue-cd.iso
|
|
|
27-02-2011, 19:37
|
#7
|
Guest
|
Re: Fake AV masquerading as Java Update
Quote:
Originally Posted by Web-Junkie
The ones that change the explorer shell are pain too, Thinkpoint being one:
Stops you going into safe mode, doesn't stop taskmanager though 
|
safe mode with command promt no shell launched then just run explorer.exe . only had to do it once though
|
|
|
27-02-2011, 19:40
|
#8
|
Inactive
Join Date: Dec 2006
Location: Lincoln UK
Age: 76
Services: 50Mb, TV & Phone
Posts: 3,673
|
Re: Fake AV masquerading as Java Update
Thanks for that Dragon. I've used Avira rescue cd many times in the past which works rather well but I'll have to give the Bit-Defender version a try as well. One can never have too many good tools.
|
|
|
28-02-2011, 17:16
|
#9
|
cf.mega poster
Join Date: Jan 2004
Location: M'boro
Age: 68
Services: phone,BB20meg ,telly
Posts: 1,818
|
Re: Fake AV masquerading as Java Update
Quote:
Originally Posted by Matty_
Th
Where`s your botton? Sounds like a place up north 
|
I think it's a place for special boys and girls
http://www.cvt.org.uk/our-communities/botton-village-north-yorkshire
|
|
|
03-03-2011, 05:54
|
#10
|
Permanently Banned
Join Date: Dec 2007
Location: Wales UK
Age: 43
Services: 50mb Cable, L TV and Phone XL.
Posts: 3,480
|
Re: Fake AV masquerading as Java Update
yep 2 of my mates got the PC Tools virus.
This has been around since about 2007 under various different names but all looks roughly the same and do roughly the same thing.
|
|
|
03-03-2011, 10:37
|
#11
|
Inactive
Join Date: Jan 2007
Location: Doncaster, S. Yorks.
Age: 42
Services: TV:Sky+, BB:DRL VDSL2 40/10 with Ask4, Phone:Mobile Only
Posts: 2,320
|
Re: Fake AV masquerading as Java Update
Quote:
Originally Posted by Scrubbs
|
That was a bit uncalled for...they can't help how they were born
|
|
|
03-03-2011, 10:39
|
#12
|
Guest
|
Re: Fake AV masquerading as Java Update
Quote:
Originally Posted by Welshchris
yep 2 of my mates got the PC Tools virus.
This has been around since about 2007 under various different names but all looks roughly the same and do roughly the same thing.
|
its not a virus its malware aimed at getting your credit card details for nefarious purposes
|
|
|
09-03-2011, 19:09
|
#13
|
Permanently Banned
Join Date: Jul 2007
Location: South Yorkshire
Age: 41
Services: Sky+ HD All Entertainment Packs, VM M TV, BT Unlimited Anytime, VM Talk Weekend Phone, VM XXL BB
Posts: 1,396
|
Re: Fake AV masquerading as Java Update
Quote:
Originally Posted by Scrubbs
|
 your sick mate
|
|
|
09-03-2011, 19:22
|
#14
|
Smeghead
Join Date: Feb 2004
Location: Glasgow
Age: 44
Services: Sky Q 2Tb, Sky Q mini, boxsets and Sports & Movies HD, Sky Fibre unlimited
Posts: 14,515
|
Re: Fake AV masquerading as Java Update
I know the VM DHS team have been getting inundated with calls about this. Seems a lot of people fall for it.
__________________
AMD Ryzen 7 7700 | 32GB DDR5 6000 | RADEON 7900XT | WD 2TB NVME
|
|
|
09-03-2011, 23:09
|
#15
|
cf.mega poster
Join Date: Jan 2004
Location: M'boro
Age: 68
Services: phone,BB20meg ,telly
Posts: 1,818
|
Re: Fake AV masquerading as Java Update
Quote:
Originally Posted by haydnwalker
That was a bit uncalled for...they can't help how they were born 
|
How is it uncalled for?? they are special , I didn't put any smileys or winking or any other symbols or jokes. I mentioned it because there is a place called Botton and it's a lovely place to visit and any advertising for their site can't be a bad thing.
It all depends on which way your mind works.
|
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +1. The time now is 22:20.
|