Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Fake AV masquerading as Java Update

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion
Register FAQ Community Calendar

Fake AV masquerading as Java Update
Reply
 
Thread Tools
Old 27-02-2011, 17:17   #1
Zing
Guest
 
Posts: n/a
Fake AV masquerading as Java Update

IE appears to allow automatic install. Firefox blocks it. Pop up shows the Java mug and on next boot PC Tools is installed and blocking some usage.

Its a typical program of this type easily cleaned using Rkill and Malwarebytes but still a pain in the botton
  Reply With Quote
Advertisement
Old 27-02-2011, 17:27   #2
Web-Junkie
Inactive
 
Join Date: Aug 2004
Services: 30mb BB
Posts: 1,556
Web-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpack
Re: Fake AV masquerading as Java Update

So, how did you let yourself get infected in the first place, dodgy websites again
Web-Junkie is offline   Reply With Quote
Old 27-02-2011, 17:42   #3
Zing
Guest
 
Posts: n/a
Re: Fake AV masquerading as Java Update

not me
  Reply With Quote
Old 27-02-2011, 17:58   #4
Matty_
cf.geek
 
Join Date: May 2008
Location: Wherever i lay my hat!
Age: 54
Posts: 736
Matty_ has reached the bronze age
Matty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze ageMatty_ has reached the bronze age
Re: Fake AV masquerading as Java Update

This is one of the reasons i dislike Java, it is becoming more and more of an infection vector (allthough it`s not really in this case).
Where`s your botton? Sounds like a place up north

Security Shield seems to be the one doing the rounds at the moment, one in a lovely pink
Matty_ is offline   Reply With Quote
Old 27-02-2011, 18:31   #5
Web-Junkie
Inactive
 
Join Date: Aug 2004
Services: 30mb BB
Posts: 1,556
Web-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpackWeb-Junkie has a very nice sixpack
Re: Fake AV masquerading as Java Update

The ones that change the explorer shell are pain too, Thinkpoint being one:



Stops you going into safe mode, doesn't stop taskmanager though
Web-Junkie is offline   Reply With Quote
Old 27-02-2011, 19:33   #6
dragon
Inactive
 
Join Date: Jan 2004
Posts: 3,898
dragon has reached the bronze age
dragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze agedragon has reached the bronze age
Re: Fake AV masquerading as Java Update

I've had success using the Bit-defender rescue CD in the past to remove infections from a machine, It's a linux based live CD with the Bit-defender AV built in which means you're booting from a clean environment which should in theory help where a rootkit is suspected. (As you are booted from the CD instead of into the compromised OS on your hard-drive)

If it detects a usable network connection it will download the latest definitions before starting to scan the system.

http://download.bitdefender.com/resc...-rescue-cd.iso
dragon is offline   Reply With Quote
Old 27-02-2011, 19:37   #7
Zing
Guest
 
Posts: n/a
Re: Fake AV masquerading as Java Update

Quote:
Originally Posted by Web-Junkie View Post
The ones that change the explorer shell are pain too, Thinkpoint being one:



Stops you going into safe mode, doesn't stop taskmanager though
safe mode with command promt no shell launched then just run explorer.exe . only had to do it once though
  Reply With Quote
Old 27-02-2011, 19:40   #8
Dai
Inactive
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 76
Services: 50Mb, TV & Phone
Posts: 3,673
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Send a message via MSN to Dai
Re: Fake AV masquerading as Java Update

Thanks for that Dragon. I've used Avira rescue cd many times in the past which works rather well but I'll have to give the Bit-Defender version a try as well. One can never have too many good tools.
Dai is offline   Reply With Quote
Old 28-02-2011, 17:16   #9
Scrubbs
cf.mega poster
 
Scrubbs's Avatar
 
Join Date: Jan 2004
Location: M'boro
Age: 68
Services: phone,BB20meg ,telly
Posts: 1,818
Scrubbs has a bronzed appealScrubbs has a bronzed appeal
Scrubbs has a bronzed appealScrubbs has a bronzed appealScrubbs has a bronzed appealScrubbs has a bronzed appealScrubbs has a bronzed appeal
Re: Fake AV masquerading as Java Update

Quote:
Originally Posted by Matty_ View Post
Th
Where`s your botton? Sounds like a place up north

I think it's a place for special boys and girls
http://www.cvt.org.uk/our-communities/botton-village-north-yorkshire
Scrubbs is offline   Reply With Quote
Old 03-03-2011, 05:54   #10
Welshchris
Permanently Banned
 
Join Date: Dec 2007
Location: Wales UK
Age: 43
Services: 50mb Cable, L TV and Phone XL.
Posts: 3,480
Welshchris is the helpful oneWelshchris is the helpful oneWelshchris is the helpful oneWelshchris is the helpful oneWelshchris is the helpful oneWelshchris is the helpful oneWelshchris is the helpful oneWelshchris is the helpful oneWelshchris is the helpful oneWelshchris is the helpful oneWelshchris is the helpful oneWelshchris is the helpful oneWelshchris is the helpful oneWelshchris is the helpful oneWelshchris is the helpful oneWelshchris is the helpful oneWelshchris is the helpful oneWelshchris is the helpful one
Re: Fake AV masquerading as Java Update

yep 2 of my mates got the PC Tools virus.

This has been around since about 2007 under various different names but all looks roughly the same and do roughly the same thing.
Welshchris is offline   Reply With Quote
Old 03-03-2011, 10:37   #11
haydnwalker
Inactive
 
Join Date: Jan 2007
Location: Doncaster, S. Yorks.
Age: 42
Services: TV:Sky+, BB:DRL VDSL2 40/10 with Ask4, Phone:Mobile Only
Posts: 2,320
haydnwalker has reached the bronze age
haydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze age
Re: Fake AV masquerading as Java Update

Quote:
Originally Posted by Scrubbs View Post
I think it's a place for special boys and girls
http://www.cvt.org.uk/our-communities/botton-village-north-yorkshire
That was a bit uncalled for...they can't help how they were born
haydnwalker is offline   Reply With Quote
Old 03-03-2011, 10:39   #12
Zing
Guest
 
Posts: n/a
Re: Fake AV masquerading as Java Update

Quote:
Originally Posted by Welshchris View Post
yep 2 of my mates got the PC Tools virus.

This has been around since about 2007 under various different names but all looks roughly the same and do roughly the same thing.
its not a virus its malware aimed at getting your credit card details for nefarious purposes
  Reply With Quote
Old 09-03-2011, 19:09   #13
the-cable-guy
Permanently Banned
 
Join Date: Jul 2007
Location: South Yorkshire
Age: 41
Services: Sky+ HD All Entertainment Packs, VM M TV, BT Unlimited Anytime, VM Talk Weekend Phone, VM XXL BB
Posts: 1,396
the-cable-guy is a jewel in the roughthe-cable-guy is a jewel in the roughthe-cable-guy is a jewel in the roughthe-cable-guy is a jewel in the roughthe-cable-guy is a jewel in the rough
Re: Fake AV masquerading as Java Update

Quote:
Originally Posted by Scrubbs View Post
I think it's a place for special boys and girls
http://www.cvt.org.uk/our-communities/botton-village-north-yorkshire
your sick mate
the-cable-guy is offline   Reply With Quote
Old 09-03-2011, 19:22   #14
Stephen
Smeghead
 
Stephen's Avatar
 
Join Date: Feb 2004
Location: Glasgow
Age: 44
Services: Sky Q 2Tb, Sky Q mini, boxsets and Sports & Movies HD, Sky Fibre unlimited
Posts: 14,515
Stephen has a nice shiny starStephen has a nice shiny starStephen has a nice shiny star
Stephen has a nice shiny starStephen has a nice shiny starStephen has a nice shiny starStephen has a nice shiny starStephen has a nice shiny starStephen has a nice shiny starStephen has a nice shiny starStephen has a nice shiny starStephen has a nice shiny starStephen has a nice shiny starStephen has a nice shiny starStephen has a nice shiny starStephen has a nice shiny starStephen has a nice shiny starStephen has a nice shiny starStephen has a nice shiny starStephen has a nice shiny starStephen has a nice shiny star
Re: Fake AV masquerading as Java Update

I know the VM DHS team have been getting inundated with calls about this. Seems a lot of people fall for it.
__________________
AMD Ryzen 7 7700 | 32GB DDR5 6000 | RADEON 7900XT | WD 2TB NVME
Stephen is offline   Reply With Quote
Old 09-03-2011, 23:09   #15
Scrubbs
cf.mega poster
 
Scrubbs's Avatar
 
Join Date: Jan 2004
Location: M'boro
Age: 68
Services: phone,BB20meg ,telly
Posts: 1,818
Scrubbs has a bronzed appealScrubbs has a bronzed appeal
Scrubbs has a bronzed appealScrubbs has a bronzed appealScrubbs has a bronzed appealScrubbs has a bronzed appealScrubbs has a bronzed appeal
Re: Fake AV masquerading as Java Update

Quote:
Originally Posted by haydnwalker View Post
That was a bit uncalled for...they can't help how they were born


How is it uncalled for?? they are special , I didn't put any smileys or winking or any other symbols or jokes. I mentioned it because there is a place called Botton and it's a lovely place to visit and any advertising for their site can't be a bad thing.

It all depends on which way your mind works.
Scrubbs is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 20:11.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum