techPowerUp! Forums

Go Back   techPowerUp! Forums > Software > General Software

Reply
 
Thread Tools
Old Aug 1, 2012, 04:59 PM   #1
MxPhenom 216
Knowledgeable Posting Whore
 
MxPhenom 216's Avatar
 
Join Date: Aug 2010
Location: Seattle, WA
Posts: 6,019 (5.89/day)
Thanks: 1,338
Thanked 1,185 Times in 902 Posts

System Specs

[WARNING] Read this if you have Java

Last night after play some DayZ with erocker, ducky, Haru and Alex logged out and and exitted out of all my programs to shut down for the night and down by the clock Java icon came up like it was updating.....................

Well it wasn't updating it was actually installing Live Security Platinum a Hoax anti virus program that throws false positives out like you have a viruses and such. It also puts a proxy on your internet and disables all exe programs so nothing works.

There are a ton of ways to get rid of it, but it comes down to finding the one that will work well.

Just thought id let everyone know. There is definitely a Java exploit going around and its nasty.

Once I figure out how to get rid of it I will let you all know.
__________________
Motocross is not just a sport, it's a lifestyle.

File Server: Intel Pentium G630, 8GB PNY 1600, AsRock H77M Micro, Corsair CX430M, Vertex 2 90GB (OS), 2x WD Red 2TB in RAID1
“We will never know our full potential, unless we push ourselves to find it. -Travis Rice”

Last edited by MxPhenom 216; Aug 1, 2012 at 05:32 PM.
MxPhenom 216 is online now  
Reply With Quote
The Following 6 Users Say Thank You to MxPhenom 216 For This Useful Post:
Old Aug 2, 2012, 01:12 AM   #2
stinger608
Eligible for custom title
 
stinger608's Avatar
 
Join Date: Nov 2008
Location: Wyoming
Posts: 5,512 (3.28/day)
Thanks: 7,935
Thanked 2,554 Times in 1,792 Posts
Send a message via MSN to stinger608

System Specs

yea, keep us updated man!!!
__________________
#3 Forever A Fan!
Just Because I Don't Care Doesn't Mean I Don't Understand



Check our team Status on Free-DC
stinger608 is offline  
Crunching for Team TPU
Reply With Quote
Old Aug 2, 2012, 03:22 AM   #3
95Viper
3500 Posts
 
95Viper's Avatar
 
Join Date: Oct 2008
Location: στο άλφα έως ωμέγα
Posts: 3,855 (2.26/day)
Thanks: 2,040
Thanked 1,424 Times in 1,123 Posts

System Specs

Quote:
Originally Posted by nvidiaintelftw View Post
Once I figure out how to get rid of it I will let you all know.
Maybe, this will help.
Link is to a guide at bleepingcomputer.com:
Remove Live Security Platinum (Uninstall Guide)

Or, this one at Malwarebytes:
Removal instructions for Live Security Platinum

Last edited by 95Viper; Aug 2, 2012 at 03:36 AM. Reason: Fixed link
95Viper is offline  
Reply With Quote
Old Aug 2, 2012, 03:41 AM   #4
Jstn7477
2000 Posts
 
Jstn7477's Avatar
 
Join Date: Aug 2009
Location: Sarasota, Florida, USA
Posts: 3,248 (2.34/day)
Thanks: 397
Thanked 1,249 Times in 840 Posts

System Specs

lol, "Trojan.LameShield"

Hope nobody else gets this as it does sound rather annoying to remove (like most fake AV programs).
__________________
Intel Crunchers (34 threads): 4770K 4.3G (7t), 2x 3770K 4.3G (14t), 2600K 4G (7t), X3210 (3t), P-M 735A, P4 HT 3G
AMD Crunchers (12 cores):1100T 3.6G (3t), 1045T 3.4G (2t), X4 640 3.2G, X2 4200+, T64 ML-37
AMD Folders (6272 GCN cores): 2x 7950 1125/1475, 7970 1150/1650, 7770 1100/1200
NV Folders (2336 GF10x + 1344 GK104 cores):GTX 470 & 465 720/1715, 4x 460 768MB 825/2000, GTS 450, 660Ti 1228/6000

HEATWARE
Jstn7477 is online now  
Crunching for Team TPU More than 25k PPD
Reply With Quote
Old Aug 2, 2012, 04:03 AM   #5
LAN_deRf_HA
3500 Posts
 
LAN_deRf_HA's Avatar
 
Join Date: Apr 2008
Posts: 4,067 (2.14/day)
Thanks: 295
Thanked 851 Times in 594 Posts

System Specs

This seems similar to the thousand and one variants of fake security center infections. Malwarebytes in safemode usually get's rid of this stuff but the damage can remain. Might need to use system restore, and you should always run ccleaner's registry repair afterwards.
LAN_deRf_HA is offline  
Reply With Quote
Old Aug 2, 2012, 04:21 AM   #6
MxPhenom 216
Knowledgeable Posting Whore
 
MxPhenom 216's Avatar
 
Join Date: Aug 2010
Location: Seattle, WA
Posts: 6,019 (5.89/day)
Thanks: 1,338
Thanked 1,185 Times in 902 Posts

System Specs

Quote:
Originally Posted by LAN_deRf_HA View Post
This seems similar to the thousand and one variants of fake security center infections. Malwarebytes in safemode usually get's rid of this stuff but the damage can remain. Might need to use system restore, and you should always run ccleaner's registry repair afterwards.
I think im just going to be re imaging my system. this thing wrecks havoc on Windows main service.exe files so damage will always be there.
__________________
Motocross is not just a sport, it's a lifestyle.

File Server: Intel Pentium G630, 8GB PNY 1600, AsRock H77M Micro, Corsair CX430M, Vertex 2 90GB (OS), 2x WD Red 2TB in RAID1
“We will never know our full potential, unless we push ourselves to find it. -Travis Rice”
MxPhenom 216 is online now  
Reply With Quote
Old Aug 2, 2012, 05:07 AM   #7
MxPhenom 216
Knowledgeable Posting Whore
 
MxPhenom 216's Avatar
 
Join Date: Aug 2010
Location: Seattle, WA
Posts: 6,019 (5.89/day)
Thanks: 1,338
Thanked 1,185 Times in 902 Posts

System Specs

its going to be a pain, but its what I got to do to for peace of mind that my system is healthy. no messed up files.
__________________
Motocross is not just a sport, it's a lifestyle.

File Server: Intel Pentium G630, 8GB PNY 1600, AsRock H77M Micro, Corsair CX430M, Vertex 2 90GB (OS), 2x WD Red 2TB in RAID1
“We will never know our full potential, unless we push ourselves to find it. -Travis Rice”
MxPhenom 216 is online now  
Reply With Quote
Old Aug 2, 2012, 12:53 PM   #8
TheMailMan78
Banstick Dummy
 
TheMailMan78's Avatar
 
Join Date: Jun 2007
Location: Crystal River, FL
Posts: 15,142 (6.86/day)
Thanks: 1,337
Thanked 6,860 Times in 3,752 Posts

System Specs

You went somewhere or downloaded something you shouldn't have. Only go to safe sites and stay off of torrents. I know you hate anti-virus programs but now you see why MS built one into win 8.
TheMailMan78 is offline  
Reply With Quote
The Following User Says Thank You to TheMailMan78 For This Useful Post:
Old Aug 2, 2012, 04:18 PM   #9
MxPhenom 216
Knowledgeable Posting Whore
 
MxPhenom 216's Avatar
 
Join Date: Aug 2010
Location: Seattle, WA
Posts: 6,019 (5.89/day)
Thanks: 1,338
Thanked 1,185 Times in 902 Posts

System Specs

Quote:
Originally Posted by TheMailMan78 View Post
You went somewhere or downloaded something you shouldn't have. Only go to safe sites and stay off of torrents. I know you hate anti-virus programs but now you see why MS built one into win 8.
Yeah downloaded and installed Java a long time ago lol. the only thing ive downloaded recently and installed was DayZ commander.
__________________
Motocross is not just a sport, it's a lifestyle.

File Server: Intel Pentium G630, 8GB PNY 1600, AsRock H77M Micro, Corsair CX430M, Vertex 2 90GB (OS), 2x WD Red 2TB in RAID1
“We will never know our full potential, unless we push ourselves to find it. -Travis Rice”
MxPhenom 216 is online now  
Reply With Quote
Old Aug 2, 2012, 04:21 PM   #10
TheMailMan78
Banstick Dummy
 
TheMailMan78's Avatar
 
Join Date: Jun 2007
Location: Crystal River, FL
Posts: 15,142 (6.86/day)
Thanks: 1,337
Thanked 6,860 Times in 3,752 Posts

System Specs

Quote:
Originally Posted by nvidiaintelftw View Post
Yeah downloaded and installed Java a long time ago lol. the only thing ive downloaded recently and installed was DayZ commander.
Java doesn't just randomly download a virus. You have to visited an infected site or installed something.
TheMailMan78 is offline  
Reply With Quote
Old Aug 2, 2012, 04:22 PM   #11
Sir B. Fannybottom
1000 Posts
 
Sir B. Fannybottom's Avatar
 
Join Date: Jun 2011
Location: Canadia
Posts: 1,842 (2.47/day)
Thanks: 1,767
Thanked 940 Times in 561 Posts

System Specs

Quote:
Originally Posted by nvidiaintelftw View Post
Yeah downloaded and installed Java a long time ago lol. the only thing ive downloaded recently and installed was DayZ commander.
Just stop being an emo and just use an anti virus, loosing 10mbs of ram is better than needing to reformat every 6 months.
__________________
I do say, what is this madness?
Sir B. Fannybottom is online now  
Reply With Quote
The Following User Says Thank You to Sir B. Fannybottom For This Useful Post:
Old Aug 2, 2012, 04:24 PM   #12
MxPhenom 216
Knowledgeable Posting Whore
 
MxPhenom 216's Avatar
 
Join Date: Aug 2010
Location: Seattle, WA
Posts: 6,019 (5.89/day)
Thanks: 1,338
Thanked 1,185 Times in 902 Posts

System Specs

Quote:
Originally Posted by TheMailMan78 View Post
Java doesn't just randomly download a virus. You have to visited an infected site or installed something.
Like I said the last thing I installed with DayZ commander, and I only go to facebook, newegg, TPU, OCN, and then pinkbike a big mountain bike forum.
__________________
Motocross is not just a sport, it's a lifestyle.

File Server: Intel Pentium G630, 8GB PNY 1600, AsRock H77M Micro, Corsair CX430M, Vertex 2 90GB (OS), 2x WD Red 2TB in RAID1
“We will never know our full potential, unless we push ourselves to find it. -Travis Rice”
MxPhenom 216 is online now  
Reply With Quote
Old Aug 2, 2012, 04:31 PM   #13
TheMailMan78
Banstick Dummy
 
TheMailMan78's Avatar
 
Join Date: Jun 2007
Location: Crystal River, FL
Posts: 15,142 (6.86/day)
Thanks: 1,337
Thanked 6,860 Times in 3,752 Posts

System Specs

Facebook could be it right there. Also I once went to Hardware Canucks and just clicking on the forums I was hit with a Java exploit from one of their advertisers. JS.Black Hole from what I remember that downloads things like fake virus scanners. Most JS exploits come from shady advertisers and there is ZERO you can do about it......except keeping MSE updated.


Edit: It wasnt JS. Black Hole it was VirTool:JS/Obfuscator.BN.
http://www.microsoft.com/security/po...tid=2147646584

I even made a thread about it here.............over a year ago.
http://www.techpowerup.com/forums/sh...d.php?t=148036

Last edited by TheMailMan78; Aug 2, 2012 at 04:39 PM.
TheMailMan78 is offline  
Reply With Quote
The Following User Says Thank You to TheMailMan78 For This Useful Post:
Old Aug 2, 2012, 06:28 PM   #14
MxPhenom 216
Knowledgeable Posting Whore
 
MxPhenom 216's Avatar
 
Join Date: Aug 2010
Location: Seattle, WA
Posts: 6,019 (5.89/day)
Thanks: 1,338
Thanked 1,185 Times in 902 Posts

System Specs

Quote:
Originally Posted by TheMailMan78 View Post
Facebook could be it right there. Also I once went to Hardware Canucks and just clicking on the forums I was hit with a Java exploit from one of their advertisers. JS.Black Hole from what I remember that downloads things like fake virus scanners. Most JS exploits come from shady advertisers and there is ZERO you can do about it......except keeping MSE updated.


Edit: It wasnt JS. Black Hole it was VirTool:JS/Obfuscator.BN.
http://www.microsoft.com/security/po...tid=2147646584

I even made a thread about it here.............over a year ago.
http://www.techpowerup.com/forums/sh...d.php?t=148036
yeah this stuff sucks ass. Last night on TS i was talking about this stuff with Dave and Alex and they were like you are becoming Mailman with virus paranoia
__________________
Motocross is not just a sport, it's a lifestyle.

File Server: Intel Pentium G630, 8GB PNY 1600, AsRock H77M Micro, Corsair CX430M, Vertex 2 90GB (OS), 2x WD Red 2TB in RAID1
“We will never know our full potential, unless we push ourselves to find it. -Travis Rice”
MxPhenom 216 is online now  
Reply With Quote
Old Aug 2, 2012, 06:29 PM   #15
TheMailMan78
Banstick Dummy
 
TheMailMan78's Avatar
 
Join Date: Jun 2007
Location: Crystal River, FL
Posts: 15,142 (6.86/day)
Thanks: 1,337
Thanked 6,860 Times in 3,752 Posts

System Specs

Quote:
Originally Posted by nvidiaintelftw View Post
yeah this stuff sucks ass. Last night on TS i was talking about this stuff with Dave and Alex and they were like you are becoming Mailman with virus paranoidia.
Its only paranoia if no one is out to get you........they are.
TheMailMan78 is offline  
Reply With Quote
The Following 3 Users Say Thank You to TheMailMan78 For This Useful Post:
Old Aug 2, 2012, 11:46 PM   #16
MxPhenom 216
Knowledgeable Posting Whore
 
MxPhenom 216's Avatar
 
Join Date: Aug 2010
Location: Seattle, WA
Posts: 6,019 (5.89/day)
Thanks: 1,338
Thanked 1,185 Times in 902 Posts

System Specs

So i got a USB flash drive. Going to wipe my system clean and install Windows 8
__________________
Motocross is not just a sport, it's a lifestyle.

File Server: Intel Pentium G630, 8GB PNY 1600, AsRock H77M Micro, Corsair CX430M, Vertex 2 90GB (OS), 2x WD Red 2TB in RAID1
“We will never know our full potential, unless we push ourselves to find it. -Travis Rice”
MxPhenom 216 is online now  
Reply With Quote
Old Aug 3, 2012, 12:45 AM   #17
brandonwh64
Addicted to Bacon and StarCrunches!!!
 
brandonwh64's Avatar
 
Join Date: Sep 2009
Location: Chatsworth, GA
Posts: 13,662 (9.90/day)
Thanks: 2,164
Thanked 5,382 Times in 3,729 Posts
Send a message via ICQ to brandonwh64 Send a message via AIM to brandonwh64 Send a message via MSN to brandonwh64 Send a message via Yahoo to brandonwh64

System Specs

I use AVG and it has stopped many of the auto installer java/flash scripts that are in FB and other websites. Its virtually quite and never bugs me about anything but detecting possible harm.
__________________
Cruncher's:
All GPU's
GPU's:
7970 3GB = 8 Threads
5770 1GB OCed = 2 Threads
brandonwh64 is offline  
Crunching for Team TPU
Reply With Quote
Old Aug 3, 2012, 03:29 AM   #18
MxPhenom 216
Knowledgeable Posting Whore
 
MxPhenom 216's Avatar
 
Join Date: Aug 2010
Location: Seattle, WA
Posts: 6,019 (5.89/day)
Thanks: 1,338
Thanked 1,185 Times in 902 Posts

System Specs

Quote:
Originally Posted by brandonwh64 View Post
I use AVG and it has stopped many of the auto installer java/flash scripts that are in FB and other websites. Its virtually quite and never bugs me about anything but detecting possible harm.
dude AVG went to shit after the last few years.

Update:

So I was not able to install windows 8! My sound card doesn't have Windows 8 drivers, and the WIndows 7 ones don't work. Back to Windows 7. Good to have my rig back
__________________
Motocross is not just a sport, it's a lifestyle.

File Server: Intel Pentium G630, 8GB PNY 1600, AsRock H77M Micro, Corsair CX430M, Vertex 2 90GB (OS), 2x WD Red 2TB in RAID1
“We will never know our full potential, unless we push ourselves to find it. -Travis Rice”
MxPhenom 216 is online now  
Reply With Quote
Old Aug 3, 2012, 03:35 AM   #19
brandonwh64
Addicted to Bacon and StarCrunches!!!
 
brandonwh64's Avatar
 
Join Date: Sep 2009
Location: Chatsworth, GA
Posts: 13,662 (9.90/day)
Thanks: 2,164
Thanked 5,382 Times in 3,729 Posts
Send a message via ICQ to brandonwh64 Send a message via AIM to brandonwh64 Send a message via MSN to brandonwh64 Send a message via Yahoo to brandonwh64

System Specs

Quote:
Originally Posted by nvidiaintelftw View Post
dude AVG went to shit after the last few years.
I have never had an issue out of it???? Seems to be protecting me just fine. Same install of windows 7 for over 2 years
__________________
Cruncher's:
All GPU's
GPU's:
7970 3GB = 8 Threads
5770 1GB OCed = 2 Threads
brandonwh64 is offline  
Crunching for Team TPU
Reply With Quote
Old Aug 3, 2012, 03:36 AM   #20
OneMoar
Banned
 
Join Date: Apr 2010
Posts: 2,345 (2.01/day)
Thanks: 91
Thanked 442 Times in 380 Posts

System Specs

I quit using AV ages ago so long as you are not a idiot you will NEVER have a problem
OneMoar is offline  
Reply With Quote
Old Aug 3, 2012, 04:25 AM   #21
TheMailMan78
Banstick Dummy
 
TheMailMan78's Avatar
 
Join Date: Jun 2007
Location: Crystal River, FL
Posts: 15,142 (6.86/day)
Thanks: 1,337
Thanked 6,860 Times in 3,752 Posts

System Specs

Quote:
Originally Posted by OneMoar View Post
I quit using AV ages ago so long as you are not a idiot you will NEVER have a problem
Yup. An idiot that will never know hes infected. So sure. You never have a problem because you have no way to tell. Its like having AIDS but saying your clean because you were never tested.
TheMailMan78 is offline  
Reply With Quote
Old Aug 3, 2012, 04:27 AM   #22
OneMoar
Banned
 
Join Date: Apr 2010
Posts: 2,345 (2.01/day)
Thanks: 91
Thanked 442 Times in 380 Posts

System Specs

Quote:
Originally Posted by TheMailMan78 View Post
Yup. An idiot that will never know hes infected. So sure. You never have a problem because you have no way to tell. Its like having AIDS but saying your clean because you were never tested.
no way to tell ? Orly
I take it you don't monitor your running processes or know how you're machine behaves under normal use then ... I don't need some software to tell me that something is running on my machine that should't be
OneMoar is offline  
Reply With Quote
Old Aug 3, 2012, 04:32 AM   #23
TheMailMan78
Banstick Dummy
 
TheMailMan78's Avatar
 
Join Date: Jun 2007
Location: Crystal River, FL
Posts: 15,142 (6.86/day)
Thanks: 1,337
Thanked 6,860 Times in 3,752 Posts

System Specs

Quote:
Originally Posted by OneMoar View Post
no way to tell ? Orly
I take it you don't monitor your running processes or know how you're machine behaves under normal use then ... I don't need some software to tell me that something is running on my machine that should't be
Yes because all malware shows up under your task manager.
TheMailMan78 is offline  
Reply With Quote
The Following User Says Thank You to TheMailMan78 For This Useful Post:
Old Aug 3, 2012, 04:41 AM   #24
OneMoar
Banned
 
Join Date: Apr 2010
Posts: 2,345 (2.01/day)
Thanks: 91
Thanked 442 Times in 380 Posts

System Specs

Quote:
Originally Posted by TheMailMan78 View Post
Yes because all malware shows up under your task manager.
I am not gonna argue with you you are wrong just because you are not a
s good as I am and are not capable of understanding it on the same level as me does not make you correct ... or even close. I have worked on plenty of AV infected machines and have very rarely resorted to having to use a AV scanner to resolve the issue if you belive there exists a single malware or virus or rootkit that can go undetected with out some crappy bloated Av software telling you that my computer should not be establishing a connection on port 31337 to some ip in china well then I feel sorry for you or need to have it tell me that i should not have processes attempting to hook into system services with strange handles
you have a ways to go before you get to my level
OneMoar is offline  
Reply With Quote
Old Aug 3, 2012, 04:45 AM   #25
TheMailMan78
Banstick Dummy
 
TheMailMan78's Avatar
 
Join Date: Jun 2007
Location: Crystal River, FL
Posts: 15,142 (6.86/day)
Thanks: 1,337
Thanked 6,860 Times in 3,752 Posts

System Specs

Quote:
Originally Posted by OneMoar View Post
I am not gonna argue with you you are wrong just because you are not a
s good as I am and are not capable of understanding it on the same level as me does not make you correct ... or even close. I have worked on plenty of AV infected machines and have very rarely resorted to having to use a AV scanner to resolve the issue if you belive there exists a single malware or virus or rootkit that can go undetected with out some crappy bloated Av software telling you that my computer should not be establishing a connection on port 31337 to some ip in china well then I feel sorry for you or need to have it tell me that i should not have processes attempting to hook into system services with strange handles
you have a ways to go before you get to my level
I guess ignorance is bliss. Carry on.
TheMailMan78 is offline  
Reply With Quote
The Following User Says Thank You to TheMailMan78 For This Useful Post:
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Do you have 1 or more 7970's + Eyefinity? If so, i need your help... Please read on. Stu @ MSD AMD / ATI 3 Mar 25, 2012 04:10 PM
Have you seen/read this article?? FierceRed AMD / ATI 0 Mar 4, 2012 07:00 PM
You like Fifa on PC, READ THIS KainXS Games 16 Jun 27, 2009 10:44 AM


All times are GMT. The time now is 04:41 AM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
no new posts