Hello everyone, I have been using MagicJack for about 3 months and I have absolutely no problems with it at all, except for one kind of big one.
Ever since I installed MagicJack, it seems that pretty close to everyday I have to remove different Rogue Antivirus programs from the computer. Mostly Palladium or AntiSpyware 2011 ones in particular.
Now it's important that I stress that I do not use this computer for anything but running MagicJack, that is it. All web browsing and computing is done via my laptop that I use on a wireless connection. No web browsing or computing is done at all on the computer running MagicJack..
I do keep the computer fully patched and updated, as well as having an antivirus program (Symantec Endpoint Protection) and the Windows firewall turned on.
Has anyone else experienced this problem? If so what am I doing wrong? I have to believe that this influx of infections has something to do with leaving the computer running 24/7 and the MagicJack connection.
Any help would be greatly appreciated
Rogue Antivirus Spyware
Moderators: Bill Smith, Pilot
-
bitstopjoe
- Future magicJack CEO
- Posts: 2844
- Joined: Sat Sep 13, 2008 5:25 pm
- Location: North East Pennsylvania
- V-Man
- MagicJack Expert
- Posts: 99
- Joined: Tue Mar 30, 2010 9:26 pm
- Location: Fort Worth, Texas
- Contact:
I've been running MJ for close to a year now and that's never happened to me either. I agree with Joe.....sounds like someone "helped" you.
IMHO, this sounds like another good reason to use a thin client with an active EWF. Since the EWF locks out any kind of permanent write to the flash drive unless the admin does a commit, this is the perfect way to prevent ANY kind of unwanted software from getting in your OS. Additionally, anytime I see there's been an update push from MJ, I do a complete power down of the tc which in turn does a fresh install of the mj update onto the RAM. Once the update is finished, i do a commit and I'm good-to-go until the next mj push.
Not suggesting you go buy a thin client though.....what works for me might not work for you. Besides, I suspect MJ will have their own stand alone ATA in the not too distant future with the recent VocalTec/YMax merger.
http://sec.gov/Archives/edgar/data/1005 ... xv99wb.htm
Kudos to Bill Smith for the above link.
IMHO, this sounds like another good reason to use a thin client with an active EWF. Since the EWF locks out any kind of permanent write to the flash drive unless the admin does a commit, this is the perfect way to prevent ANY kind of unwanted software from getting in your OS. Additionally, anytime I see there's been an update push from MJ, I do a complete power down of the tc which in turn does a fresh install of the mj update onto the RAM. Once the update is finished, i do a commit and I'm good-to-go until the next mj push.
Not suggesting you go buy a thin client though.....what works for me might not work for you. Besides, I suspect MJ will have their own stand alone ATA in the not too distant future with the recent VocalTec/YMax merger.
http://sec.gov/Archives/edgar/data/1005 ... xv99wb.htm
Kudos to Bill Smith for the above link.
Last edited by V-Man on Wed Jan 05, 2011 6:01 pm, edited 1 time in total.
MJ user since Feb '10
MJ MagicFeatures user since Mar '10
NT TK6000 user since Apr '10
Dedicated MJ Thin Client: HP t5710 1.2GHz 1gF/512R, running MJ, MagicFeatures & TightVNC, 12-15 watts w/o monitor, roughly $1.25 per month electric cost
MJ MagicFeatures user since Mar '10
NT TK6000 user since Apr '10
Dedicated MJ Thin Client: HP t5710 1.2GHz 1gF/512R, running MJ, MagicFeatures & TightVNC, 12-15 watts w/o monitor, roughly $1.25 per month electric cost
-
crackerjack
- Dan Should Pay Me
- Posts: 784
- Joined: Fri Nov 16, 2007 9:32 pm
Re: Rogue Antivirus Spyware
Once fully cleaned you should be ok. You still have remnants of trojan/rootkit running not fully removed by SymantecMrX wrote:Hello everyone, I have been using MagicJack for about 3 months and I have absolutely no problems with it at all, except for one kind of big one.
Ever since I installed MagicJack, it seems that pretty close to everyday I have to remove different Rogue Antivirus programs from the computer. Mostly Palladium or AntiSpyware 2011 ones in particular.
Now it's important that I stress that I do not use this computer for anything but running MagicJack, that is it. All web browsing and computing is done via my laptop that I use on a wireless connection. No web browsing or computing is done at all on the computer running MagicJack..
I do keep the computer fully patched and updated, as well as having an antivirus program (Symantec Endpoint Protection) and the Windows firewall turned on.
Has anyone else experienced this problem? If so what am I doing wrong? I have to believe that this influx of infections has something to do with leaving the computer running 24/7 and the MagicJack connection.
Any help would be greatly appreciated
Do these steps...
d/l combofix from http://www.bleepingcomputer.com/downloa ... s/combofix
d/l proggy from malwarebytes.org
run combofix to completion
run malwarebytes in full scan mode
activate protection in malwarebytes
optional-buy malwarebytes
Stop clicking on stupid links
Good Luck
CrackerJack
MagicJack Customer #73
MagicJack user since May 2007
MagicJack abuser since June 2007
"I gots mo' numbers than a Lotto machine!!!"
CrackerJack
MagicJack Customer #73
MagicJack user since May 2007
MagicJack abuser since June 2007
"I gots mo' numbers than a Lotto machine!!!"
Re: Rogue Antivirus Spyware
Might want to run antispyware removal in Safe Mode
To enter Safe Mode reboot Windows and press the F8 key (on the top row of the keyboard) a couple of times. If you’ve done it correctly you will see the following screen:
I recommend chosing Safe Mode with Networking so you can still access the internet and download whatever programs you need to.
Once you enter safe mode you will see the desktop but it won’t look as pretty as it usually does since Windows hasn’t loaded the normal graphics drivers.
To enter Safe Mode reboot Windows and press the F8 key (on the top row of the keyboard) a couple of times. If you’ve done it correctly you will see the following screen:
I recommend chosing Safe Mode with Networking so you can still access the internet and download whatever programs you need to.
Once you enter safe mode you will see the desktop but it won’t look as pretty as it usually does since Windows hasn’t loaded the normal graphics drivers.