PDA

View Full Version : TrojanHunter: (Delsha.100) False alarm?


Someguy
May 5th, 2004, 06:06 PM
I just did a scan with the trial TrojanHunter and got the message: "Found trojan file: D:\Download\Development\j2sdk-1_4_2-doc.zip/rmi-protocol7.html (Delsha.100)".

I find this strange because it is a html file and part of the official Java SDK documentation from Sun.

Is this a false alarm?

Thanks all.

Gavin - DiamondCS
May 6th, 2004, 12:44 AM
Definitely will be, I'd leave it and wait for an official response

DelSha I think DELSHARE, which is probably one of the BAT files which is included in some autospreader bots - once they get on the machine via NetBIOS, they remove all shared drives so noone comes along and steals the machine off them (since they know "own" it)

hayc59
May 9th, 2004, 12:54 PM
Someguy, this may help(thanks Marti for the helping hand!!)
-{ Quote: "Virus found in the Java™ Runtime Environment, Standard Edition (JRE) cache directory
This error applies to you if you are using any of the following platforms:
Windows 98, ME, NT, 2000, XP, 2003

SYMPTOM(S)
Malicious applets have been discovered in the JRE cache directory. Anti-virus programs have detected such malicious applets in the following directory:
C:\Documents and Settings\<username>\Application Data\Sun\Java\Deployment\cache\javapi\v1. 0\jar\
These malicious applets are designed to exploit vulnerabilities in the Microsoft VM (Microsoft Security Bulletin MS03-011).
If you are using the Sun JVM™ as your default virtual machine, these malicious applets cannot cause any harm to your computer." }-MoreInfo--->
http://java.com/en/download/help/cache_virus.jsp