Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 29th, 2003, 09:35 AM
PhiloVance's Avatar
PhiloVance PhiloVance is offline
Regular Poster
 
Join Date: Jan 2003
Location: Bakersfield, CA
Posts: 88
Default (Java.ByteVerify.exploit trojan

Just found I have this trojan: (Java.ByteVerify.exploit trojan. My eTrust AV program was unable to delete/rename it. How do I get rid of it? Thanks
__________________
Security

-Win 7 machine: Windows Firewall, Microsoft Security Essentials, Spywareblaster and Malwarebytes.

-Win XP machine: Windows Firewall, Eset Nod 32 and Spywareblaster.
  #2  
Old August 29th, 2003, 09:58 AM
PhiloVance's Avatar
PhiloVance PhiloVance is offline
Regular Poster
 
Join Date: Jan 2003
Location: Bakersfield, CA
Posts: 88
Default Re:(Java.ByteVerify.exploit trojan

Sorry, should have given more info:

Win xp home + sp1
Dell 450 Pentium 2
450mhz 328mb ram


Also see attached log.

Thanks.
Attached Files
File Type: txt aug2903VIRUSLOG.TXT (21.3 KB, 0 views)
__________________
Security

-Win 7 machine: Windows Firewall, Microsoft Security Essentials, Spywareblaster and Malwarebytes.

-Win XP machine: Windows Firewall, Eset Nod 32 and Spywareblaster.
  #3  
Old August 29th, 2003, 10:18 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,463
Default Re:(Java.ByteVerify.exploit trojan

Philo,

In order to make sure (as much as possible) this isn't a false positive, use the free services available to check these particular files. Have a look over on our free services page.

Keep us posted.

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #4  
Old August 29th, 2003, 10:20 AM
StAnger StAnger is offline
Regular Poster
 
Join Date: Jun 2003
Posts: 84
Default Re:(Java.ByteVerify.exploit trojan

Try this:
Close all browsers, Start > Settings > Control panel > Java Plugin [version number] > Choose Cache and click remove JAR Cache.
__________________
Stop to warm at karmas burning
Or look ahead, but keep on turning
  #5  
Old August 29th, 2003, 10:24 AM
StAnger StAnger is offline
Regular Poster
 
Join Date: Jun 2003
Posts: 84
Default Re:(Java.ByteVerify.exploit trojan

Sorry Paul,

Didn't mean to get in your way.
__________________
Stop to warm at karmas burning
Or look ahead, but keep on turning
  #6  
Old August 29th, 2003, 11:05 AM
microwave microwave is offline
Infrequent Poster
 
Join Date: Aug 2003
Posts: 6
Default Re:(Java.ByteVerify.exploit trojan

Quote:
quoting: StAnger link=board=30;threadid=13039;start=0#msg83579 date=1062167048]
Sorry Paul,

Didn't mean to get in your way.

Now you've done it - boss is coming after you!

microwave
  #7  
Old August 29th, 2003, 12:59 PM
PhiloVance's Avatar
PhiloVance PhiloVance is offline
Regular Poster
 
Join Date: Jan 2003
Location: Bakersfield, CA
Posts: 88
Default Re:(Java.ByteVerify.exploit trojan

Thanks for the link to the free services page. Will do when I get home (at work right now). And double thanks for your quick response.
__________________
Security

-Win 7 machine: Windows Firewall, Microsoft Security Essentials, Spywareblaster and Malwarebytes.

-Win XP machine: Windows Firewall, Eset Nod 32 and Spywareblaster.
  #8  
Old September 3rd, 2003, 04:22 AM
Elle_N
 
Posts: n/a
Default Re:(Java.ByteVerify.exploit trojan

Please let me begin with an apology for not being particularly computer literate...
I run Vet anti-virus software on my computer, and recently received notification of this trojan while doing a virus check.
I did as you suggested, and performed an on-line scan which did not detect any problems.
Interestingly, it appears that the offending folders, as identified by Vet, are applets, etc. downloaded when playing games like TextTwist and Collapse on Yahoo. Could these be potentially harmful?
At any rate, I located and emptied the folder.
Incidentally, when I followed your suggestion, and located the Jave plug-in settings, I couldn't find a jar cache, only a jpi cache. Should I have cleared that as well? Please pardon my ignorance.
I found this site by doing plugging Vet's findings into Google, and I just want to say that you guys are incredibly knowledgeable and helpful
If I hadn't found this site, I would have been stumped: having found out I have a trojan that couldn't be removed from the system.
Thank you!
  #9  
Old September 3rd, 2003, 04:36 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,378
Default Re:(Java.ByteVerify.exploit trojan

Hi Elle_N,

I'm not sure if there are version differences for Sun Java, but this is what I get when I click the Folder icon behind .jpi cache.

HTH,

Pieter
Attached Images
 
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.
Remove & Prevent spyware
It's human to make mistakes. It's even more so to blame the computer for it.
  #10  
Old September 3rd, 2003, 11:53 AM
Kwea
 
Posts: n/a
Default Re:(Java.ByteVerify.exploit trojan

My AV (Same as you Philo) picked it up this morning. I just installed the AV, so I do not know how the files got there (Recently reformatted system).

Here is a portion of my log:
C:\Documents and Settings\Jared Silva\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Dummy.class-10ff38d8-7370db5d.class - Java.ByteVerify.exploit trojan. Deleted.
C:\Documents and Settings\Jared Silva\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\VerifierBug.class-6bd7446e-320b0bf5.class - Java.ByteVerify.exploit trojan. Deleted.

You can find virus information here:
http://vil.nai.com/vil/content/v_100261.htm

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-011.asp

According to MS, if you upgrade Microsoft VM to version 3810 or later, you are fine.

I do not even have Microsoft VM on my system, so I do not think I have anything to worry about.
  #11  
Old September 4th, 2003, 01:18 AM
PhiloVance's Avatar
PhiloVance PhiloVance is offline
Regular Poster
 
Join Date: Jan 2003
Location: Bakersfield, CA
Posts: 88
Default Re:(Java.ByteVerify.exploit trojan

Sorry so late in reporting back. I tried several sites, the one who also found this trojan was http://housecall.trendmicro.com/

I deleted the trojan after taking STAnger's advice.

Later on 8/31 I got the attached and was able to delete it, but just deleted to my recycle bin then emptied the recycle bin. Must be why it appears in my restore area. Had to turn off system restore, reboot, and turn it back on. All seems well now...no trojans or virus for a few days.



__________________
Security

-Win 7 machine: Windows Firewall, Microsoft Security Essentials, Spywareblaster and Malwarebytes.

-Win XP machine: Windows Firewall, Eset Nod 32 and Spywareblaster.
  #12  
Old September 4th, 2003, 01:20 AM
PhiloVance's Avatar
PhiloVance PhiloVance is offline
Regular Poster
 
Join Date: Jan 2003
Location: Bakersfield, CA
Posts: 88
Default Re:(Java.ByteVerify.exploit trojan

Here's the attached...didn't seem to work last time.
Attached Images
 
__________________
Security

-Win 7 machine: Windows Firewall, Microsoft Security Essentials, Spywareblaster and Malwarebytes.

-Win XP machine: Windows Firewall, Eset Nod 32 and Spywareblaster.
  #13  
Old September 4th, 2003, 07:13 AM
Elle_N
 
Posts: n/a
Default Re:(Java.ByteVerify.exploit trojan

Thank you all so much for your help

And for taking the time to explain where the other cache is located.

All the best,
Elle
  #14  
Old September 4th, 2003, 02:05 PM
keith keith is offline
Infrequent Poster
 
Join Date: Sep 2003
Posts: 4
Default Re:(Java.ByteVerify.exploit trojan

Sorry but I'm a little confused here. StAnger advised to delete the jar folder contents and yet my virsu scan shows the infected files as being in the .jpi_cache folder. Surely I should delete the contents of the .jpi_cache folder to erase the virus. Could someone confirm what I should do as I don't really want to guess, the results could be dramatic (I think).

Thanks,

Keith
  #15  
Old September 4th, 2003, 02:24 PM
StAnger StAnger is offline
Regular Poster
 
Join Date: Jun 2003
Posts: 84
Default Re:(Java.ByteVerify.exploit trojan

This is the part of Philovance log:

C:\Documents and Settings\Joseph\.jpi_cache\jar\1.0\archive.jar-27b6d962-64f7e647.zip>VerifierBug.class - Java.ByteVerify.exploit trojan.
C:\Documents and Settings\Joseph\.jpi_cache\jar\1.0\archive.jar-27b6d962-64f7e647.zip contains infected files.
C:\Documents and Settings\Joseph\.jpi_cache\jar\1.0\archive.jar-27b6d966-542fd7fa.zip>VerifierBug.class - Java.ByteVerify.exploit trojan.
C:\Documents and Settings\Joseph\.jpi_cache\jar\1.0\archive.jar-27b6d966-542fd7fa.zip contains infected files

Follow the path where your scanner found the Exploit and you'll be fine.
__________________
Stop to warm at karmas burning
Or look ahead, but keep on turning
  #16  
Old September 4th, 2003, 02:29 PM
keith keith is offline
Infrequent Poster
 
Join Date: Sep 2003
Posts: 4
Default Re:(Java.ByteVerify.exploit trojan

Sorry to be a pain here, but can I delete all of the contents of the .jpi_cache folder (to be ceratin I get rid of the virus completely) or is that likely to cause damage to the system? I don't know what the folder is used for.
  #17  
Old September 4th, 2003, 02:42 PM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,378
Default Re:(Java.ByteVerify.exploit trojan

Hi keith,

I just hit the Clear button for the .jpi_cache (after checking, there was nothing in there) and the subfolders remain in place, so it wonīt destroy any important folders.

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.
Remove & Prevent spyware
It's human to make mistakes. It's even more so to blame the computer for it.
  #18  
Old September 4th, 2003, 03:20 PM
keith keith is offline
Infrequent Poster
 
Join Date: Sep 2003
Posts: 4
Default Re:(Java.ByteVerify.exploit trojan

Excellent news. Followed the advice, clearing the .jpi_cache folder via the Java plugin route and the next scan I ran found no virus. Looks like the machine is clean again. Thanks for all the help.

My only concern now is, where did I pick the virus up from?? My machines sit behind a Netgear FR314 router and firewall so I thought I was safe from infections.

Any one got any ideas?
  #19  
Old September 4th, 2003, 04:42 PM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,378
Default Re:(Java.ByteVerify.exploit trojan

Hi keith,

Most likely from a site you visited. What is stored in this cache are java-applets. The easiest comparison would be with the items Windows stores in your Downloaded Program Files folder.
Little programs that can be called upon from a website youīre visiting.

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.
Remove & Prevent spyware
It's human to make mistakes. It's even more so to blame the computer for it.
  #20  
Old September 4th, 2003, 05:39 PM
keith keith is offline
Infrequent Poster
 
Join Date: Sep 2003
Posts: 4
Default Re:(Java.ByteVerify.exploit trojan

If the virus can be picked up just browsing the internet then I suppose I'm never really going to know whether or not my machine gets infected at any time. Pity, because I had hoped that the router firewall might have helped prevent the downloading of "dubious" data. I assume therefore that the only answer is to complete virus scans on a daily basis as my AV package didn't notify me that an infection was within any page I had browsed.

Thanks again for the very helpful advice.

Regards,

Keith.
  #21  
Old September 5th, 2003, 12:11 PM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,218
Default Re:(Java.ByteVerify.exploit trojan

Keith, I can reccommend the following programmes: Port Explorer from www.diamondcs.com.au this programme will allow you to see any ougoing connections and stop them in real time, also from the same company TDS3 (Anti-Trojan) and WormGuard which will protect against unknown and potentially dangerous scripts and worms

HTH Pilli
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
  #22  
Old September 29th, 2003, 09:08 AM
sjnet
 
Posts: n/a
Default Re:(Java.ByteVerify.exploit trojan

Quote:
quoting: Pilli link=board=30;threadid=13039;start=15#msg85486 date=1062778273]
Keith, I can reccommend the following programmes: Port Explorer from www.diamondcs.com.au this programme will allow you to see any ougoing connections and stop them in real time, also from the same company TDS3 (Anti-Trojan) and WormGuard which will protect against unknown and potentially dangerous scripts and worms

HTH Pilli

How to prevent my ie from opening redirections when i am visiting infected www by Java.ByteVerify.exploit trojan?

Is it possible? Do I have to close the application and clear my internet temporary files eachtime?

Regards,
Piotr
  #23  
Old September 29th, 2003, 09:25 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,378
Default Re:(Java.ByteVerify.exploit trojan

Hi Piotr,

If you are using the Microsoft Virtual Machine: http://www.microsoft.com/technet/tre...n/MS03-011.asp

If you are using the Sun Java:
Start > Control Panel > Java Plug-In > Cache tab > remove the checkmark before enable caching.

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.
Remove & Prevent spyware
It's human to make mistakes. It's even more so to blame the computer for it.
  #24  
Old September 30th, 2003, 10:42 PM
Libra Libra is offline
Infrequent Poster
 
Join Date: May 2003
Posts: 34
Default Re:(Java.ByteVerify.exploit trojan

Hi,
I'm just curious (I don't have that trojan) but I was reading the thread and decided to look for that Java Plugin. I don't have any Java Plugin in my Control Panel. I'm running Windows 98se and IE6 SP1 and java came with the pc. I have the latest build. Where is my cache/jar located? (I don't have the C:\documents and xxx either).
Thanks.
Sincerely, Libra
  #25  
Old October 1st, 2003, 02:42 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,378
Default Re:(Java.ByteVerify.exploit trojan

Hi Libra,

The Java Plug-In in the Control Panel is only present if you are using Sun's Java.
The Microsoft Virtual machine stores the applets in the Temporary Internet Files.

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.
Remove & Prevent spyware
It's human to make mistakes. It's even more so to blame the computer for it.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:07 AM.


Powered by vBulletinŪ Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright Đ2002 - 2010, Wilders Security Forums