(Java.ByteVerify.exploit trojan

Discussion in 'malware problems & news' started by PhiloVance, Aug 29, 2003.

Thread Status:
Not open for further replies.
  1. charlie brown 1949

    charlie brown 1949 Registered Member

    Joined:
    Jul 6, 2005
    Posts:
    1
    I had the java.byteverify!.exploit virus on my PC and I followed the instructions I found in a couple of the posted responses on this webstie and it deleted all the virus files. As noted go to;
    1. control panel
    2. click open the java icon
    3. on the "general" tab in Temprary Files click "Delete Files" leave all the boxes checked on the small screen that comes up and click ok, it takes a few seconds and eliminates all temp files.
    4. Click on settings then click the radio button that says Maximum and set it or leave it set at 0 (zero) for the amount of disk space.

    As an extra precaution you can also start up your Internet Browser and under tools click "Internet Options" and delete cookies and files and offline temp files, then click on settings and view files and make sure they all got deleted (if not delete them manually then click vie objects and delete all objects and start fresh.

    This should eliminate all the Java.byteverify!exploit trojan viruses
     
  2. vangelene graves

    vangelene graves Registered Member

    Joined:
    Jul 12, 2005
    Posts:
    1
    I need help

    i have a virus protection but my scan says that java.byte verify is on my pc how can i remove it i can't ascess the java progam
     
  3. epiktus

    epiktus Registered Member

    Joined:
    Sep 26, 2005
    Posts:
    1
    Hi, I've had this exploit trojan for awhile now and i cant seem to get rid of it.
    It has changed all my fonts and settings in my Internet Explorer, it wont allow me to sign into MSN Messenger and now It wont let me go to any webpages. In the mean time I have been using mozilla firefox which is great and works.
    But i would still like this problem fixed. I have tried all your tips and tricks (thanks for them) could you offer any other advice, would formatting my hard drive be an option.
     
  4. funkyfaz

    funkyfaz Guest

    I had the java/byteverify virus. This was very helpful but i deleted the jar file and everything and both the jarjar things. I thought the virus could not be deleted. I even emptied the recycle bin with no problems!!! I am now doing a scan to see if it has gone. Ill tell you if it has!!
    Faye
     
  5. funkyfazzy

    funkyfazzy Guest

    Yeah!! All clear!! Thanks people!!!
    Fayexxx
     
  6. commander.M

    commander.M Registered Member

    Joined:
    Oct 25, 2005
    Posts:
    1
    Thanks Charlie_Brown_1949!

    A quick and easy way to remove those nasty java bastards!
    Does anyone know how to send this junk back to the people that sent it to me?

    commander.M
     
  7. help_me

    help_me Guest

    I could really use some help. My computer contracted the Java.ByteVerify.exploit thingie. I have tried all of the examples in this thread. My EzAntivirus scanner can no longer pick it up and I can't find it manually on my computer anymore but the symptoms of not allowing me to enter certain websites and I still can't run MSN. Is there something that I might have missed by anychance. I Also tried to do the Windows Update but it won't let me get to the download screen either.

    Any and all help would be much appreciated.
     
  8. TopperID

    TopperID Registered Member

    Joined:
    Oct 1, 2004
    Posts:
    1,527
    Location:
    London
    Your problems are unlikely to be caused by ByteVerify, so D/L, install and run CCleaner:-

    http://www.ccleaner.com/

    When you have done that, do an online scan here:-

    http://www.kaspersky.com/downloads/kws/kavwebscan.html

    If it finds anything, make a note of the full file path and name of the malware.

    If you are having difficulty accessing cerain sites this could be due to a variety of reasons, eg your Hosts file, malware redirecting you via an IE DefaultPrefix hijack, your browser settings etc. So the first thing to do is confirm whether or not you are clean.

    You can also check on your version of Sun Java by going here, using I.E., and if there is a newer version available allow it to install it:-

    http://www.java.com/en/download/windows_automatic.jsp

    You can install the latest Windows patches here:-

    http://v5.windowsupdate.microsoft.com/v5consumer/default.aspx?ln=en-us
     
  9. Wilfredo

    Wilfredo Guest

    Hello,

    I have found out that you can manually clean this virus after running AVG. You should open the test center window of your AVG antivirus and click over test results. A new window opens with all the test you have done to your machine.

    Go to your last test result and press the button content,situated between the remove and back buttons in the lower right part of your window. Select the zip files which contain the virus, the button Move to virus vault will appear,press it and that is all.
     
  10. gssss

    gssss Guest

    I did this and it fixed my problem.
    Thanks
     
  11. joshius

    joshius Guest

    hi my name is josh i have the following trojans and dont know how to get rid of them please help i am only 12
    Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jcb.jar-61406f82-4e9e1d87.zip>InsecureClassLoader.class - Java.ByteVerify!exploit trojan.
    C:\Documents and Settings\JJC.JOSH\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jcb.jar-61406f82-4e9e1d87.zip>GetAcceC:\Documents and Settings\JJC.JOSH\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jcb.jar-61406f82-4e9e1d87.zip>Dummy.class - Java.ByteVerify!exploit trojan.
    C:\Documents and Settings\JJC.JOSH\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jcb.jar-61406f82-4e9e1d87.zip>Installer.class - Java.Shinwow.Q trojan.
    C:\Documents and Settings\JJC.JOSH\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jcb.jar-61406f82-4e9e1d87.zip contains infected files.ss.class - Java.ByteVerify!exploit trojan.
    there is 4 in total i am using etrust ez armour
     
  12. `mishimasan`

    `mishimasan` Registered Member

    Joined:
    Feb 19, 2005
    Posts:
    209
    Location:
    London, England
    Ok guys, I've got a really irritating problem. And it started with a java.byteverify. trojan etc.

    I had about 12 infected files, and purging my cache didn't seem to help. So I ran AVG SoHo Edition and it seemed to clear my computer. I ran another test to make sure and there was no trace of the virus, even after I rebooted my system.

    So my question to you all IS..... Why do I see THIS when I open my start menu, and why can't I open the "All Programs" tree? It is like my icons in the start menu have become idle.

    Whenever I try and click on an icon in the most used programs list on the start menu - Windows tells me that it cannot create a shortcut here, would you like to copy this shortcut to the desktop instead?

    Please help - much appreciated,

    `Mishima San`
     
  13. `mishimasan`

    `mishimasan` Registered Member

    Joined:
    Feb 19, 2005
    Posts:
    209
    Location:
    London, England
    It's ok, problem solved. I think that it was just windows playing up.
     
  14. juddd

    juddd Guest

    whats AVG
     
  15. snowbound

    snowbound Retired Moderator

    Joined:
    Feb 18, 2003
    Posts:
    8,723
    Location:
    The Big Smoke
  16. judddd

    judddd Guest

    i am having trouble deleting the jar thing. i think i pressed somthing i wasnt supposed to and now i dont even see the jar thing when i go to control panel and then java plug in.


    please help
     
  17. Line

    Line Registered Member

    Joined:
    Jun 4, 2006
    Posts:
    20
    Location:
    London
    Hello everyone! Thank you for all the useful information.

    System: Windows XP Professional SP2
    AV scan using AVG Free Edition 8-12 objects infected:
    3 entries:
    c:\Documents and Settings\J\Application Data\Sun\Java|Deployment\cache\javapi\v1.0\jar\java.jar-47723671-24b268c1.zip
    Then the same followed by GetAccess.class and Installer.class.
    3 entries:
    c:\Documents and Settings\J\Application Data\Sun\Java|Deployment\cache\javapi\v1.0\jar\loaderadv495.jar-5fe653df-3d5a0b19.zip
    Then the same followed by Counter.class and Parser.class.

    As Libra (#24) I could not found a Java Plug in the Control panel. I only have a Java icon (JRE version 1.5.0_06 but there is no CACHE or JPI tabs). So I opened Java anyway and went to Temporary Internet Files, Setting, View Applets and deleted the 2 infected entries listed in the Java Applet Cache Viewer and that seem to have cleared it. Should I delete everything in there? Should the box Enable Caching be ticked or not?

    I am not sure if I have a Microsoft MV. I am extremely careful, as we downloads music via Ares Ultra and K-LitePro which I thought was safe as I paid for unlimited membership via freemovienow / movieshare and have ETD Security Scanner as well. On top of that I also carry out the following at least twice/three times a week:

    Deleted IE Temporary Internet Files Cookies & Files (ticked box ‘Delete all offline content’),
    Delete unwanted files, Empty Recyclin Bin, Run Diskcleaneup, MS updates/patches always up to date, Deleted unused applications via Control Panel, Download updates and run Spybot S&D and AVG. And all three options are switched on in the Security Center (incl. Firewall).

    So I have no idea have I got infected!! Could downloading music via MSN Messenger have caused this infection (my brother tried this once last week)? How can I prevent the above from happening again?

    Thank you. :)
     
  18. TopperID

    TopperID Registered Member

    Joined:
    Oct 1, 2004
    Posts:
    1,527
    Location:
    London
    This is how it is for latest Java:-

    http://www.java.com/en/download/help/5000020300.xml
    You don't need to keep applets in your cache so you can delete them all. If you regularly clean out your Java cache and block Java when at unknown or possibly risky sites then you probably would not need to disable caching - though it would prevent you from finding Java bugs with AV scans, so it is up to you whether to disable or not.
    Well look here and you can find out how to tell if you have it and how to get rid of it if you have:-

    http://www.java.com/en/download/help/uninstall_msvm.xml
    Save yourself copious amounts of trouble by downloading and regularly using CCleaner:-

    http://www.ccleaner.com/
    If you visit a web site with Sun Java enabled you have no choice as to what applets that site can put into your Java cache. To be properly protected you should consider blocking things like Active X, Sun Java and scripting etc. and only enabling them when you are at a 'safe' site that requires them:-

    http://www.markusjansson.net/exp.html

    http://www.bleepingcomputer.com/tutorials/tutorial102.html

    If that all seems indijestible, some FireWalls can be used to block Java instead of configuring the Browser, but not the free ones I fear.:'(
     
  19. nickwsf

    nickwsf Registered Member

    Joined:
    Jul 12, 2006
    Posts:
    1
    Location:
    Southern California
    WHAT HAPPENS IF I LEAVE Java.ByteVerify ON MY COMPUTER?
     
  20. TopperID

    TopperID Registered Member

    Joined:
    Oct 1, 2004
    Posts:
    1,527
    Location:
    London
    In all likelyhood, absolutely nothing!

    It's exploiting Microsoft's old VM for Java, if you've upgraded to Sun Java you should not be vulnerable to ByteVerify.

    http://forum.java.sun.com/thread.jspa?forumID=54&threadID=605000

    Indeed some people almost view Byteverify, on a fully patched system, as a 'false positive':-

    http://forum.java.sun.com/thread.jspa?threadID=641519&tstart=0

    However, it is a nuisance because it shows up in AV scans and it is maliceous code so it's best just to get rid of it.
     
  21. itsmemario

    itsmemario Registered Member

    Joined:
    Aug 6, 2006
    Posts:
    2
    does anyone know what this trojan does to my pc.... i tried deleting my java files that its infecting.....im not even sure if that worked?

    or at the least can someone tell me how to get rid of this trojan
     
    Last edited by a moderator: Aug 6, 2006
  22. itsmemario

    itsmemario Registered Member

    Joined:
    Aug 6, 2006
    Posts:
    2
    *puppy* oh no its me ..............mario
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.