(Java.ByteVerify.exploit trojan

Discussion in 'malware problems & news' started by PhiloVance, Aug 29, 2003.

Thread Status:
Not open for further replies.
  1. huntermcg

    huntermcg Guest

    Java.ByteVerify.exploit, Also known as: Blackbox Trojan.
    http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=36725
    Java.Shinwow, Also known as: Java/Beyond.Trojan
    http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=36651

    Take the trial version of TrojanHunter. Simply download and run the setup file from:
    http://www.misec.net/products/TrojanHunter.exe after the install. make a LiveUpdate from TrojanHunter and then make a full system scan.
     
  2. CrazyJimmy

    CrazyJimmy Guest

    For those people who are saying "it's not in the java folder":

    My problems were all to be found in C:\windows\.jpi_cache\jar\1.0

    and once I deleted the contents of said folder, the problems disappeared.

    I'm using AVGfree (which found the problem, but wouldn't solve it) & Win98SE... I'm also using Mozilla & have completely banned activex... yeah...
     
  3. ljsmaryk

    ljsmaryk Guest

    download adaware se and you will relieve yourself of this problem.
     
  4. angelrat

    angelrat Guest

    No you wont. I have adaware se and I have lots and lots of this stupid trojan. It's breeding or something. aaaaaaghhhh
     
  5. diane

    diane Guest

     
  6. Sleeper

    Sleeper Guest

    Got the same problem, equally solved.
    Thx stAnger
     
  7. `mishimasan`

    `mishimasan` Registered Member

    Joined:
    Feb 19, 2005
    Posts:
    209
    Location:
    London, England
    I just want to say what excellent forums these are. Upon receiving the confirmation that my computer was indeed infected with the byte/verify virus I was worried that it was going to spread out of control (previous virus removal attempts had failed). However, with problems like these it's always best to talk to people who have dealt with them before, and want to give their input and help on the topic. So I typed the virus name into google along with forums, and along came this forum link.

    Above average help - fast response times - I had to make myself a member. Thanks a lot.

    Sincerely,

    `Mishima San`
     
  8. Paul Wilders

    Paul Wilders Administrator

    Joined:
    Jul 1, 2001
    Posts:
    12,475
    Location:
    The Netherlands
    Thanks for the compliment - and welcome ;)

    regards,

    paul
     
  9. Mako3

    Mako3 Guest

    Hey I have the same thing. I was running Norton Antivirus 2005 and it says Noron AV has detected a virus on your computer. and in the details it says this:
    Object Name: C:\Program Files\...\6D6F1B09.tmp
    Virus Name: Trojan.ByteVerify
    Action Taken: Unable to repair this file.

    Also this is rated as a High Risk. How can I get rid of this trojan?
    My system is Windows Xp Profession SP2.
    Also I ran my full system scan with TM PC-Cilling IS 2005 right b4 I ran it with N.A.V and it didnt even detect it.

    Thanks,
    Mako3
     
  10. `mishimasan`

    `mishimasan` Registered Member

    Joined:
    Feb 19, 2005
    Posts:
    209
    Location:
    London, England
    I imagine, if the virus is detected in the Program Files, then you need to find which folder contains the virus, then see if you can manually delete the virus. If the program who's directory contains the virus can be uninstalled and reinstalled, then try this also.

    However you may want to hang around and wait for some more replies.

    p.s. also try following some of the above posts (clearing the java caches, and deleting the temporary internet files and all offline content).
     
  11. pissed

    pissed Guest

    I've tried ALL methods in these and other posts and I'm still getting 2 viruses popping up in AVG every 2 minutes...
     
  12. d_b

    d_b Guest

    I think the verifierbug.class showing up in AVG might be a false possitive. I have run Avg, house calls online scan, panda's online scan, adawareSE, Trojan Hunter, Microsofts Antispyware, Spybot and the only one thats show the trojan is AVG. I dont use sun jave program, only MS VM

    For those using Sun java you might want to check this out http://www.broadbandreports.com/forum/remark,11363541~mode=flat

    Good luck to all of you!!

    dan
     
  13. ficus

    ficus Guest

    i was infected by this virus, able to delete from my cache, now i have contracted it again. seems i cannot delete it from my cache anymore by repeating the same steps.... has it found immunity!? haha......
    well, please, help!!!! does anyone know what i can do?
     
  14. depechemodez

    depechemodez Registered Member

    Joined:
    Mar 22, 2005
    Posts:
    1
    Strange Java/Byte Verify

    My paid Personal AVG will almost certainly finds the JAVA/Byte verify everytime after an update on my Sun JAVA. Thats strange isn't it ? I mean, I put my JAVA to ask me upon downloading the JAVA update and once downloaded and updated .. there it was .. the JAVA/Byte verify thingy will appear. Im using Firefox.

    btw, thanx for the info in here .. i managed to delete them all. I suspect(correct me if im wrong) that AVG may not find it dangerous as it did heals and delete some other related files to the JAVA/byte verify on the same scan. So far i have been very satisfied with the paid AVG .. daily updates and detects almost all viruses and spywares out there(again .. this is limited to AVG presents to me).

    how to be sure ? 100% sure ? I mean, yes, we can download all sort of virus/trojan scanners but still, we'd never know rite ? Its frustrating and consumes a whole lot of our time.

    Thanx again !
     
  15. elishavit

    elishavit Guest

    i followed the Java routine advise and ran again my AVG . This time it didn't find any virus . Thanks.
     
  16. Turtle

    Turtle Guest

  17. dvk01

    dvk01 Global Moderator

    Joined:
    Oct 9, 2003
    Posts:
    3,131
    Location:
    Loughton, Essex. UK
    Removing Java trojans That your antivirus has found

    If you still are using JAVA 1.4 or earlier
    open control panel, select java plug in control panel, select cache and then press clear cache

    If you are using 1.5 version it's slightly different so read here

    http://www.java.com/en/download/help/5000020300.xml
     
  18. Debbie

    Debbie Guest

    Housecall wasn't able to remove/clean the Java.Byte from my system. What I did find that worked was a thread suggesting "If using Sun Java, go to control panel, java plug in, set your cache to zero. Internet Options delete cache".
    Thank You for the help.
     
  19. lec

    lec Guest

    me too adaware wont get rid of it. what will? the first mentioned item in the post above?
     
  20. dvk01

    dvk01 Global Moderator

    Joined:
    Oct 9, 2003
    Posts:
    3,131
    Location:
    Loughton, Essex. UK
    read post 92 and follow instructions

    if you still use M$ java for some reason then

    1) Open Control Panel
    2) Click on Internet Options
    3) On the General Tab, in the middle of the screen, click on Delete Files
    4) You may also want to check the box "Delete all offline content"
    5) Click on OK and wait for the hourglass icon to stop after it deletes the temporary internet files
    6) You can now click on Delete Cookies and click OK to delete cookies that websites have placed on your hard drive
     
  21. alex2k

    alex2k Guest

    dont mean to sound like a computer dummy, but what is a java-plug in? ive looked on my control panel and i cannot find anything. i am using windows 98, would this affect it at all? please reply,
    regards alex
     
  22. dvk01

    dvk01 Global Moderator

    Joined:
    Oct 9, 2003
    Posts:
    3,131
    Location:
    Loughton, Essex. UK
    if you are using windows 98 then you will still be using M$ Java so follow advice in post 95
     
  23. I have contracted the Java byte verify... malware several times in porn sites.

    After much trial and error, this method always cleans it.

    First, I have the newest version of McAfee and that stops some of it from coming in, but now all of it. I'm totally up to date on Window's updates. I have Adaware SE Plus running resident, and that does not stop nor detect it. Other programs that do not detect it: A2, Ewido, Ad-Aware SE, Housecall, Microsoft Antispyware, bitdefender online scan, Spybot S&D...

    And I have these things which does not stop it: SpywareGuard, SpywareBlaster, WinPatrol, IE-Spyad...

    Frusteratingly, McAfee detects most of it, but ends up telling me it cannot clean it, nor delete it, nor quarantine it.

    But here is what I do now and it seems to work everytime:

    1. Go to Tools, Internet Options, Delete Cookies and Delete Files (including offline content).

    2. Go to Control Panel, Java Icon and delete all files.

    3. Run CCleaner (free program) that cleans up all sorts of stuff.

    4. Run Panda ActiveScan (free online scanner). For some reason, the Panda product does what McAfee, Trend, A2, Spybot, Ad-Aware SE.... and others cannot. It finds all remaining java.byteverify...type malware and eliminates it.

    This has made me very tempted to buy the full Panda line next time around -- although I've read that it's a consumption hog, etc... it does seem to work.

    FTP
     
  24. Willow_r17

    Willow_r17 Guest

    I would like some help please. I have read all of the replies on this and have tried them all... So far nothing has worked! Im getting frustrated and dont know what to do. Im on a Compaq and am using Windows 98. I have all the updates and the patch. Ive run and adware program and a spyware remover. I have also run my anit-virus program and it could not delete the files. If someone had some information as to how to delete this I would be grateful or if someone could tell me how to turn on system restore on windows 98. I have also deleted all the temp internet files and run disk cleanup. HELP PLEASE!!!!!
     
  25. AvianFlux

    AvianFlux Registered Member

    Joined:
    Dec 7, 2004
    Posts:
    237
    In Java's Control Panel, setting Temporary Internet Files storage to 0 MB, and disabling cacheing works on my computer.

    Nothing gets stored - including trojans. :D
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.