| View previous topic :: View next topic |
| Author |
Message |
Matt_D
Cadet

 Joined: Apr 22, 2008 Posts: 6 Location: UK
|
Posted: Tue Apr 22, 2008 8:28 pm Post subject: Java.Trojan.Exploit.Bytverify - gone, but what's the damage? |
|
|
Not sure if this is really the correct forum or not, so apologies if it isn't.
Some info:
My PC runs XP SP2, & I use Kaspersky Internet Security 7 (Firewall & AV etc.), Spybot S&D, AdAware, Spywareblaster, cwshredder, & HiJackThis. All are up to date. I also use Firefox with AdBlockPlus & NoScript for web browsing (with IE7 only generally being used for Windows Update).
I tend to do a full My Computer scan with KIS7 every few days or so, with it set to "Maximum", but customised to make it, well, more than Maximum.
On Saturday (IIRC), I performed a few free online scans using BitDefender, Trend Micro Housecall, a squared, & F Secure.
BitDefender claimed it found two java .class files infected with "Java.Trojan.Exploit.Bytverify", somewhere within "C:\Documents and Settings\[My Wife's Profile]\Application Data\Sun\Java\Deployment\cache\".
BD then cleaned it, & the other online scans (after the BD scan/clean) found nothing. A full KIS scan also later found nothing.
She had not used my PC in a week or so, having finally got her new laptop, while the last full KIS scan before this "incident" was only a day or two earlier, & found absolutely nothing.
So, did KIS somehow miss this "Bytverify" thing?
Or could it have been a false positive by BD?
Also, what are the chances of anything dodgy having been done with this "Bytverify" trojan?
Checking it out on Google, it seems it exploits a vulnerability in the Microsoft Virtual Machine, & was discovered in 2003. The exploit was patched in 2003.
http://www.bitdefender.com/site/VirusInfo/showVirusInfo/547
http://secunia.com/advisories/8559/
http://www.microsoft.com/technet/security/bulletin/MS03-011.asp
So... seeing as my PC actually uses the current up to date Sun Java, rather than the MS Virtual Machine, could this "Java.Trojan.Exploit.Bytverify" have done anything anyway?
Do I have anything to worry about?
Any help/advice much appreciated
I don't want to go to the hassle of nuking my PC & changing all passwords for nothing.
|
|
| Back to top |
|
 |
k027
Special Response Team Guest Forums Host

 Joined: Aug 25, 2003 Posts: 8506
|
Posted: Tue Apr 22, 2008 9:57 pm Post subject: |
|
|
Anti-malware companies are not consistent in how they name various viruses, trojans, etc. Two companies may use different names for the same exploit or the same name for different exploits. To determine the characteristics and possible adverse effects of the malware detected on your computer you need to look at the malware data base for the particular anti-malware program that detected the malware.
|
|
| Back to top |
|
 |
Matt_D
Cadet

 Joined: Apr 22, 2008 Posts: 6 Location: UK
|
Posted: Tue Apr 22, 2008 10:07 pm Post subject: |
|
|
The first search result in Google for "Java.Trojan.Exploit.Bytverify" was the link I gave in my first post for Bitdefender.com's description (http://www.bitdefender.com/site/VirusInfo/showVirusInfo/547), and it was BitDefender's online scan that found it.
|
|
| Back to top |
|
 |
Matt_D
Cadet

 Joined: Apr 22, 2008 Posts: 6 Location: UK
|
Posted: Sat Apr 26, 2008 11:00 pm Post subject: |
|
|
Does anyone have any ideas/help?
|
|
| Back to top |
|
 |
Cudni
Special Response Team
 Joined: Dec 10, 2002 Posts: 3717 Location: Et In Arcadia ego
|
Posted: Sat Apr 26, 2008 11:05 pm Post subject: |
|
|
did you empty java cache? in any case nothing to worry about
Cudni _________________ Hecho en Mexico
|
|
| Back to top |
|
 |
Matt_D
Cadet

 Joined: Apr 22, 2008 Posts: 6 Location: UK
|
Posted: Tue Apr 29, 2008 12:38 am Post subject: |
|
|
Thanks.
I'm not sure - didn't realise that there actually was a separate Java cache that you could empty.
You're sure there would be nothing to worry about anyway?
|
|
| Back to top |
|
 |
Matt_D
Cadet

 Joined: Apr 22, 2008 Posts: 6 Location: UK
|
Posted: Sun May 04, 2008 12:01 am Post subject: |
|
|
Anyone? 
|
|
| Back to top |
|
 |
PCBruiser
SRT Team Lead
 Forums Admin
 Joined: May 11, 2005 Posts: 11723
|
|
| Back to top |
|
 |
Matt_D
Cadet

 Joined: Apr 22, 2008 Posts: 6 Location: UK
|
Posted: Mon May 05, 2008 8:41 pm Post subject: |
|
|
Hi,
Sorry, but I think you've misread the problem/question
I've already removed an alleged infection using the BitDefender Online Scan, & have since scanned with other online scanners, plus my own Kaspersky etc.
I just want to know if it sounds like it was a real infection or not, & if there is actually anything to worry about...
...Seeing as KIS never previously detected this "Java.Trojan.Exploit.Bytverify" thing, only the BitDefender Online Scan did, plus the BitDefender entry for "Java.Trojan.Exploit.Bytverify" mentions that it exploits a flaw in an old unpatched version of the MS Virtual Machine
|
|
| Back to top |
|
 |
k027
Special Response Team Guest Forums Host

 Joined: Aug 25, 2003 Posts: 8506
|
Posted: Mon May 05, 2008 9:53 pm Post subject: |
|
|
| Quote: | | I just want to know if it sounds like it was a real infection or not |
If you are concerned about a false positive, the only way to check that is to submit the file to the developer of the detecting software or cross-check the detection with other anti-malware programs. If the file has already been removed, there's not much you can do to verify if it in fact was a true or false positive detection.
|
|
| Back to top |
|
 |
|
|