CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Anyone hear of Java Open Stream t ??????

 
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> AntiVir Personal Edition Classic [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
cochise1

Trooper
Trooper


Joined: Dec 07, 2004
Posts: 15
Location: USA

PostPosted: Tue Jan 25, 2005 11:37 am    Post subject: Anyone hear of Java Open Stream t ??????
Reply with quote

Antivir recently detected Java Open Stream t on my pc and I did forward a zip file of it to Germany to tell me if it was a false positive. Avpe came back and said it was a real virus/trojan so I deleted the file.

I have not been able to find any info on it and was curious if anyone out there has heard of it or can supply a link to what it is.

Back to top
View users profile Send private message
mrrockford

News Admin
News Admin
AVPE Host
AVPE Host

Joined: Apr 24, 2004
Posts: 3010

Forums Admin MVP Premium Team F@H

PostPosted: Tue Jan 25, 2005 6:07 pm    Post subject:
Reply with quote

Howdy,

Can you please post the portion of your scan log where this was/is listed. I would like to find more info but can't find anything with the given name.

Another question - at what level is your heuristic scan set to?


_________________
"Anyone who considers protocol unimportant has never dealt with a cat."

L. Long
Back to top
View users profile Send private message Visit posters website
cochise1

Trooper
Trooper


Joined: Dec 07, 2004
Posts: 15
Location: USA

PostPosted: Tue Jan 25, 2005 6:58 pm    Post subject:
Reply with quote

mrrockford wrote:
Howdy,

Can you please post the portion of your scan log where this was/is listed. I would like to find more info but can't find anything with the given name.

Another question - at what level is your heuristic scan set to?


Heuristic set to medium. I will check if I kept the e-mail that I sent which included the log file when I get home later. I have Antivir set to overwrite each log file which maybe I should change to append. I hope I still have the copy in my sent folder so that I can let you take a look at it.

Back to top
View users profile Send private message
mrrockford

News Admin
News Admin
AVPE Host
AVPE Host

Joined: Apr 24, 2004
Posts: 3010

Forums Admin MVP Premium Team F@H

PostPosted: Tue Jan 25, 2005 8:07 pm    Post subject:
Reply with quote

Thanks


_________________
"Anyone who considers protocol unimportant has never dealt with a cat."

L. Long
Back to top
View users profile Send private message Visit posters website
cochise1

Trooper
Trooper


Joined: Dec 07, 2004
Posts: 15
Location: USA

PostPosted: Wed Jan 26, 2005 10:53 am    Post subject:
Reply with quote

cochise1 wrote:
mrrockford wrote:
Howdy,

Can you please post the portion of your scan log where this was/is listed. I would like to find more info but can't find anything with the given name.

Another question - at what level is your heuristic scan set to?


Heuristic set to medium. I will check if I kept the e-mail that I sent which included the log file when I get home later. I have Antivir set to overwrite each log file which maybe I should change to append. I hope I still have the copy in my sent folder so that I can let you take a look at it.


Sorry, but all the data is gone. From what I remember, the directory was c/windows/sun/java/deployment...... and that is as far as I remember. I will be prepared the next time something like that happens.

Back to top
View users profile Send private message
Tbagz

Cadet
Cadet


Joined: Feb 14, 2005
Posts: 3
Location: USA

PostPosted: Mon Feb 14, 2005 7:03 am    Post subject:
Reply with quote

I too just found this virus/Trojin. it is located: C:\Documents and Settings\User\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar

The infected files AVG found are: javainstaller.jar-3cc46f89-680c9792.zip, and : javainstaller.jar-3cc46f89-680c9792.zip\javainstaller\InstallerApplet.class

I have a "program" called Java (TM) Plug-in Control Panel that is in this directroy.....C:\DocumentsandSettings\User\ApplicationData\Sun\Java\Deployment\cache\javapi\v1.0\

Is it this proram? I think it was Downloaded when I was attempting a Speedtest. Any Help would be Great.

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Mon Feb 14, 2005 3:29 pm    Post subject:
Reply with quote

Hi Tbagz,

Welcome to CastleCops. Very Happy

Antivirus companies are the worst for telling people that trojans are viruses. True, some antivirus applications can detect trojans, but trojans are not viruses. They are spywares that can load stuff on your computer for the purpose of using it for their own ends.

Do you use a firewall? Firewalls block most basic trojans automatically. I would suggest this one at this page here: CastleCops Link/downloads-cats-5-10-10.html ZoneAlarm is also a good freeware firewall. It's at the top of this page here in CastleCop's Download Section: CastleCops Link/downloads-cats-5-20-10.html

Quote:
Sygate Personal Firewall
Description: FREE for personal use, Sygate Personal Firewall 5.x provides best of breed security in a user friendly interface, protecting your PC from hackers, trojans and DoS attacks. New features include full-ICS support, protocol driver level protection, enhanced logging, and more. Sygate Personal Firewall is the first FREE personal firewall to offer protection from malicious code intrusions, keeping the information on your PC safe and private. Version: 5.x Filesize: 8.44 MB


It would help to know your operating system, but without it I would advise you to download a trial copy of TrojanHunter. I use this application. It is reasonably priced if you choose to purchase it after 30 days. It is one of the top three anti-trojans in the world. Here is a DIRECT DOWNLOAD LINK for TrojanHunter from CastleCops Downloads. It's compatible with all Windows platforms.

Quote:
TrojanHunter
Description: TrojanHunter searches for and removes trojans from your system. You have the ability to add custom trojan definitions and detection rules. If you are downloading files from the Internet, you need TrojanHunter! Features: High-speed file scan engine capable of detecting modified trojans Memory scanning for detecting any modified variant of a particular build of a trojan Registry scanning for detecting traces of trojans in the registry Inifile scanning for detecting traces of trojans in configuration files Port scanning for detecting open trojan ports The Advanced Trojan Analyzer, an exclusive feature of TrojanHunter, is able to find whole classes of trojans using advanced scanning techniques TrojanHunter Guard for resident memory scanning - detect any trojans if they manage to start up LiveUpdate utility for effortless ruleset updating via the Internet Add custom trojan definitions and detection rules Process list giving details about every running process on the system, including the path to the actual executable file Accurate removal of all detected trojans - even if they are running or if the trojan has injected itself into another process Built-in netstat viewer Extensive help files Free technical support via e-mail. Version: 4.0 Filesize: 5.88 MB


You will need to update it online to get the latest rule-set files. For the trial version you have to do this manually. Full instructions are provided here: http://www.misec.net/trojanhunter/updating/

For Windows XP and 2000 only an excellent freeware anti-trojan called Ewido Security Suite can help you. You can find it on this page at CastleCop's Downloads (3rd one down): CastleCops Link/downloads-cat-6.html

Get one, install it, update it, run it, and let it fix everything it finds. Then let us know?


Best regards


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Mon Feb 14, 2005 3:38 pm    Post subject:
Reply with quote

Note: Tbagz was fixed in the AVG Topics Forum.

This thread is locked. If you want it open contact a moderator.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> AntiVir Personal Edition Classic All times are GMT
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer