CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 952
Comments: 28
block bottom
spacer spacer

Java.Trojan.Exploit.Bytverify - gone, but what's the damage?

 
Post new topic   Reply to topic       All -> FavForums -> Catch All - Guests [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Matt_D

Cadet
Cadet


Joined: Apr 22, 2008
Posts: 6
Location: UK

PostPosted: Tue Apr 22, 2008 8:28 pm    Post subject: Java.Trojan.Exploit.Bytverify - gone, but what's the damage?
Reply with quote

Not sure if this is really the correct forum or not, so apologies if it isn't.

Some info:

My PC runs XP SP2, & I use Kaspersky Internet Security 7 (Firewall & AV etc.), Spybot S&D, AdAware, Spywareblaster, cwshredder, & HiJackThis. All are up to date. I also use Firefox with AdBlockPlus & NoScript for web browsing (with IE7 only generally being used for Windows Update).

I tend to do a full My Computer scan with KIS7 every few days or so, with it set to "Maximum", but customised to make it, well, more than Maximum.

On Saturday (IIRC), I performed a few free online scans using BitDefender, Trend Micro Housecall, a squared, & F Secure.

BitDefender claimed it found two java .class files infected with "Java.Trojan.Exploit.Bytverify", somewhere within "C:\Documents and Settings\[My Wife's Profile]\Application Data\Sun\Java\Deployment\cache\".

BD then cleaned it, & the other online scans (after the BD scan/clean) found nothing. A full KIS scan also later found nothing.

She had not used my PC in a week or so, having finally got her new laptop, while the last full KIS scan before this "incident" was only a day or two earlier, & found absolutely nothing.

So, did KIS somehow miss this "Bytverify" thing?

Or could it have been a false positive by BD?


Also, what are the chances of anything dodgy having been done with this "Bytverify" trojan?

Checking it out on Google, it seems it exploits a vulnerability in the Microsoft Virtual Machine, & was discovered in 2003. The exploit was patched in 2003.

http://www.bitdefender.com/site/VirusInfo/showVirusInfo/547

http://secunia.com/advisories/8559/

http://www.microsoft.com/technet/security/bulletin/MS03-011.asp


So... seeing as my PC actually uses the current up to date Sun Java, rather than the MS Virtual Machine, could this "Java.Trojan.Exploit.Bytverify" have done anything anyway?


Do I have anything to worry about?


Any help/advice much appreciated Smile

I don't want to go to the hassle of nuking my PC & changing all passwords for nothing.

Back to top
View users profile Send private message
k027

Special Response Team
Guest Forums Host
Guest Forums Host

Joined: Aug 25, 2003
Posts: 8412

1st Responders SRT

PostPosted: Tue Apr 22, 2008 9:57 pm    Post subject:
Reply with quote

Anti-malware companies are not consistent in how they name various viruses, trojans, etc. Two companies may use different names for the same exploit or the same name for different exploits. To determine the characteristics and possible adverse effects of the malware detected on your computer you need to look at the malware data base for the particular anti-malware program that detected the malware.

Back to top
View users profile Send private message
Matt_D

Cadet
Cadet


Joined: Apr 22, 2008
Posts: 6
Location: UK

PostPosted: Tue Apr 22, 2008 10:07 pm    Post subject:
Reply with quote

The first search result in Google for "Java.Trojan.Exploit.Bytverify" was the link I gave in my first post for Bitdefender.com's description (http://www.bitdefender.com/site/VirusInfo/showVirusInfo/547), and it was BitDefender's online scan that found it.

Back to top
View users profile Send private message
Matt_D

Cadet
Cadet


Joined: Apr 22, 2008
Posts: 6
Location: UK

PostPosted: Sat Apr 26, 2008 11:00 pm    Post subject:
Reply with quote

Does anyone have any ideas/help?

Back to top
View users profile Send private message
Cudni

Special Response Team


Joined: Dec 10, 2002
Posts: 3683
Location: Et In Arcadia ego
MIRT MVP SRT

PostPosted: Sat Apr 26, 2008 11:05 pm    Post subject:
Reply with quote

did you empty java cache? in any case nothing to worry about

Cudni


_________________
Hecho en Mexico
Back to top
View users profile Send private message Visit posters website
Matt_D

Cadet
Cadet


Joined: Apr 22, 2008
Posts: 6
Location: UK

PostPosted: Tue Apr 29, 2008 12:38 am    Post subject:
Reply with quote

Thanks.


I'm not sure - didn't realise that there actually was a separate Java cache that you could empty.


You're sure there would be nothing to worry about anyway?

Back to top
View users profile Send private message
Matt_D

Cadet
Cadet


Joined: Apr 22, 2008
Posts: 6
Location: UK

PostPosted: Sun May 04, 2008 12:01 am    Post subject:
Reply with quote

Anyone? Smile

Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Sun May 04, 2008 5:04 am    Post subject:
Reply with quote

I strongly recommend that you follow CastleCops' Malware Removal and Prevention procedure, a system CastleCops devised to enable users to either partially, or fully clean their systems without the direct aid of an expert.

Please read these instructions carefully. You will find the Malware Removal and Prevention Procedure here:

http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction

If that doesn't fix the problem, then go to this Forum, read the instructions at the top of the page carefully:

CastleCops Link/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html

Follow these instructions:

CastleCops Link/t102301-Hijackthis_Guidelines_Read_Before_Posting.html

and one of CC's trained 1st Responders or Security Experts will help you.

Note to everyone: You must be a CastleCops member to post for help in the HJT forum. Do not post a HJT log anywhere other than in our HJT forum. If you post them here or in other forums, they will be deleted or ignored.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
Matt_D

Cadet
Cadet


Joined: Apr 22, 2008
Posts: 6
Location: UK

PostPosted: Mon May 05, 2008 8:41 pm    Post subject:
Reply with quote

Hi,

Sorry, but I think you've misread the problem/question Smile


I've already removed an alleged infection using the BitDefender Online Scan, & have since scanned with other online scanners, plus my own Kaspersky etc.


I just want to know if it sounds like it was a real infection or not, & if there is actually anything to worry about...

...Seeing as KIS never previously detected this "Java.Trojan.Exploit.Bytverify" thing, only the BitDefender Online Scan did, plus the BitDefender entry for "Java.Trojan.Exploit.Bytverify" mentions that it exploits a flaw in an old unpatched version of the MS Virtual Machine

Back to top
View users profile Send private message
k027

Special Response Team
Guest Forums Host
Guest Forums Host

Joined: Aug 25, 2003
Posts: 8412

1st Responders SRT

PostPosted: Mon May 05, 2008 9:53 pm    Post subject:
Reply with quote

Quote:
I just want to know if it sounds like it was a real infection or not


If you are concerned about a false positive, the only way to check that is to submit the file to the developer of the detecting software or cross-check the detection with other anti-malware programs. If the file has already been removed, there's not much you can do to verify if it in fact was a true or false positive detection.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Catch All - Guests All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer