Help with virus removal please

Help with virus removal please

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Help with virus removal please John 08-31-2006
Posted by =?Utf-8?B?Sm9obg==?= on August 31, 2006, 11:03 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Somehow I've gotten a Java Virus.
Running XP home with AVG free, trendmicro anti spy and spybot s&d.
This is what shows up on AVG report.

Application Data/Sun
Java/ByteVerify
Infected Embedded

Trojan horse Java/Class Loader

I was able to move the Byte verify to the virus vault but I can't figure out
how to get rid of the Trojan.
Would removing the Java program and reinstalling it help?
I'm not that computer savy and just noticed it this morning.
All help is appreciated.

Thanks



Posted by David H. Lipman on August 31, 2006, 4:28 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Somehow I've gotten a Java Virus.
| Running XP home with AVG free, trendmicro anti spy and spybot s&d.
| This is what shows up on AVG report.
|
| Application Data/Sun
| Java/ByteVerify
| Infected Embedded
|
| Trojan horse Java/Class Loader
|
| I was able to move the Byte verify to the virus vault but I can't figure out
| how to get rid of the Trojan.
| Would removing the Java program and reinstalling it help?
| I'm not that computer savy and just noticed it this morning.
| All help is appreciated.
|
| Thanks
|

If you are using any version of Sun Java that is prior to JRE Version 5.0 update
6,
then you are strongly urged to remove any/all versions that are prior to JRE/JSE
Version 5.0 update 6. There are vulnerabilities in them and they are actively
being
exploited. It is possible that is how you got infected with malware.

Therefore, it is highly suggested that if there are any prior versions of Sun
Java
to Version 5 update 6 on the PC that they be removed ASAP.

The latest version is Sun Java JRE/JSE Version 5.0 Update 8

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version.

Such as...
C:\Program Files\Java\jre1.5.0_08

http://www.java.com/en/download/manual.jsp

or

http://java.sun.com/javase/downloads/index.jsp


FYI:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102557-1


1) Dump the contents of your IE cache -
Start --> settings --> control panel --> Internet options --> delete
files

2) Dump the contents of the Mozilla FireFox Cache { if you use FireFox }
Tools --> Options --> Privacy --> Cache --> Clear

3) Dump the contents of your Sun Java cache -
Start --> settings --> control panel --> Java applet --> cache --> clear
or
Start --> settings --> control panel --> Java applet --> general -->
settings -->
delete files

4) Re-scan your system using your anti virus software.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by =?Utf-8?B?Sm9obg==?= on August 31, 2006, 7:13 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
David

Thank you for the helpful response.
Followed your instructions.
Deleted temp files in Java
Went into program folders and deleted all but lastest update ver.8.
Went to add remove programs and deleted ver. 4.
Should I delete ver. 6?
Restarted and logged on to safe mode and ran AVG scan and came up no
virus!!!!!!!!!!!
Seems like you were right on target and I can't thank you enough.
Don't want to wear out my welcome but when I ran the scan I noticed a couple
oddities.
Kernel 32 .dll
Shell 32 .dll both showed change rather than ok.

Partition table [MBR]
Boot Sector of disk both showed reading error

Not trying to push my luck just wanted to make sure everything is ok with my
system.

Again
Thank you very much. People like you make this forum worthwile.

John


"David H. Lipman" wrote:

>
> | Somehow I've gotten a Java Virus.
> | Running XP home with AVG free, trendmicro anti spy and spybot s&d.
> | This is what shows up on AVG report.
> |
> | Application Data/Sun
> | Java/ByteVerify
> | Infected Embedded
> |
> | Trojan horse Java/Class Loader
> |
> | I was able to move the Byte verify to the virus vault but I can't figure out
> | how to get rid of the Trojan.
> | Would removing the Java program and reinstalling it help?
> | I'm not that computer savy and just noticed it this morning.
> | All help is appreciated.
> |
> | Thanks
> |
>
> If you are using any version of Sun Java that is prior to JRE Version 5.0
update 6,
> then you are strongly urged to remove any/all versions that are prior to
JRE/JSE
> Version 5.0 update 6. There are vulnerabilities in them and they are actively
being
> exploited. It is possible that is how you got infected with malware.
>
> Therefore, it is highly suggested that if there are any prior versions of Sun
Java
> to Version 5 update 6 on the PC that they be removed ASAP.
>
> The latest version is Sun Java JRE/JSE Version 5.0 Update 8
>
> Simple check, look under...
> C:\Program Files\Java
>
> The only folder under that folder should be the latest version.
>
> Such as...
> C:\Program Files\Java\jre1.5.0_08
>
> http://www.java.com/en/download/manual.jsp
>
> or
>
> http://java.sun.com/javase/downloads/index.jsp
>
>
> FYI:
> http://sunsolve.sun.com/search/document.do?assetkey=1-26-102557-1
>
>
> 1) Dump the contents of your IE cache -
> Start --> settings --> control panel --> Internet options --> delete
files
>
> 2) Dump the contents of the Mozilla FireFox Cache { if you use FireFox }
> Tools --> Options --> Privacy --> Cache --> Clear
>
> 3) Dump the contents of your Sun Java cache -
> Start --> settings --> control panel --> Java applet --> cache -->
clear
> or
> Start --> settings --> control panel --> Java applet --> general -->
settings -->
> delete files
>
> 4) Re-scan your system using your anti virus software.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Posted by David H. Lipman on August 31, 2006, 8:36 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| David
|
| Thank you for the helpful response.
| Followed your instructions.
| Deleted temp files in Java
| Went into program folders and deleted all but lastest update ver.8.
| Went to add remove programs and deleted ver. 4.
| Should I delete ver. 6?
| Restarted and logged on to safe mode and ran AVG scan and came up no
| virus!!!!!!!!!!!
| Seems like you were right on target and I can't thank you enough.
| Don't want to wear out my welcome but when I ran the scan I noticed a couple
| oddities.
| Kernel 32 .dll
| Shell 32 .dll both showed change rather than ok.
|
| Partition table [MBR]
| Boot Sector of disk both showed reading error
|
| Not trying to push my luck just wanted to make sure everything is ok with my
| system.
|
| Again
| Thank you very much. People like you make this forum worthwile.
|
| John
|


The only version of Sun Java left should be the LATEST version.

There should be only one version left on your PC.

Glad to help !

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by karl levinson, mvp on September 1, 2006, 8:53 am
If you were  Registered and logged in, you could reply and use other advanced thread options


> Don't want to wear out my welcome but when I ran the scan I noticed a
> couple
> oddities.
> Kernel 32 .dll
> Shell 32 .dll both showed change rather than ok.
>
> Partition table [MBR]
> Boot Sector of disk both showed reading error
>
> Not trying to push my luck just wanted to make sure everything is ok with
> my
> system.

Viruses very rarely make changes to the MBR and boot sector any more. I
don't know what is causing those read errors, but suspect it is not a virus
and is probably a question for a support forum regarding your AV product.
The same is probably true for the two changed files, but again I'd defer to
a support forum for your AV product.

FYI, you will probably continue to get notices about "java Bytverify." It
is extremely old and only affects Microsoft JVM, not the Sun JVM. If you
have removed the MS JVM, you are safe from it. But your web browser will
still download the infected but harmless bytverify file. Existence of this
file does not prove infection.



Similar ThreadsPosted
Virus Removal November 6, 2008, 8:12 am
Virus/trojan removal July 29, 2006, 3:28 pm
help with Virus removal in system 32 October 11, 2006, 7:02 pm
Removal of norton anti virus software - conflict with 'PC Tools AV April 22, 2006, 4:03 pm
Help with PC removal from listing September 8, 2005, 6:47 pm
Removal of Win32Worfo January 4, 2006, 12:29 am
zlob removal please help August 25, 2007, 7:58 pm
PrcViewer removal October 26, 2007, 4:15 pm
Ad/Spyware removal problem December 28, 2005, 12:29 am
Alfacleaner - Removal questions March 16, 2006, 12:46 am

The site map in XML format XML site map

Contact Us | Privacy Policy