Help with virus removal please

Help with virus removal please

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Help with virus removal please John 08-31-2006
Posted by David H. Lipman on September 1, 2006, 2:53 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


|
| Viruses very rarely make changes to the MBR and boot sector any more. I
| don't know what is causing those read errors, but suspect it is not a virus
| and is probably a question for a support forum regarding your AV product.
| The same is probably true for the two changed files, but again I'd defer to
| a support forum for your AV product.
|
| FYI, you will probably continue to get notices about "java Bytverify." It
| is extremely old and only affects Microsoft JVM, not the Sun JVM. If you
| have removed the MS JVM, you are safe from it. But your web browser will
| still download the infected but harmless bytverify file. Existence of this
| file does not prove infection.
|

Karl:

Are you SURE about JS/ByteVerify is NOT exploiting Sun Java ?
There have been some questions about that fact.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by karl levinson, mvp on September 1, 2006, 11:29 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>
>
> |
> | Viruses very rarely make changes to the MBR and boot sector any more. I
> | don't know what is causing those read errors, but suspect it is not a
> virus
> | and is probably a question for a support forum regarding your AV
> product.
> | The same is probably true for the two changed files, but again I'd defer
> to
> | a support forum for your AV product.
> |
> | FYI, you will probably continue to get notices about "java Bytverify."
> It
> | is extremely old and only affects Microsoft JVM, not the Sun JVM. If
> you
> | have removed the MS JVM, you are safe from it. But your web browser
> will
> | still download the infected but harmless bytverify file. Existence of
> this
> | file does not prove infection.
> |
>
> Karl:
>
> Are you SURE about JS/ByteVerify is NOT exploiting Sun Java ?
> There have been some questions about that fact.

Well, I suppose it is possible, but I'd want some validation from an av web
site. As far as I know, for the first few years of its existence, bytverify
was an exploit against an old MS JVM vuln. This site doesn't mention Sun
java in the description, and it seems like bytverify hasn't been updated
since 2003:

www.symantec.com/security_response/writeup.jsp?docid=2003-090514-4048-99&tabid=1

It could probably end up in the Sun Java cache, I would expect.




Posted by David H. Lipman on September 2, 2006, 7:59 am
If you were  Registered and logged in, you could reply and use other advanced thread options


|
| Well, I suppose it is possible, but I'd want some validation from an av web
| site. As far as I know, for the first few years of its existence, bytverify
| was an exploit against an old MS JVM vuln. This site doesn't mention Sun
| java in the description, and it seems like bytverify hasn't been updated
| since 2003:
|
|
www.symantec.com/security_response/writeup.jsp?docid=2003-090514-4048-99&tabid=1
|
| It could probably end up in the Sun Java cache, I would expect.
|

I am seeing the JS/ByteVerify used in Exploits to get the unsuspecting infected
with the
Backdoor.Haxdoor RootKit Trojan and others.

McAfee also indicates Explotation od MSJVM but there are those who have voiced
concerns
about it and Sun Java.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by karl levinson, mvp on September 2, 2006, 10:30 am
If you were  Registered and logged in, you could reply and use other advanced thread options


> McAfee also indicates Explotation od MSJVM but there are those who have
> voiced concerns
> about it and Sun Java.

I'd be surprised if we had gone three years without someone discovering and
confirming this sooner.

Or, if it was a modified virus, I'd be surprised it also matched the
signature for the original Bytverify. Possible, but I'm skeptical.

Could it be that these machines still have MS JVM installed?



Posted by David H. Lipman on September 2, 2006, 10:37 am
If you were  Registered and logged in, you could reply and use other advanced thread options


|
| I'd be surprised if we had gone three years without someone discovering and
| confirming this sooner.
|
| Or, if it was a modified virus, I'd be surprised it also matched the
| signature for the original Bytverify. Possible, but I'm skeptical.
|
| Could it be that these machines still have MS JVM installed?
|

It took tool MowGreen a year and a half just to get Sun to admit there were
vulnerabilities
in older versions Sun Java. It doesn'y surprise me one bit -- anymore.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Similar ThreadsPosted
Virus Removal November 6, 2008, 8:12 am
Virus/trojan removal July 29, 2006, 3:28 pm
help with Virus removal in system 32 October 11, 2006, 7:02 pm
Removal of norton anti virus software - conflict with 'PC Tools AV April 22, 2006, 4:03 pm
Help with PC removal from listing September 8, 2005, 6:47 pm
Removal of Win32Worfo January 4, 2006, 12:29 am
zlob removal please help August 25, 2007, 7:58 pm
PrcViewer removal October 26, 2007, 4:15 pm
winlogoo removal December 25, 2008, 2:24 pm
Ad/Spyware removal problem December 28, 2005, 12:29 am

The site map in XML format XML site map

Contact Us | Privacy Policy