Computer Gurus, need help

twotonevert

Member of P.E.A.
Moderator
Donating Member
Registered
Also known as: Blackbox Trojan, Exploit-ByteVerify, JS.ByteVerify!exploit, HTML/ByteVerify!exploit, HTML.ByteVerify!exploit , JS/ByteVerify!exploit, Java.ByteVerify!exploit , Java.ByteVerify.exploit, HTML.ByteVerify.exploit, Java/ByteVerify.Exploit.240.Troj, Java ByteVerifyExploit, Java/Shinwow.F.Blackbox.Trojan, Verify

This is what I have, low threat level, but the instructions for removing it do not work. Any help? Please?
banghead.gif
 
This is not a virus, but rather a method to exploit a security vulnerability in the Microsoft Virtual Machine. This vulnerability arises as the ByteCode verifier in the Microsoft Virtual machine does not correctly check for the presence of certain malformed code when a Java applet is loaded. Attackers could exploit this vulnerability by creating malicious Java applets and inserting them into web pages. These web pages could be hosted on a site by a malicious web master, or could be sent to users as an attachment. To read more about this issue, and to download the necessary patches, please visit:

http://www.microsoft.com/technet/security/bulletin/MS03-011.mspx

For more information, or for examples of this exploit in action, please see the description of the following malware (found elsewhere in the encyclopedia):

Java.Shinwow
Note: this detection may be triggered by merely visiting a web page that contains malicious code. It does not necessarily mean your machine has been compromised, nor that your machine is vulnerable to this particular exploit.

-------------------------------------

Removal Instructions
Virus found in the Javaâ„¢ Runtime Environment, Standard Edition (JRE) cache directory

Malicious applets may be detected in the JRE cache directory by your CA antivirus solution. The default installation path for this directory can be seen below:

C:\Documents and Settings\<username>\Application Data\Sun\Java\Deployment\cache\javapi\v1. 0\jar\

These malicious applets are designed to exploit vulnerabilities in the Microsoft VM (for more information on this vulnerability, please see Microsoft Security Bulletin MS03-011).

For more information on these malicious applets and their use, please visit the Sun Microsystems Java Technology Help Knowledgebase here: http://java.com/en/download/help/cache_virus.jsp

Here are the instructions on how to manually remove these malicious applets from the JRE cache directory:

1. From the Start button, click Settings> Control Panel
2. In the Control Panel, open the "Java Plug-in Control Panel"
3. Select the Cache Tab
4. Click the Clear button inside the Cache Tab, which will clear your JRE cache directory
 
Thanks Razor, I cleared the temp files in my Java Console, is that simply all I need to worry about?
 
Also known as: Blackbox Trojan, Exploit-ByteVerify, JS.ByteVerify!exploit, HTML/ByteVerify!exploit, HTML.ByteVerify!exploit , JS/ByteVerify!exploit, Java.ByteVerify!exploit , Java.ByteVerify.exploit, HTML.ByteVerify.exploit, Java/ByteVerify.Exploit.240.Troj, Java ByteVerifyExploit, Java/Shinwow.F.Blackbox.Trojan, Verify

This is what I have, low threat level, but the instructions for removing it do not work. Any help? Please?  
banghead.gif
If you're running XP you have to disable System Restore and then run your anti-virus scan manually.

This is a pretty old virus, so depending on what anti-virus software you're running it should be removing it. If not, try Trend Micro's free scan.
 
Also known as: Blackbox Trojan, Exploit-ByteVerify, JS.ByteVerify!exploit, HTML/ByteVerify!exploit, HTML.ByteVerify!exploit , JS/ByteVerify!exploit, Java.ByteVerify!exploit , Java.ByteVerify.exploit, HTML.ByteVerify.exploit, Java/ByteVerify.Exploit.240.Troj, Java ByteVerifyExploit, Java/Shinwow.F.Blackbox.Trojan, Verify

This is what I have, low threat level, but the instructions for removing it do not work. Any help? Please?  
banghead.gif
If you're running XP you have to disable System Restore and then run your anti-virus scan manually.

This is a pretty old virus, so depending on what anti-virus software you're running it should be removing it. If not, try Trend Micro's free scan.
Thanks George, that did the trick. May have to purchase. Took forever though. I hate hackers!
guns.gif
 
Go get Spy Sweeper with anti-virus works great it's like $30.00 a year. You can download it straight from there web site at www.webroot.com.
+1, I use Spy Sweeper each week, but use Norton Antivirus Corporate...XP Pro (vista sucks), IE7 (config correctly), soft security and hardline firewalls, haven't had a bug in over 5 years...

learn how to protect yourself on the net, everything is going that direction eventually, otherwise get used to
banghead.gif
 
Go get Spy Sweeper with anti-virus works great it's like $30.00 a year. You can download it straight from there web site at www.webroot.com.
+1, I use Spy Sweeper each week, but use Norton Antivirus Corporate...XP Pro (vista sucks), IE7 (config correctly), soft security and hardline firewalls, haven't had a bug in over 5 years...

learn how to protect yourself on the net, everything is going that direction eventually, otherwise get used to  
banghead.gif

clap.gif
 
Booting in "Safe Mode" is usually a good idea for a full AV scan when you know you have an issue..
beerchug.gif



Next time use protection....
rofl.gif
 
also, if you are using XP, go to RUN in your start menu and manually dump your temp files, type %temp%, trash everything there. Also, get rid of all your Prefetch files periodically.

Another way: Make sure you can see all your files, open windows explorer, Tools, Folder options, View, click on Show hidden files and folder. Then, go to C drive, Documents & Settings, (user name), local settings, Temp. Viruses usually unload here because moving to other places. G'luck!
 
Back
Top