From: " - 781" <
[email protected]>
| RESULTS:
|
| 08/16/2006 13:53:18
|
| Options:
| "C:\" /UNZIP /WINMEM /SUB /ANALYZE /PANALYZE /STREAMS /CLEAN /ALL /DEL /MIME
| /PROGRAM /EXCLUDE C:\AV-CLS\EXCLIST.TXT /HTML
| "C:\AV-CLS\MCAFEE\SCANREPORT.HTML"
|
| Scanning C: [MAIN]
| Scanning C:\*.*
| C:\Documents and Settings\Chaxkal\Application
| Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-5f22f99-372d5264.zip\NEWSECURITYCL
| ASSLOADER.CLASS
| ... Found the Generic Downloader.v trojan !!!
| C:\Documents and Settings\Chaxkal\Application
| Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-5f22f99-372d5264.zip\NEWURLCLASSLO
| ADER.CLASS
| ... Found the Exploit-ByteVerify trojan !!!
| C:\Documents and Settings\Chaxkal\Application
| Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv470.jar-1ab62644-2c7b60a3.zip\DUMM
| Y.CLASS
| ... Found the Exploit-ByteVerify trojan !!!
|
If you are using any version of Sun Java that is prior to JRE Version 5.0 update 5,
then you are strongly urged to remove any/all versions that are prior to JRE/JSE
Version 5.0 update 5. There are vulnerabilities in them and they are actively being
exploited. It is possible that is how you got infected with malware.
Therefore, it is highly suggested that if there are any prior versions of Sun Java
to Version 5 on the PC that they be removed ASAP.
The latest version is Sun Java JRE/JSE Version 5.0 Update 8
Simple check, look under...
C:\Program Files\Java
The only folder under that folder should be the latest version.
Such as...
C:\Program Files\Java\jre1.5.0_08
http://www.java.com/en/download/manual.jsp
or
http://java.sun.com/javase/downloads/index.jsp
1) Dump the contents of your IE cache -
Start --> settings --> control panel --> Internet options --> delete files
2) Dump the contents of the Mozilla FireFox Cache { if you use FireFox }
Tools --> Options --> Privacy --> Cache --> Clear
3) Dump the contents of your Sun Java cache -
Start --> settings --> control panel --> Java applet --> cache --> clear
or
Start --> settings --> control panel --> Java applet --> general --> settings -->
delete files
4) Re-scan your system using the Sophos module of the Multi AV Scanning Tool.