Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

java exploit problem...

 
   Security Forums (Home) -> General Discussions RSS
Next:  Avira AntiVir Question  
Author Message
Uncle Vinnie

External


Since: May 18, 2007
Posts: 7



(Msg. 1) Posted: Fri May 18, 2007 7:46 am
Post subject: java exploit problem...
Archived from groups: alt>comp>anti-virus (more info?)

I am sorry to bother you folks.. I have CA and am at whits end trying to
find out how to contact them for support.. hence, why I hope you can help in
the meantime...

Scans continually identify 6 infected files and Etrust doesn't do anything
about them.. quaratine, delete...
Please tell me, what is my next step?

thank you...


C:\Documents and Settings\HP_Administrator\Application
Data\Sun\Java\Deployment\cache\6.0\1\748d8a81-3bfbac0f <BaaaaBaa.class> -
Java/ByteVerify!exploit trojan. Infected.
C:\Documents and Settings\HP_Administrator\Application
Data\Sun\Java\Deployment\cache\6.0\1\748d8a81-3bfbac0f <VaaaaaaaBaa.class> -
Java/ByteVerify!exploit trojan. Infected.

C:\Documents and Settings\HP_Administrator\Application
Data\Sun\Java\Deployment\cache\6.0\1\748d8a81-3bfbac0f <Baaaaa.class> -
Java/Shinwow.BJ trojan. Infected.

C:\Documents and Settings\HP_Administrator\Application
Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\crtdcghcn.jar-53c7de81-2b53548a.zip
<BaaaaBaa.class> - Java/ByteVerify!exploit trojan. Infected.

C:\Documents and Settings\HP_Administrator\Application
Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\crtdcghcn.jar-53c7de81-2b53548a.zip
<VaaaaaaaBaa.class> - Java/ByteVerify!exploit trojan. Infected.

C:\Documents and Settings\HP_Administrator\Application
Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\crtdcghcn.jar-53c7de81-2b53548a.zip
<Baaaaa.class> - Java/Shinwow.BJ trojan. Infected.


--
B'rgds,

Vinnie

 >> Stay informed about: java exploit problem... 
Back to top
Login to vote
Uncle Vinnie

External


Since: May 18, 2007
Posts: 7



(Msg. 2) Posted: Fri May 18, 2007 8:17 am
Post subject: Re: java exploit problem... [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

I think I got them... I googled, found a little bit about them... applied a
patch to XP, and deleted temporarly Java files, as well as the one crtdc...
jar file (actually 2).. all scans clean...

thanks! Hope I did it right...!

Uncle Vinnie wrote:
> I am sorry to bother you folks.. I have CA and am at whits end trying
> to find out how to contact them for support.. hence, why I hope you
> can help in the meantime...
>
> Scans continually identify 6 infected files and Etrust doesn't do
> anything about them.. quaratine, delete...
> Please tell me, what is my next step?
>
> thank you...
>
>
> C:\Documents and Settings\HP_Administrator\Application
> Data\Sun\Java\Deployment\cache\6.0\1\748d8a81-3bfbac0f
> <BaaaaBaa.class> - Java/ByteVerify!exploit trojan. Infected.
> C:\Documents and Settings\HP_Administrator\Application
> Data\Sun\Java\Deployment\cache\6.0\1\748d8a81-3bfbac0f
> <VaaaaaaaBaa.class> - Java/ByteVerify!exploit trojan. Infected.
>
> C:\Documents and Settings\HP_Administrator\Application
> Data\Sun\Java\Deployment\cache\6.0\1\748d8a81-3bfbac0f <Baaaaa.class>
> - Java/Shinwow.BJ trojan. Infected.
>
> C:\Documents and Settings\HP_Administrator\Application
> Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\crtdcghcn.jar-53c7de81-2b53548a.zip
> <BaaaaBaa.class> - Java/ByteVerify!exploit trojan. Infected.
>
> C:\Documents and Settings\HP_Administrator\Application
> Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\crtdcghcn.jar-53c7de81-2b53548a.zip
> <VaaaaaaaBaa.class> - Java/ByteVerify!exploit trojan. Infected.
>
> C:\Documents and Settings\HP_Administrator\Application
> Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\crtdcghcn.jar-53c7de81-2b53548a.zip
> <Baaaaa.class> - Java/Shinwow.BJ trojan. Infected.

--
B'rgds,

Vinnie

 >> Stay informed about: java exploit problem... 
Back to top
Login to vote
David H. Lipman

External


Since: Jul 04, 2003
Posts: 1719



(Msg. 3) Posted: Fri May 18, 2007 9:07 pm
Post subject: Re: java exploit problem... [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "Uncle Vinnie" <vinrin57.DeleteThis@optonline.not.net>

| I think I got them... I googled, found a little bit about them... applied a
| patch to XP, and deleted temporarly Java files, as well as the one crtdc...
| jar file (actually 2).. all scans clean...
|
| thanks! Hope I did it right...!
|


Yes. You must delete the Java Jars (ZIP type files).


If you are using any version of Sun Java that is prior to JRE Version 6.0,
then you are strongly urged to remove any/all versions.
There are numerous vulnerabilities in them and they are actively being exploited.

It is highly suggested that you update to the latest version which is Sun Java JRE/JSE
Version 6.0 update 1 (jre 6u1)

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version.

Such as...
C:\Program Files\Java\jre1.6.0_01

http://java.sun.com/javase/downloads/index.jsp
http://www.java.com/en/download/manual.jsp

FYI:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102557-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102622-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102729-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102732-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102760-1



--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm
 >> Stay informed about: java exploit problem... 
Back to top
Login to vote
Uncle Vinnie

External


Since: May 18, 2007
Posts: 7



(Msg. 4) Posted: Fri May 18, 2007 9:07 pm
Post subject: Re: java exploit problem... [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Thank you Dave...

1.6.01 is there.. should I delete all the others?? There are 4 folders of
various 1.5 releases??



David H. Lipman wrote:
> From: "Uncle Vinnie" <vinrin57.RemoveThis@optonline.not.net>
>
>> I think I got them... I googled, found a little bit about them...
>> applied a patch to XP, and deleted temporarly Java files, as well as
>> the one crtdc... jar file (actually 2).. all scans clean...
>>
>> thanks! Hope I did it right...!
>>
>
>
> Yes. You must delete the Java Jars (ZIP type files).
>
>
> If you are using any version of Sun Java that is prior to JRE Version
> 6.0,
> then you are strongly urged to remove any/all versions.
> There are numerous vulnerabilities in them and they are actively
> being exploited.
>
> It is highly suggested that you update to the latest version which is
> Sun Java JRE/JSE Version 6.0 update 1 (jre 6u1)
>
> Simple check, look under...
> C:\Program Files\Java
>
> The only folder under that folder should be the latest version.
>
> Such as...
> C:\Program Files\Java\jre1.6.0_01
>
> http://java.sun.com/javase/downloads/index.jsp
> http://www.java.com/en/download/manual.jsp
>
> FYI:
> http://sunsolve.sun.com/search/document.do?assetkey=1-26-102557-1
> http://sunsolve.sun.com/search/document.do?assetkey=1-26-102622-1
> http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1
> http://sunsolve.sun.com/search/document.do?assetkey=1-26-102729-1
> http://sunsolve.sun.com/search/document.do?assetkey=1-26-102732-1
> http://sunsolve.sun.com/search/document.do?assetkey=1-26-102760-1

--
B'rgds,

Vinnie
 >> Stay informed about: java exploit problem... 
Back to top
Login to vote
David H. Lipman

External


Since: Jul 04, 2003
Posts: 1719



(Msg. 5) Posted: Sat May 19, 2007 12:20 am
Post subject: Re: java exploit problem... [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "Uncle Vinnie" <vinrin57 DeleteThis @optonline.not.net>

| Thank you Dave...
|
| 1.6.01 is there.. should I delete all the others?? There are 4 folders of
| various 1.5 releases??
|

Remove ALL old versions from the Control Panel applet "Add/Remove Programs" first.

Then if there are remnants you can delete them manually from...
C:\Program Files\Java

But leave the latest alone; C:\Program Files\Java\jre1.6.0_01


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm
 >> Stay informed about: java exploit problem... 
Back to top
Login to vote
Dennis Schmitz

External


Since: May 19, 2007
Posts: 1



(Msg. 6) Posted: Sat May 19, 2007 10:52 pm
Post subject: Re: java exploit problem... [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:npr3i.2211$TU1.2182@trnddc07...
> From: "Uncle Vinnie" <vinrin57 DeleteThis @optonline.not.net>
>
> | Thank you Dave...
> |
> | 1.6.01 is there.. should I delete all the others?? There are 4 folders
of
> | various 1.5 releases??
> |
>
> Remove ALL old versions from the Control Panel applet "Add/Remove
Programs" first.
>
> Then if there are remnants you can delete them manually from...
> C:\Program Files\Java
>
> But leave the latest alone; C:\Program Files\Java\jre1.6.0_01
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>

Hey Dave,

Trying to remove the old versions of JAVA through the CONTROL PANEL -
ADD/REMOVE list.
Everytime I try, it wants to access the internet and install the old
versions again. Get message that version is already installed.

How do you remove the old versions? I have the new version dl'd and ready to
install.

Thanks, Dennis
 >> Stay informed about: java exploit problem... 
Back to top
Login to vote
David H. Lipman

External


Since: Jul 04, 2003
Posts: 1719



(Msg. 7) Posted: Sun May 20, 2007 2:12 pm
Post subject: Re: java exploit problem... [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "Dennis Schmitz" <dschmitz1.DeleteThis@kc.rr.com>




| Hey Dave,

| Trying to remove the old versions of JAVA through the CONTROL PANEL -
| ADD/REMOVE list.
| Everytime I try, it wants to access the internet and install the old
| versions again. Get message that version is already installed.

| How do you remove the old versions? I have the new version dl'd and ready to
| install.

| Thanks, Dennis


Never let Sun Java auto-update. Do it manually.

Copntrol panel --> Java --> Update
Uncheck teh box for; "Check for updates auto matically"



--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm
 >> Stay informed about: java exploit problem... 
Back to top
Login to vote
Shharkbait

External


Since: Aug 15, 2007
Posts: 3



(Msg. 8) Posted: Wed Aug 15, 2007 12:53 pm
Post subject: Re: java exploit problem... [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

David and Others...
Thanks for all of the great info here. I just found two instances of the
'crtdcghcn.jar' trojan on my machine and will use your advice to clean my
machine.

Please tell tho... What do these trojan do in my system? Have I be
vulerable to password leaks or other problems? Do I need to be worried
about cancelling credit cards and bank accounts?

Thanks for your help!

shharkbait
 >> Stay informed about: java exploit problem... 
Back to top
Login to vote
kurt wismer

External


Since: Jul 04, 2003
Posts: 1562



(Msg. 9) Posted: Wed Aug 15, 2007 8:54 pm
Post subject: Re: java exploit problem... [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Shharkbait wrote:
> David and Others...
> Thanks for all of the great info here. I just found two instances of the
> 'crtdcghcn.jar' trojan on my machine and will use your advice to clean my
> machine.
>
> Please tell tho... What do these trojan do in my system? Have I be
> vulerable to password leaks or other problems? Do I need to be worried
> about cancelling credit cards and bank accounts?

it's not possible to tell from a filename (crtdcghcn.jar is the file
name of a java archive file) what you have or what it does... if your
scanner doesn't detect it then submit it to an anti-virus vendor for
analysis...

--
"it's not the right time to be sober
now the idiots have taken over
spreading like a social cancer,
is there an answer?"
 >> Stay informed about: java exploit problem... 
Back to top
Login to vote
Shharkbait

External


Since: Aug 15, 2007
Posts: 3



(Msg. 10) Posted: Wed Aug 15, 2007 10:57 pm
Post subject: Re: java exploit problem... [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"it's not possible to tell from a filename (crtdcghcn.jar is the file
name of a java archive file) what you have or what it does... if your
scanner doesn't detect it then submit it to an anti-virus vendor for
analysis..."
---------------------------------------
Thanks... In the examples I have seen in this forum and else where, a long
series of numbers and letters follows the 'crtdcghcn.jar', always a
different number sequence... I am hoping to find out if these trojans are
responsible for an excessively large amount of data downloadng into my
system.

Thanks for your input.

Shharkbait
 >> Stay informed about: java exploit problem... 
Back to top
Login to vote
Offbreed

External


Since: Jan 15, 2006
Posts: 98



(Msg. 11) Posted: Thu Aug 16, 2007 6:07 am
Post subject: Re: java exploit problem... [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Shharkbait wrote:
> "it's not possible to tell from a filename (crtdcghcn.jar is the file
> name of a java archive file) what you have or what it does... if your
> scanner doesn't detect it then submit it to an anti-virus vendor for
> analysis..."
> ---------------------------------------
> Thanks... In the examples I have seen in this forum and else where, a long
> series of numbers and letters follows the 'crtdcghcn.jar', always a
> different number sequence... I am hoping to find out if these trojans are
> responsible for an excessively large amount of data downloadng into my
> system.
>

You are trying to find out what that is, right? Nobody needs a child
pornography charge.
 >> Stay informed about: java exploit problem... 
Back to top
Login to vote
David H. Lipman

External


Since: Jul 04, 2003
Posts: 1719



(Msg. 12) Posted: Sun Aug 19, 2007 4:26 pm
Post subject: Re: java exploit problem... [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "Shharkbait" <bob RemoveThis @reece.net>


| Thanks... In the examples I have seen in this forum and else where, a long
| series of numbers and letters follows the 'crtdcghcn.jar', always a
| different number sequence... I am hoping to find out if these trojans are
| responsible for an excessively large amount of data downloadng into my
| system.
|
| Thanks for your input.
|
| Shharkbait
|

If there is a Trojan or exploit code, it is a .CLASS file in the Java Jar which is a ZIP
type file.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm
 >> Stay informed about: java exploit problem... 
Back to top
Login to vote
Shharkbait

External


Since: Aug 15, 2007
Posts: 3



(Msg. 13) Posted: Fri Aug 24, 2007 3:00 pm
Post subject: Re: java exploit problem... [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

I think my system is clean...

Did not find a .class fiel in the Java Jar, nor did I find a .ZIP file...

Thank you for your help...

shharkbait
 >> Stay informed about: java exploit problem... 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Java ByteVerify - detected, but is it a problem ? - System has had an AVG detection of a strain of this via myspace group. A full scan finds infected files in .jar archive (.class, etc)in IE temp files. I've read some old posts about updating to the latest version of Sun Java vs. MS Java and I can do that...

DSO Exploit? - What is DSO Exploit that SpyBot keeps finding and I keep removing?

dso exploit? - Hi. My girlfriend's got dso exploit trouble on her pc. I understand that CW Shredder is the only tool that will get rid of this problem, but I can't find a currently functioning download link that will work for it. Any idea where I can get CW..

DOS Exploit - Has anyone found this when running Spybot? I did and it won't geaux away. How can I permanently get rid of it??? Tdubya

EXPLOIT-- what is this and what do I do - AVG found a virus they call EXPLOIT. It's location is: c\Documents and Settings\My Name\Local Settings\Temporary Internet Files\ContentIE5\OHUJGHAR\ It's filename is: 2_z[1].html I've moved it to the Virus Vault. Does that take care of the..
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]