Author Topic: Java update / jucheck.exe  (Read 3273 times)

0 Members and 1 Guest are viewing this topic.

Offline Riddley

  • Newbie
  • *
  • Posts: 6
Java update / jucheck.exe
« on: February 21, 2013, 12:20:16 PM »
I keep getting a pop-up from jucheck.exe (C:\Program Files (x86)\Common Files\Java\Java Update) for updating my java. The issue is that AVAST keeps detecting malware-gen32 issues when doing so. Scanning the exe file with avast indicates the files is clean.

I decided to just bypass the autoupdate and get the newest version of java from http://www.java.com/en/download/windows_xpi.jsp?locale=en, however when attempting to download, AVAST gives an alert listing a file as malware. A windows screen then pops up stating "AppData\Local\Temp\xRwTBONy.exe.part could not be saved, because the source file could not be read."

Can someone help?

Offline NON

  • Japanese User
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1889
Re: Java update / jucheck.exe
« Reply #1 on: February 21, 2013, 01:08:00 PM »
Confirmed, Java online installer is detected as Malware-gen.
Installer itself (downloaded with avast disabled) is not detected. Must be a false positive. :(

Jotti Malware Scan:
http://virusscan.jotti.org/en/scanresult/cbe52e198b9882fedeb00cd9149c851be7fdf313
Main: Win7 SP1 32bit / Core i5 450M 2.4GHz / 4GB RAM / avast! 2015 Premier / COMODO IS 6 (FW/D+/Cloud)
Mobile: Vista SP2 32bit / Core 2 Duo SU9300 1.2GHz / 3GB RAM / avast! 2014 Free / Online Armor Free (FW/PG)

Offline Kwartet!

  • Full Member
  • ***
  • Posts: 175
Re: Java update / jucheck.exe
« Reply #2 on: February 21, 2013, 01:29:38 PM »
Manually installing from java.com results in detection by webshield, see screen capture.

In a previous attempt, fileshield detected BIT2.tmp in my temp directory. According to its log |>UPX threat Wi32:Malware-gen Moved to chest.

Must be something with the filepacker (UPX).

Best regards

EDIT Oehh.., sig is not up to date. O well.
« Last Edit: February 21, 2013, 01:32:48 PM by Kwartet! »
Athlon64x2, 2GB, XPProSP3, 32 bit | Windows Firewall | FF15 sandboxed by Avast, NoScript, TrafficLight, WOT | AIS7.0.1466, EMET, USB-set | MBAM (on-demand)

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 1274
Re: Java update / jucheck.exe
« Reply #3 on: February 21, 2013, 03:11:24 PM »
Hello,
thanks for notice, it should be fixed by stream update.

Milos