Author Topic: Java Byte Verify  (Read 4897 times)

0 Members and 1 Guest are viewing this topic.

ianb

  • Guest
Java Byte Verify
« on: August 22, 2004, 07:39:39 PM »
First of all thanks to Awil for supplying this free software.

I'm using Avast Home (free).  I have run a few tests on the software and find it very good but why can't it seem to detect the Java Byte Verify virus ?

Offline MikeBCda

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2247
Re:Java Byte Verify
« Reply #1 on: August 22, 2004, 08:56:59 PM »
Hi ianb, and welcome to the avast family,

If you have reporting enabled and check the report after the scan, I'll bet you'll find that avast couldn't scan because of a "corrupted archive".  What Sun Java (I presume that's what you're using) calls "zip" files aren't true zips, but use their own oddball compression method.  And that seems to be the favorite target of the byte-verify thing.

I suspect that any infected files that are turning up are probably in your Java cache folders and nowhere else.  Those are easy enough to get rid of, just open your Java control panel and empty the cache.

Hopefully that'll get you cleaned up again.  If it's still turning up afterwards, let us know and someone else should be able to give you additional help.

Best,
Mike
Intel Atom D2700, 2 gig RAM, Win 7 x64 SP1 & IE-11, Firefox 51.0
(default). 320 gig HD, 15Mb DSL, Win firewall, Avast 12.3.2280 free, SpywareBlaster, MBAM Prem., Crypto-Prevent

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:Java Byte Verify
« Reply #2 on: August 22, 2004, 09:50:14 PM »
Avast may have this one under amother name in the vps.
Java.ByteVerify.exploit also known as Blackbox Trojan, Exploit-ByteVerify, HTML.ByteVerify.exploit, Java/ByteVerify.Exploit.240.Troj, Java/Shinwow.F.Blackbox.Trojan, Verify.

It is not a virus.

This is not a virus, but rather a method to exploit a security vulnerability in the Microsoft Virtual Machine. This vulnerability arises as the ByteCode verifier in the Microsoft Virtual machine does not correctly check for the presence of certain malformed code when a Java applet is loaded. Attackers could exploit this vulnerability by creating malicious Java applets and inserting them into web pages. These web pages could be hosted on a site by a malicious web master, or could be sent to users as an attachment.

More about this exploit and the patch can be found HERE

Negeltu

  • Guest
Re:Java Byte Verify
« Reply #3 on: August 22, 2004, 11:07:46 PM »
Mike,

The compressed archives that are in the sun folder aren't zip files.  They are Java Archive Files( JAR) files.  :)

ianb

  • Guest
Re:Java Byte Verify
« Reply #4 on: August 22, 2004, 11:53:21 PM »
Thanks for the replys.  

I run XP SP2 (fully updated), Avast, Zone Alarm, Spy Bot, Ad Aware, Spywareblaster and MYIE2 with pop up blocker enabled  ....... also clean frequently with Absolute Shield Internet Eraser.

I understand that Java Byte Verify is related to the Microsoft VM and am not too worried as I have uninstalled that and put Sun Java in it's place.  I would still like to be warned about it though (if poss) as Norton, Trend etc do.

It was this test (amongst others) that impressed me with Avast http://www.gfi.com/emailsecuritytest/



 

Offline MikeBCda

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2247
Re:Java Byte Verify
« Reply #5 on: August 23, 2004, 03:46:28 AM »
Mike,

The compressed archives that are in the sun folder aren't zip files.  They are Java Archive Files( JAR) files.  :)

Hi Negeltu,

Part of the confusion is that Sun puts things in a zillion different places on the drive -- sounds like their people all learned MS's tactics very thoroughly.  ;)

I agree that Sun uses mostly JAR's -- but in the cache folder (somewhere under Documents & Settings, on XP) it also uses some ZIP's.

Best,
Mike
Intel Atom D2700, 2 gig RAM, Win 7 x64 SP1 & IE-11, Firefox 51.0
(default). 320 gig HD, 15Mb DSL, Win firewall, Avast 12.3.2280 free, SpywareBlaster, MBAM Prem., Crypto-Prevent