However hard I try.....

  • Thread starter Thread starter TonyIOW
  • Start date Start date

TonyIOW

Guest
....I just can't keep the viruses at bay! :spitfire I'm running AVG free edition, zone alarm and spybot on my pc - which is using Windows media centre operating system.

Today I did an AVG system scan and it told me I've picked up 4 viruses...3 of them are Java\ByteVerify, and the other is Java\openstream. AVG didn't give me the chance to quarantine them and for the life of me I can't find any means of getting rid - either within AVG or by searching on the web.

Can anyone help please? :bow

Thanks, Tony
 
Try this

TonyIOW said:
....I just can't keep the viruses at bay! :spitfire I'm running AVG free edition, zone alarm and spybot on my pc - which is using Windows media centre operating system.

Today I did an AVG system scan and it told me I've picked up 4 viruses...3 of them are Java\ByteVerify, and the other is Java\openstream. AVG didn't give me the chance to quarantine them and for the life of me I can't find any means of getting rid - either within AVG or by searching on the web.

Can anyone help please? :bow

Thanks, Tony

It could be that there are remants of malicious code lurking in the registry and just starts up again. I'm no expert but try this:

Make sure you have absolutely up-to-date anti-virus signatures
Disconnect from the Internet
Switch off your PC
Wait a few seconds for the disk to spin down
Switch PC on again
Run anti-virus to check system
Follow instructions for any "baddies" it picks up
Delete any viruses found
Any that you can't delete follow the anti-virus software links to their web site for additional instructions - follow them to eradicate viruses
If viruses are persistent then use an alternative anti-virus scanner
If possible you should also load and run Spybot or Adaware to keep your system clean of spyware

Hope this helps

Bob
 
Restart your PC and keep pressing the 'F8' key on your keyboard until a menu appears that gives you an option that says 'Safe Mode' and choose that.
Now you're PC will load into a strange looking version of Windows, just bear with it.
When it loads up start your antivirus program and do a scan with it, it should now let you get rid of the problems.
Restart the PC as normal when it has finished


If not, another thing you could try is going to http://windowsupdate.microsoft.com and install all the available updates, this sometimes helps get rid of some problems ;)


Oh and I know I keep saying but if you are running Windows XP then download Windows Defender from www.microsoft.com that's another good help I have found in the past :)
 
Tony,

as SOAA said BUT before you do that turn off system restore. go
control panel > system > system restore
turn it off.
now follow SOAA's instructiions.

once your confident all is clear turn system restore back on again.
this little monkeys hide in the system restore files so they just keep coming back everytime you reboot.

hope thats a bit of a help
 
redcastle said:
Tony,

as SOAA said BUT before you do that turn off system restore. go
control panel > system > system restore
turn it off.
now follow SOAA's instructiions.

once your confident all is clear turn system restore back on again.
this little monkeys hide in the system restore files so they just keep coming back everytime you reboot.

hope thats a bit of a help
Cheers Redcastle I had forgot that :)
 
In addition to all of the above Download Hijackthis
Run it and it will give you a list of everything running
Often you can then mark the offending item for deletion.

If you are unsure, paste the log file on here.
:D
 
Wow, thanks for the quick replies guys. :) Well, I tried all that, but no luck I'm afraid. I turned off system restore, started up in safe mode and did the scan with AVG....sure enough it showed up the viruses but, as in "normal" mode, it doesn't seem to have a means of letting me deal with them. It has a "heal" and "archive" function, but it won't default to doing either of those, and when i highlight the entries in the log, a little message tells me that "selected object is located inside the archive and cannot be healed". When I used Norton AV on an old pc I recall that it used to give a directory of the things and specific instructions for removal....AVG doesn't appear to do that for these ones - but then again, I s'pose I can't complain, 'cos it is free after all!

Anyway, I then downloaded Hijackthis as suggested but could find no ref in the log to the file roots identified in AVG.

Any more suggestions, or is it a case of the dreaded complete format of my hard drive? :(

Thanks again, Tony
 
Here's a few more suggestions:
Microsoft has a patch available for this, you can get the patch from: http://www.microsoft.com/technet/security/bulletin/MS03-011.mspx


Try some of these aswell:
* Go to *c:\windows\.jpi_cache\jar* using windows explorer. delete everything in there. it's just cache, so don't sweat it. voila! i just got rid of it doing that.

* Please visit the following link and see if this could help you: http://securityresponse.symantec.com/avcenter/cgi-bin/virauto.cgi?vid=36538

* I tried all of the methods described and my AVG said I still had the virus. I went to my start button, clicked on accessaries, went to system tools, and performed the disk clean-up. That removed the downloaded program files from the temporary folder, which I believe was the source of the virus. I ran AVG, and it came up clean.

* I recently had this problem on my computer. I went to the link website listed below, and followed the instructions. Haven't had a problem since. http://java.com/en/download/help/cache_virus.jsp

* These malicious applets are designed to exploit vulnerabilities in the Microsoft VM. Here are the instructions on how to manually remove these malicious applets from the JRE cache directory: 1. From the Start button, click Settings > Control Panel. 2.) In the Control Panel, open the "Java Plug-in Control Panel". 3.) Select the Cache Tab. 4.) Click the Clear button inside the Cache Tab, which will clear your JRE cache directory. For users of Windows in Spanish: Ir a Inicio, panel de control, seleccionar vista clásica, doble click en java, seleccionar general, delete temporary files.

* I downloaded AdAware SE and got rid of the java/byteverify. It is free and only takes a few minutes to do. I do not know if it will be a permanent removal or not but I certainly hope so.

* Took a suggestion from your one of the contributors on your site, went to accessories, systems, scan disk and ran the same and pronto the virus was removed. Thank you.

* To remove Java/ByteVerify in Windows XP: 1) Click start, click search, click 'All files and folders'. 2) Click 'more advanced options', and tick the boxes 'search system folders', 'search hidden files and folders', 'search subfolders'. 3) In 'All or part of the file name:' box type blackbox.class, then click 'search' button. 4) In the right hand pane locate the item blackbox.class, right click it, click delete, click OK. Please note the item may appear as blackbox.class or blackBox.class remove each of these entries and both if present.

* Run spysweeper (or any other well established spy remover, etc) in safe mode, as it will run faster and will not crash or stall. (whenever your system is struggling to remove any viruses, adware or spyware, do it in safe mode.

* Here is a handy little program that will help delete any Java-ByteVerify entries. It's small, fast and really helps keep your system clean. Best of all, it's free. It is CCleaner or Crap Cleaner. Find it at http://www.softpedia.com/get/Security/Secure-cleaning/CCleaner.shtml click on options, advanced and untick 'only delete files in Windows Temp folders older than 48 hours.' You will be surprised how much junk it will clean and your system will run better for it.

* Run Ilsystemwiper.my AVG finds java-byteverify from time to time and running ilsystem wiper (free download) works everytime.

* As was stated above I used the program ccleaner to rid my computer of this pest. It was very fast and easy.

* The problem is not just with IE. I got the Java-ByteVerify trojan/virus using Firefox. Doesn't matter on what browser you're on. Even with Firefox you need Java plugins to view most of the sites. Just use a firewall like Zonealarm and updte your XP with SP2. Should prevent most of these malicious worms in the first place.

Also, try switching System Restore off again, reboot your PC normally once and then reboot it again and go into Safe Mode, run a virus scan and hopefully this time it should get rid of the viruses ;)
 
Thanks Jamie - that little lot will keep me out of mischief for a while! I'll work my way through the suggestions tomorrow and report back on how I get on!

Thanks also to everyone else for your help and suggestions, it's very much appreciated.

Tony
 
You dont say where AVG found them, a lot of the Java based stuff is found in temporary internet files (Cache) and deleteing your cache resolves the issue. Also it is very easy to see false posatives in such detection.
 
There's a lot to be said for doing a good clean windows re-install (after a format).

You'll pick up a 250gig USB hard drive for £80-£90 now.......use that for a files/settings and progs backup, then the whole re-install process will only take an hour or so rather than the day it'd normally take to get everything re-installed.

I've got all my install CD's and the progs I want in an 'Install' folder as well, in the order I re-install them in (AVG first always, then Zonealarm, then Firefox and Email, then the rest of Ofice and all the other progs)

It makes life a lot easier not having to shuffle CD's around and having everything in one place....and a fresh install wil always be the fastest :thumb
 
What Fanum said. You can spend forever chasing down virii, trojans etc or you can make a backup (or two to be safe) of all your data and just do a fresh install.

Worked for me.

Adam :)
 
Fanum said:
There's a lot to be said for doing a good clean windows re-install (after a format).

You'll pick up a 250gig USB hard drive for £80-£90 now.......use that for a files/settings and progs backup, then the whole re-install process will only take an hour or so rather than the day it'd normally take to get everything re-installed.

yup, but if you image your shiny new install straight away you can reinstall again in under 10 minutes :thumb

also, if you buy an internal drive, they are only about 50 quid & transfer data faster.
 
Heres the last gasp saloon
Hijack this is recommended but if you still have no joy or find it too difficult download smitrem

http://www.bleepingcomputer.com/files/smitRem.php

follow the read me
its a safe mode jobbie again but ive just sorted three or four machines that were stubborn using it and its powerful medicine.

Its pretty well as fanum and cookie and others said though, nothing like a nice fresh start to liven the old girl up
 
Thanks once again folks...I've worked my way steadily through your various suggestions but I still can't get rid of the bugs. Fortunately my docs etc are well backed up, and I have an external hard drive - so I'm going to go for a format and re-install ....should be relatively painless! Famous last words!!

Tony
 


Back
Top Bottom