the following viruses where found by avast on me computer last night;
File C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-4378e4d-4aa5fbd2.zip\GetAccess.class is infected by JS:ClassLoader-7 - Deleted
File C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-4378e4d-4aa5fbd2.zip\InsecureClassLoader.class is infected by JS:Exploit-Bytverify-11 - Deleted
File C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-4378e4d-4aa5fbd2.zip\Installer.class is infected by Win32:Trojano-477 [Trj] - Deleted
File C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv255.jar-667ca30e-35a7cc55.zip\Counter.class is infected by JS:Classloader-6 - Deleted
File C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv255.jar-667ca30e-35a7cc55.zip\Parser.class is infected by JS:ClassLoader-5 - Delete:
these have been since deleted.
i run the following programs to help protect me on the net ( iam on b/b) ALL FULLY UPDATED
Avast Home Ed ( fully updated) with resident scanner set on high
Zone alarm free version
spybot
ad-aware
spywareguard
spywareblaster
the only reason avast found the viruses is when i was doing a check with ad-aware, should avast have found these viruses straight away when they come on my computer ( with the standard shield) ?
i have since done two thorough with scan archives selected, and totally clean , do i need to take any more action.
I don’t know what version of windo$e you are using or what flavour of java either … it would appear you are now clear, however you might want to use the search function in the forum and double check your system for any malware. Long involved process but better to be safe than sorry!
Some further research about browser settings and java … permisions might be useful too.
Let us know how you get on.
You will find links here to HijackThis and an online scanner for results of it’s log file.
just go to control panel… then open the java plugin if it’s there and go to the cache tab… click clear cache in the top right corner… then uncheck enable caching.
Logfile of HijackThis v1.97.7
Scan saved at 09:39:36, on 30/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
1] You are using a old version of HJT
2] You do not have your system up-to-date
3] You are using a old version of IE
4] Use my HJT log analazer and the online one.
Be careful what you choose to fix based upon the recommendations of that analyzer. It has recommened to fix MANY legitimate things on my system. Double and triple check other sources for the things it says to fix BEFORE you fix them.
Just wanted to make it clear that it is the ONLINE analyzer that has given me the false positives. I should have been more clear. Sorry about that. No harm intended. I actually haven’t tried Eddy’s analyzer, but I certainly will.
Trying to decipher the initial HT scan report can be confusing and it is easy to remove vital files making things worse and in some cases, users of HT have reported that the computer was put into a compete state of “crash”.
I have used the HTA without incident and have found its’ analysis accurate and easy to follow.