Author Topic: Java Malware alert!  (Read 1345 times)

Offline Denholm

  • Plutonium Member
  • *******
  • Posts: 9667
      • No. 603 Squadron
Re: Java Malware alert!
« Reply #15 on: April 17, 2010, 10:15:19 PM »
It effects all versions of Sun's Java runtime, regardless of the OS.  However, the chances of the malware/spyware program being able to run on a Linux box is pretty low as virtually all these types of programs are written for Windows.
Thanks for the clarification.
Get your Daily Dose of Flame!
FlameThink.com
No. 603 Squadron... Visit us on the web, if you dare.

Drug addicts are always disappointed after eating Pot Pies.

Offline Tac

  • Platinum Member
  • ******
  • Posts: 4085
Re: Java Malware alert!
« Reply #16 on: May 01, 2010, 10:31:24 PM »
Yep, I got it... of all things by looking at a webcomic that i've been a fan of for ages. :(

Im having kapersky clean the bugger out.

Offline Tac

  • Platinum Member
  • ******
  • Posts: 4085
Re: Java Malware alert!
« Reply #17 on: May 02, 2010, 04:29:53 AM »
Guess its so new kapersky didnt squash it.

Still, the bugger cant hide.


I got this from an ad banner (which I didnt click.. apparently it loads with the banner image on whatever website you happen to be on).

It starts in the system processes (cntr-alt-del , processes) under 'rundll32'

once it loads it becomes

awwhbbdtssd.exe

and it starts popping up messages above the clock with icons that look like the native windows antivirus system (yellow shield with !) telling you that WINDOWS has detected a trojan infection and to activate your AV.

No matter what you do, the system will refuse to load any programs.. not the antivirus, not the browser.. nothing. It will tell you the .exe file associated with the program is infected ... doing cntr-alt-del will briefly launch the task manager.. then it gets blocked saying tskmngr.exe is infected (lol!)

It does not load itself on windows safe mode...but avirus programs wont catch it there either.

Only way to block it is to stop the rundll file process as windows starts by doing cntr-alt-del while windows is just starting to load...

then you can use windows.

msconfig will show the awwhbbdtssd.exe as a startup program ... and thats where you'll find the folder its hiding in.

in my case it was hiding in 2 locations. on the desktop under:

kaka://c:\documents and settings\administrator\local setings\application data\asojkhanw\awwhbbdtssd.exe/netalert.htm

and of course,

c:\documents and settings\administrator\local setings\application data\asojkhanw\awwhbbdtssd.exe

killed the entire asojkhanw folder, cleaned all cookies, temp files, history, did an extra deep scan with 2 avirus programs I had..

rebooted one last time..

and its gone.

at least... its not blocking my pc no more nor popping up messages.

Offline Eagleclaw

  • Copper Member
  • **
  • Posts: 298
Re: Java Malware alert!
« Reply #18 on: May 02, 2010, 07:25:20 AM »
So from what Im hearing, this thing can get through a firewall pretty easily? If your computer were to get this bug, would something like Sysclean be able to get rid of it? How about Norton, Kaspersky or Malware Remover?
The day no hoes would fly......

Offline DREDIOCK

  • Plutonium Member
  • *******
  • Posts: 17775
Re: Java Malware alert!
« Reply #19 on: May 02, 2010, 10:56:51 AM »
Rkill

I always keep copies of it. Both on my machines and on a flash drive I keep that has security programs on it (Anti malware etc.)

It will not rid your machine of the buggers. but it will end the processes of them so you can clean your machine using your antivirus/malware solution of choice

If you have kids. Or ummm other people who carelessly click on things or go places they ought not to. this is one handly little item

http://www.technibble.com/rkill-repair-tool-of-the-week/
Death is no easy answer
For those who wish to know
Ask those who have been before you
What fate the future holds
It ain't pretty

Offline bravoa8

  • Silver Member
  • ****
  • Posts: 1571
Re: Java Malware alert!
« Reply #20 on: May 02, 2010, 11:29:19 AM »
Thanks skuzzy I don't trust Java anyway I'm fraid I do have it on one of my computers though! :eek:

Offline bravoa8

  • Silver Member
  • ****
  • Posts: 1571
Re: Java Malware alert!
« Reply #21 on: May 02, 2010, 04:46:04 PM »
Thanks skuzzy I don't trust Java anyway I'm fraid I do have it on one of my computers though! :eek:
Hmm I didn't type that right :uhoh So,will I get a virus if my Java updates?

Offline Ghastly

  • Silver Member
  • ****
  • Posts: 1756
Re: Java Malware alert!
« Reply #22 on: May 03, 2010, 03:11:23 PM »
Java Runtime 1.6.0_20 was released in response to this exploit - I hesitate to say it "fixes the issue" given that I don't have first hand knowledge that it does, but it's supposed to.

But this brings us to another caveat - Sun's Java run-time drives me utterly bugnuts, anyway.  Prior to somewhere in the vicinity of 1.60 version 4, it installed new versions without removing the old - and a developer can "request" an older version at run-time.  I've looked at machines that LITERALLY had more than a dozen versions of the runtime. 

Make sure remove all unnecessary older versions via Add/Remove so that the only one listed is the new one.   

And if you need to access a web site and/or run an IE-based widget/add-in

(insert -> another of my pet peeves, if you want to provide an app that I "must" use to access the information your company is providing to mine, then write a #*@* app, don't depend on IE and then tell me that I can't update IE and/or Java until after you rewrite your widget!)

that requires an older version, then I'd urge you to pressure the provider to update their website or widget to no longer be version specific.

<S>
"Curse your sudden (but inevitable!) betrayal!"
Grue

Offline MrRiplEy[H]

  • Persona Non Grata
  • Plutonium Member
  • *******
  • Posts: 11633
Re: Java Malware alert!
« Reply #23 on: May 04, 2010, 08:40:52 AM »
Java Runtime 1.6.0_20 was released in response to this exploit - I hesitate to say it "fixes the issue" given that I don't have first hand knowledge that it does, but it's supposed to.

But this brings us to another caveat - Sun's Java run-time drives me utterly bugnuts, anyway.  Prior to somewhere in the vicinity of 1.60 version 4, it installed new versions without removing the old - and a developer can "request" an older version at run-time.  I've looked at machines that LITERALLY had more than a dozen versions of the runtime. 

Make sure remove all unnecessary older versions via Add/Remove so that the only one listed is the new one.   

And if you need to access a web site and/or run an IE-based widget/add-in

(insert -> another of my pet peeves, if you want to provide an app that I "must" use to access the information your company is providing to mine, then write a #*@* app, don't depend on IE and then tell me that I can't update IE and/or Java until after you rewrite your widget!)

that requires an older version, then I'd urge you to pressure the provider to update their website or widget to no longer be version specific.

<S>


I don't use any products of companies that require the use of java and/or IE. Period.
Definiteness of purpose is the starting point of all achievement. –W. Clement Stone

Offline Ghastly

  • Silver Member
  • ****
  • Posts: 1756
Re: Java Malware alert!
« Reply #24 on: May 05, 2010, 09:07:57 PM »
I wish I had the luxury of making the same choice - but our clients pick the custodians, and we have to use whatever (often crappy) solution the custodian provides.   Some are OK, some hoover scummy pond water....

<S>
"Curse your sudden (but inevitable!) betrayal!"
Grue

Offline Denholm

  • Plutonium Member
  • *******
  • Posts: 9667
      • No. 603 Squadron
Re: Java Malware alert!
« Reply #25 on: May 05, 2010, 09:34:40 PM »
I wish our college would consider some simple scripting reasoning and dump their java online testing center.
Get your Daily Dose of Flame!
FlameThink.com
No. 603 Squadron... Visit us on the web, if you dare.

Drug addicts are always disappointed after eating Pot Pies.