Wikiposts
Search

Notices
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Java infection

Thread Tools
 
Search this Thread
 
Old 5th September 2012 | 10:30
  #1 (permalink)  
Thread Starter
 
Joined: Jan 2012
Posts: 2,173
Likes: 0
From: .
Java infection

Just a heads up to say that I've come across several examples on forums recently of adverts being posioned by trojans using the recently found Java exploits. It looks like they've become very common in the last week - an explanation of the background is here
Oracle rushes out patch for critical 0-day Java exploit ? The Register

Most of the ones I've seen have been incorporated into infections created using the Blackhole build-your-own-virus kit.

You can block the exploit by downloading and installing the latest version of the Java VM from java.com: Java + You
The version you need is "Java Runtime Environment 7 Update 7" (or later)
If you already have that installed then thats OK. If you have any other version, uninstall it (if you have multiple versions remove them all) and then install the new version.
Some machines will auto-update, but a lot won't.

This is a real risk and I've seen it on a number of forum sites. I've told the admins on each one but theres not a lot that can be done - users need to make sure their machines are secure.

If you want to see an example of the havoc this vulnerability can create, read Thanks ever so much Java, for that biz-wide rootkit infection ? The Register


Among other things, this exploit is also being used in another industrial espionage attack aimed at Defence Contractors
Chemical biz 'Nitro' hackers use Java to coat PCs in poison ivy ? The Register

Last edited by Milo Minderbinder; 5th September 2012 at 10:43.
Milo Minderbinder is offline  
Reply
Old 5th September 2012 | 11:23
  #2 (permalink)  
Per Ardua ad Astraeus
 
Joined: Mar 2000
Posts: 18,575
Likes: 4
From: UK
As a further caveat, 'El Reg' announced that the 'rushed-out' patch by JAVA had in fact been 'rushed out' too quickly and was flawed! Happy days.
BOAC is offline  
Reply
Old 5th September 2012 | 12:27
  #3 (permalink)  
More bang for your buck
 
Joined: Nov 2005
Posts: 3,513
Likes: 1
From: land of the clanger
'El Reg' announced that the 'rushed-out' patch by JAVA had in fact been 'rushed out' too quickly and was flawed! Happy days.
Yep, totally killed all my webcams that require java, also it cant verify java is installed on my computer.
green granite is offline  
Reply
Old 6th September 2012 | 15:42
  #4 (permalink)  
 
Joined: May 2009
Posts: 52
Likes: 0
From: N Lancs
mmmm

Last week my MSE scan picked up 7 of these infections, and removed them,
yesterday's scan found nowt, and I did the Java update. I do scan with Malwarebytes as well after MSE
txdmy1 is offline  
Reply
Old 6th September 2012 | 16:33
  #5 (permalink)  
Psychophysiological entity
20 Anniversary
 
Joined: Jun 2001
Aviation Qualifications: ATPL
Posts: 3,383
Likes: 169
From: Walton on the Naze Essex.
Mmm . . . worrying. I found I couldn't get rid of Java to start a clean install. What's more, some check they offered said mine was running correctly despite not being able to find it anywhere on the computer.

I'd deleted every folder I could find after the Programs and Features refused to do the job.


Was ver 6.0.240

When I tried to remove it the proper way, the 94mb bit of detritus gives me:


Error 1723 something about a DLL missing to INSTALL the program while I'm trying to rid myself of it.


I wasted more time than I could afford, then abandoned Java.
Loose rivets is offline  
Reply
Old 6th September 2012 | 17:35
  #6 (permalink)  
Thread Starter
 
Joined: Jan 2012
Posts: 2,173
Likes: 0
From: .
install the 30-day trial version of this and see if it can rip it out

Revo Uninstaller Pro - Uninstall Software, Remove Programs easily, Forced Uninstall

otherwise may have to resort to the installer cleanup tool from Microsoft - but thats been officially withdrawn as it has issues with Vista and Win7
Which version of Windows have you got?
Milo Minderbinder is offline  
Reply
Old 6th September 2012 | 17:59
  #7 (permalink)  
Psychophysiological entity
20 Anniversary
 
Joined: Jun 2001
Aviation Qualifications: ATPL
Posts: 3,383
Likes: 169
From: Walton on the Naze Essex.
I'm on W7 Pro


I have to be very careful, not only with my time, but with this machine. I'm on the last leg of the first book, and using the other machines, just for the next few weeks, would be tedious.

So, if it's a threat, I'll have to do it, but it was weeks ago I tried to update Java, and haven't once missed it . . . yet.
Loose rivets is offline  
Reply
Old 6th September 2012 | 18:06
  #8 (permalink)  
 
Joined: Apr 2004
Posts: 373
Likes: 0
From: Civ/HAL/SHY/FYY/PWK/AAS/WAD/AVI/GPT/BZN/BSN/WAD/BAS/FLK/WIT/MND/WAD/WIT/WAD/Civ
NATS AFPEx no longer works on J7

Only works on my laptop which remains on J6v23
unclenelli is offline  
Reply
Old 6th September 2012 | 18:26
  #9 (permalink)  
Thread Starter
 
Joined: Jan 2012
Posts: 2,173
Likes: 0
From: .
I'm seriously tempted to tell my customers to remove it completely
Only real downside I can see is that it would stop Open Office / Libre Office working
Milo Minderbinder is offline  
Reply
Old 6th September 2012 | 18:39
  #10 (permalink)  
Psychophysiological entity
20 Anniversary
 
Joined: Jun 2001
Aviation Qualifications: ATPL
Posts: 3,383
Likes: 169
From: Walton on the Naze Essex.
Milo, by that, do you mean remove Java completely?


I haven't bothered to load Open Office on this one, so I would just have to clean up the detritus at a convenient moment.

I'm hoping the sheer time this has been lingering is an indicator it's inert.
Loose rivets is offline  
Reply
Old 6th September 2012 | 18:49
  #11 (permalink)  
 
Joined: Feb 2009
Posts: 579
Likes: 0
From: Worldwide
Milo, you say the trojans are being snuck in via adverts. What effect does running ad blockers have, if any?
KBPsen is offline  
Reply
Old 6th September 2012 | 19:18
  #12 (permalink)  
Thread Starter
 
Joined: Jan 2012
Posts: 2,173
Likes: 0
From: .
Rivits
thats exactly what I mean
How often do people actually need to run Java programs? Not often. There aren't that many low-level Java apps in the real world - except for downloable games and such like. Possibly better to remove it and remove the risk
And before anyone asks - you don't need the Java VM to run Javascript - thats something completely different

KBPSen
I've only seen the infection when using machines which use IE as web browser, so no real Ad-Blocking capabilty other than the antivirus software (Avast on my laptop)
On my other machines - which run Firefox with No-Script and Adblock Plus I've seen nothing. However that could be coincidence -or due to other protection on those machines (they are well locked down)
Interestingly the initial responses from the Avast forums were that these were false positives - but that was before they were aware of the full implications - and spread - of the problem. The infections started appearing before the information was made public

Last edited by Milo Minderbinder; 6th September 2012 at 19:20.
Milo Minderbinder is offline  
Reply
Old 6th September 2012 | 21:13
  #13 (permalink)  
Administrator
 
Joined: Mar 2001
Aviation Qualifications: PPL
Posts: 8,121
Likes: 686
From: Twickenham, home of rugby
Makes me very glad I rolled back to 1.6 after having application problems with 1.7 as discussed here in June - http://www.pprune.org/computer-inter...pping-out.html

SD
Saab Dastard is offline  
Reply
Old 6th September 2012 | 23:01
  #14 (permalink)  

Official PPRuNe Chaplain
 
Joined: Apr 2001
Posts: 3,498
Likes: 0
From: Witnesham, Suffolk
Originally Posted by unclenelli
NATS AFPEx no longer works on J7

Only works on my laptop which remains on J6v23
Odd. AFPEx works fine on mine, using J7v7.
Keef is offline  
Reply
Old 7th September 2012 | 09:38
  #15 (permalink)  
More bang for your buck
 
Joined: Nov 2005
Posts: 3,513
Likes: 1
From: land of the clanger
As v7 also killed my access to the SDR at http://websdr.ewi.utwente.nl:8901/?volume=0# I've rolled back to v6.
green granite is offline  
Reply

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.