<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please in Security</title>
<link>http://www.dslreports.com/forum/r14738275</link>
<description></description>
<language>en</language>
<pubDate>Sun, 29 Nov 2009 05:29:13 EDT</pubDate>
<lastBuildDate>Sun, 29 Nov 2009 05:29:13 EDT</lastBuildDate>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,15013800</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Time to bump this thread again.  I'm still seeing a LOT of folks who have older version of Sun Java still on their systems.!  Please update your Sun Java and be sure to remove ALL older versions!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15013800</guid>
<pubDate>Tue, 13 Dec 2005 17:10:27 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14934884</link>
<description><![CDATA[<A HREF="/useremail/u/190996"><b>JackCam614</b></A> : Hey  CalamityJane <A HREF="/useremail/u/679515"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>,<br><br>I realize I'm just a wee bit 'late to the game' on this topic, but I just had to add my Sincere Thanks for all of your invaluable help with this Sun Java mess.<br><br>Thanks to you, I am now running only Version 1.5.0_06, and have removed via Ad/remove Programs 3 older versions, including the dangerous 1.4.2_03.<br><br>Hugs and Regards,<br>...<br>:)Jack]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14934884</guid>
<pubDate>Fri, 02 Dec 2005 19:14:24 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14926812</link>
<description><![CDATA[<A HREF="/useremail/u/307212"><b>Fox2</b></A> : I had 3 on 2 computers]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14926812</guid>
<pubDate>Thu, 01 Dec 2005 18:42:46 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14926174</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  jbob <A HREF="/useremail/u/996768"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>See this thread of what it looks like to have the older versions installed to see what is left over from updating.<br><br>&raquo;<A HREF="/forum/remark,14922663#14925977">Updating JAVA - MS/Sun</A><br> </DIV>Right!  The update doesn't uninstall any old versions.  You HAVE to go to the Control Panel and look in Add/remove programs and uninstall each one ...keeping the latest, of course.  Most people don't realize they have often more than one older version on there.  I think one poster in this long thread had like 5 versions on there he didn't know about.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14926174</guid>
<pubDate>Thu, 01 Dec 2005 17:21:53 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14926011</link>
<description><![CDATA[<A HREF="/useremail/u/996768"><b>jbob</b></A> : See this thread of what it looks like to have the older versions installed to see what is left over from updating.<br><br>&raquo;<A HREF="/forum/remark,14922663#14925977">Updating JAVA - MS/Sun</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14926011</guid>
<pubDate>Thu, 01 Dec 2005 16:59:36 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14925949</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  Justakiwi <A HREF="/useremail/u/1113801"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Many thanks!  :)<br> </DIV>You're quite welcome.  Let us know if you have any problems.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14925949</guid>
<pubDate>Thu, 01 Dec 2005 16:49:30 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14925884</link>
<description><![CDATA[<A HREF="/useremail/u/1113801"><b>Justakiwi</b></A> : <div class="bquote"><SMALL>said by  CalamityJane <A HREF="/useremail/u/679515"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><div class="bquote"><SMALL>said by  Justakiwi <A HREF="/useremail/u/1113801"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Error no:0x80040703<br>Failed to find dll function:ActPanel.IsJava2Netscape6Default<br><br>Any other way I can uninstall this? :huh: <br><br></DIV>&raquo;<A HREF="http://java.sun.com/products/archive/j2se/1.4.0_04/install-windows.html" >java.sun.com/products/archive/j2&middot;&middot;&middot;ows.html</A><br>This page has instructions under *Troubleshooting the Installation* about that error on that version of Sun Java and how to uninstall it.<br> </DIV>Many thanks!  :)<BR><br><SMALL>--<br>"You are never given a dream without also being given the power to make it true" ~ Richard Bach</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14925884</guid>
<pubDate>Thu, 01 Dec 2005 16:40:16 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14925446</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  Justakiwi <A HREF="/useremail/u/1113801"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Error no:0x80040703<br>Failed to find dll function:ActPanel.IsJava2Netscape6Default<br><br>Any other way I can uninstall this? :huh: <br><br></DIV>&raquo;<A HREF="http://java.sun.com/products/archive/j2se/1.4.0_04/install-windows.html" >java.sun.com/products/archive/j2&middot;&middot;&middot;ows.html</A><br>This page has instructions under *Troubleshooting the Installation* about that error on that version of Sun Java and how to uninstall it.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14925446</guid>
<pubDate>Thu, 01 Dec 2005 15:38:56 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14925395</link>
<description><![CDATA[<A HREF="/useremail/u/1113801"><b>Justakiwi</b></A> : <div class="bquote"><SMALL>said by  CalamityJane <A HREF="/useremail/u/679515"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><div class="bquote"><SMALL>said by  3SGTE <A HREF="/useremail/u/247350"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Here's mine.<br> </DIV>Those are all older verisons.  You need to update to the latest and get rid of those old ones. (Especially those old 1.4.2 versions!)<br> </DIV>I've installed the latest version but I still have an old 1.4.0_01 version showing up in Add/Remove Programs. I've tried to uninstall it but I get the following error:<br><br>Error no:0x80040703<br>Failed to find dll function:ActPanel.IsJava2Netscape6Default<br><br>Any other way I can uninstall this? :huh: <br><br><SMALL>It <B>is</B> still installed - it's not just one of those "still showing in Add/Remove Programs even though it's already been uninstalled" situations.<BR><br><SMALL>--<br>"You are never given a dream without also being given the power to make it true" ~ Richard Bach</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14925395</guid>
<pubDate>Thu, 01 Dec 2005 15:31:26 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14925109</link>
<description><![CDATA[<A HREF="/useremail/u/307212"><b>Fox2</b></A> : CJ,<br><br>I am here everyday, I am just not a big talker *lol*.<br><br>Anyway at work I already warned collegues..this forum will have a few lurkers more I guess *s*<br><br>Jake]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14925109</guid>
<pubDate>Thu, 01 Dec 2005 14:51:54 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14925087</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Hi Jake!  {{{Hugs}}} back.  And thanks for spreading the word! :)  Good to see you here!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14925087</guid>
<pubDate>Thu, 01 Dec 2005 14:48:26 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14924904</link>
<description><![CDATA[<A HREF="/useremail/u/307212"><b>Fox2</b></A> : Geez, thanks to this topic I installed the latest version of java AND uninstalled/removed the previous versions :)<br><br>Big HUG for C.Jane and thank you for All of yet again teaching me something.<br><br>I will spread the word around in Belgium (well my family and friends to start with *lol*<br><br>thanks<br><br>Jake]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14924904</guid>
<pubDate>Thu, 01 Dec 2005 14:23:02 EDT</pubDate>
</item>

<item>
<title>Re: Vulnerabilities with Sun Java</title>
<link>http://www.dslreports.com/forum/remark,14921537</link>
<description><![CDATA[<A HREF="/useremail/u/1140294"><b>Blackbird</b></A> : <div class="bquote"><SMALL>said by  caffeinator <A HREF="/useremail/u/1141361"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br> I'm a bit confused as to how that can be. As I post this, I'm running an old Celeron 366, 192Mb RAM, with Win98SE.</DIV> Well... because my dinosaur is older than your dinosaur? Version 1.5.0 has to be installed on Win98SE or higher... I (and a few not-yet extinct others) still run Win98FE. That leaves us with 1.4.2 versions - currently still max'd at 1.4.2_10 as of tonite. ;)<br><SMALL>--<br>If God wanted us to work with electrons, He'd make them big enough to see...</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14921537</guid>
<pubDate>Thu, 01 Dec 2005 01:05:56 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14920570</link>
<description><![CDATA[<A HREF="/useremail/u/601147"><b>H2OuUp2</b></A> : ava Runtime Environment Version 5.0 Update 5 Here.<br><br>I did about two months ago notice I had three versions installed, and uninstalled all but the most current one.  Now I will really watch it.<br><br>Thanks!<br><SMALL>--<br>He is no fool who gives up what he cannot keep, to gain what he cannot loose.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14920570</guid>
<pubDate>Wed, 30 Nov 2005 22:46:58 EDT</pubDate>
</item>

<item>
<title>Re: Vulnerabilities with Sun Java</title>
<link>http://www.dslreports.com/forum/remark,14920351</link>
<description><![CDATA[<A HREF="/useremail/u/1141361"><b>caffeinator</b></A> : <div class="bquote"><SMALL>said by  Blackbird <A HREF="/useremail/u/1140294"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>At least it's encouraging that those of us with old Windows versions who cannot upgrade to Java 1.5 can at least get updated 1.4.2 versions (the latest I think is 1.4.2_10) and then dump the lower revisions.<br> </DIV>I'm a bit confused as to how that can be.<br><br>As I post this, I'm running an old Celeron 366, 192Mb RAM, with Win98SE.<br><br>I have no problems with Version 1.5.0 (build 1.5.0_06-b05) that just updated now from the old 1.5.0_04.<br><br>I originally got the Java 1.4 with Opera, then have used the Control Panel to run updates as I find them needed.<br><br>Am I just lucky? Or why wouldn't nearly any computer be able to run 1.5 if I can on this ancient box?<br><br>*edit*<br><br>I did have to manually go in and remove the old Update 4 after updating to the latest using the installer..you'd think they would have a smarter installer than that.<br><br>-CaFF<br><SMALL>--<br>"Only two things are infinite, the universe and human stupidity, and I'm not sure about the former." - A. Einstein</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14920351</guid>
<pubDate>Wed, 30 Nov 2005 22:19:56 EDT</pubDate>
</item>

<item>
<title>Re: Vulnerabilities with Sun Java</title>
<link>http://www.dslreports.com/forum/remark,14909737</link>
<description><![CDATA[<A HREF="/useremail/u/1140294"><b>Blackbird</b></A> : Interesting... but it <B>still</B> doesn't address uninstalling the vulnerable old versions. :(<br>At least it's encouraging that those of us with old Windows versions who cannot upgrade to Java 1.5 can at least get updated 1.4.2 versions (the latest I think is 1.4.2_10) and then dump the lower revisions.<br><SMALL>--<br>If God wanted us to work with electrons, He'd make them big enough to see...</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14909737</guid>
<pubDate>Tue, 29 Nov 2005 17:47:51 EDT</pubDate>
</item>

<item>
<title>Vulnerabilities with Sun Java</title>
<link>http://www.dslreports.com/forum/remark,14909698</link>
<description><![CDATA[<A HREF="/useremail/u/1127059"><b>TK421</b></A> : Another FYI found today that I thought I'd share...<br><br><div class="bquote"><A HREF="http://secunia.com/advisories/17748/">Sun Java JRE Sandbox Security Bypass Vulnerabilities</A><br><br>Secunia Advisory: SA17748 Print Advisory  <br>Release Date: 2005-11-29<br><br>Critical: Highly critical<br>Impact: System access<br>Where: From remote<br>Solution Status: Vendor Patch<br><br><B>Software:</B><br>Sun Java JDK 1.5.x<br>Sun Java JRE 1.3.x<br>Sun Java JRE 1.4.x<br>Sun Java JRE 1.5.x / 5.x<br>Sun Java SDK 1.3.x<br>Sun Java SDK 1.4.x<br><br><B>Description:</B><br>Some vulnerabilities have been reported in Sun Java JRE (Java Runtime Environment), which can be exploited by malicious people to compromise a user's system.<br><br><B>Solution:</B><br>Update to the fixed versions.<br><br>JDK and JRE 5.0:<br>Update to JDK and JRE 5.0 Update 4 or later.<br>&raquo;<A HREF="http://java.sun.com/j2se/1.5.0/download.jsp" >java.sun.com/j2se/1.5.0/download.jsp</A><br><br>SDK and JRE 1.4.x:<br>Update to SDK and JRE 1.4.2_09 or later.<br>&raquo;<A HREF="http://java.sun.com/j2se/1.4.2/download.html" >java.sun.com/j2se/1.4.2/download.html</A><br><br>SDK and JRE 1.3.x:<br>Update to SDK and JRE 1.3.1_16 or later.<br>&raquo;<A HREF="http://java.sun.com/j2se/1.3/download.html" >java.sun.com/j2se/1.3/download.html</A></DIV>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14909698</guid>
<pubDate>Tue, 29 Nov 2005 17:40:34 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14907282</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  brjoon1021 <A HREF="/useremail/u/1248499"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br> do I just go through the add/romve programs in the control panel, reboot then install the newer version ? <br> </DIV>Yes, that's it! :)  No need to hunt for an uninstaller.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14907282</guid>
<pubDate>Tue, 29 Nov 2005 12:25:29 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14907209</link>
<description><![CDATA[<A HREF="/useremail/u/1248499"><b>brjoon1021</b></A> : forgive me for a dumb question:<br><br>I have JSE 5.0 update 4. To uninstall this one before upgrading to JSE 5.0 update 5. do I just go through the add/romve programs in the control panel, reboot then install the newer version ? Or... as is often the case, do I have to do a registry hunt or a web hunt for someone's "complete uninstall tool" ?<br><br>Thanks,<br><br>B.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14907209</guid>
<pubDate>Tue, 29 Nov 2005 12:14:54 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14906913</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : No problem Ciderdrinker,<br><br>Yes, there are some Universities having problems with the multiple versions needed, I just hope the software that needs it isn't the 1.4.2x versions as those seem to be the ones being exploited by Vundo/Virtumonde.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14906913</guid>
<pubDate>Tue, 29 Nov 2005 11:34:15 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14906906</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : listen to your gut instinct<br>&raquo;<A HREF="http://www.majorgeeks.com/download4158.html" >www.majorgeeks.com/download4158.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14906906</guid>
<pubDate>Tue, 29 Nov 2005 11:33:16 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14905222</link>
<description><![CDATA[<A HREF="/useremail/u/956054"><b>Ciderdrinker</b></A> : :o<br><br>Oops ... I voted before I realised it was "people who HAVE been infected". I went for "I haven't got 1.4.2_03" - & that was the only one that I've got.<br><br>It wasn't so much a security thing, as a nightmare with WebCT chat/ Question Mark Perception & more than one version of Java. Working in a University, we invariably ended up with more than one version - and having two played havoc with software that I have to support. <br><br>So, at home I have always disabled the autoupdate, & also uninstalled before installing the new one. <br><br>We have also complained to Sun about the lack of uninstalling - I'm sure that we aren't the only University who have problems with WebCT and/ or Perception and Java versions. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14905222</guid>
<pubDate>Tue, 29 Nov 2005 02:53:37 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14904919</link>
<description><![CDATA[<A HREF="/useremail/u/1295512"><b>Nirvana8</b></A> : Can a mod please pin this thread??<br><br>CalamityJane, I've done dozens of these Vundo logs over at Aumha (MowGreens home) and every one so far has Sun J2SE 1.4.2_03 installed, example:  <A HREF="http://aumha.net/viewtopic.php?t=16897&sid=3443c41d2ec3c53d03003bf93cb120ff">http://aumha.net/viewtopic.php?t=16897&sid=3443c41d2ec3c53d03003bf93cb120ff</A> <br><br>I'm using SpySweeper (lazy) to get rid of it at the moment as it seems to do the job well, any reason to stick with Atribune's fix rather?<br><br>Also, have you posted at SWI about this vulnerability as I don't see anyone there advising to uninstall the earlier versions/deleting Java folder/updating?<br><br>Best Regards, Nirvana.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14904919</guid>
<pubDate>Tue, 29 Nov 2005 01:14:06 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14892773</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Time to *bump* this topic again...we're still seeing victim's of Vundo with the old Sun Java version installed.<br>&raquo;<A HREF="/forum/remark,14892267">Need help with Virtumonde....</A><br><br>Reminder to <B>Update your Sun Java folks and remember to remove all older vulnerable versions!</B><br><br>@ MowGreen <A HREF="/useremail/u/1293091"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>, good to see you here!  Welcome to DSLR :)<br>Have you tried contacting Sun again? (maybe with a link to this thread as proof of your theory about Vundo and old Sun Java versions)?  With over 7,600 views and 150 replies they may want to take a look at this...or I can just keep bumping it as often as necessary to get the word out.<br><br>Oh, and people who have been victims of Vundo due to older Sun Java feel free to leave your comments for Sun on this page in the "feedback" section :)<br>&raquo;<A HREF="http://www.java.com/en/download/faq/index_general.xml" >www.java.com/en/download/faq/ind&middot;&middot;&middot;eral.xml</A><br><br>They are still recommending people keep the older versions....grrrrr! :o<br><br>I just left my comment:   <BLOCKQUOTE><SMALL>quote:</SMALL><HR>See this thread about older versions of Sun Java left on systems leaving folks vulnerable to the new Vundo infection in droves:<br>&raquo;<A HREF="/forum/remark,14738046">Potential Vulnerability with Sun Java auto update</A><HR></BLOCKQUOTE><br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14892773</guid>
<pubDate>Sun, 27 Nov 2005 13:29:44 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14868443</link>
<description><![CDATA[<A HREF="/useremail/u/1163332"><b>maximusqb</b></A> :   Hey thanks jfly for the link it was very helpful.  I didn't know I could clear the jre cache like that.  These days it seems like we have to be much more security conscious than in the past.  I am getting in the habit of being more cautious.  I have just started using a limited account as much as possible hoping this will add to my security measures along with the usual collection of apps like a firewall, antivirus, antispyware apps and the like.<br>  My buddy just got some virus from aol instant mesenger the other day which took him a while to get rid of.  Still not sure why he insists on using aol as he has an adelphia account and still pays aol at the same time.  I asked him why he still keeps aol and he said he wouldn't know what to do without his aol.  Guess he is into the whole aol communtity thing lol.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14868443</guid>
<pubDate>Wed, 23 Nov 2005 16:09:18 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14864277</link>
<description><![CDATA[<A HREF="/useremail/u/1127059"><b>TK421</b></A> : <div class="bquote"><SMALL>said by  maximusqb <A HREF="/useremail/u/1163332"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I had js2e 5.0 update 4 installed and yesterday norton antivirus 2005 found this: \Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-5aa0b436-56abd334.zip is infected with the Trojan.ByteVerify virus. <br><br>I removed the file and the next norton scan came up clean, then I went to the kaspersky online scanner and that came up clean too so I guess I got rid of it.  I just installed update 5 after uninstalling the old version.  I also got rid of old restore points too.  anyone know anything about this trojan.byteverify virus from the norton site it seems to be a low threat so hopefully i don't have to worry too much about it.<br> </DIV>&raquo;<A HREF="http://java.com/en/download/help/cache_virus.xml" >java.com/en/download/help/cache_virus.xml</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14864277</guid>
<pubDate>Wed, 23 Nov 2005 02:11:09 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14864272</link>
<description><![CDATA[<A HREF="/useremail/u/1127059"><b>TK421</b></A> : There's no good reason to keep 'em all, vulnerable or not. Dump the old versions.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14864272</guid>
<pubDate>Wed, 23 Nov 2005 02:09:18 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14864269</link>
<description><![CDATA[<A HREF="/useremail/u/1244598"><b>BigPoppa44</b></A> :  I have the following Sun Java Versions on my WinXp SP2 system: J2SE Runtime Environment 5.0 Update 1, Update 2, Update 3, Update 4 and Update 5. Does anyone know is there any vulnerability with having updates 1-4 of this version of Sun Java on my system or should I delete Updates 1-4 and just keep Update 5.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14864269</guid>
<pubDate>Wed, 23 Nov 2005 02:07:06 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14863798</link>
<description><![CDATA[<A HREF="/useremail/u/1163332"><b>maximusqb</b></A> : I had js2e 5.0 update 4 installed and yesterday norton antivirus 2005 found this: \Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-5aa0b436-56abd334.zip is infected with the Trojan.ByteVerify virus. <br><br>I removed the file and the next norton scan came up clean, then I went to the kaspersky online scanner and that came up clean too so I guess I got rid of it.  I just installed update 5 after uninstalling the old version.  I also got rid of old restore points too.  anyone know anything about this trojan.byteverify virus from the norton site it seems to be a low threat so hopefully i don't have to worry too much about it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14863798</guid>
<pubDate>Wed, 23 Nov 2005 00:09:29 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14862802</link>
<description><![CDATA[<A HREF="/useremail/u/1162456"><b>fatdcuk</b></A> : Well all i can see around the HJT forums is one heck of a lot of Winfixer/Vundo infections with the early version of Sun Java showing up in the *HJT logs,its got to be one of the most prolific exploits recently:( and needs as much publicity as possible to stem the tide.<br><br>*HJT show the most recent version of Sun Java installed and not if the vulnerable versions are also installed unfortunetly.<br><br>Great catch CJ,WTG Gal:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14862802</guid>
<pubDate>Tue, 22 Nov 2005 17:44:22 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14862389</link>
<description><![CDATA[<A HREF="/useremail/u/1293091"><b>MowGreen</b></A> : Sun speaks with a forked tongue in regards to removing older, vulnerable versions of their JRE. From their last Security Bulletin on <B>Vulnerability With Java Runtime Environment May Allow Untrusted Applet to Elevate Privileges</B><br>&raquo;<A HREF="http://sunsolve.sun.com/search/document.do?assetkey=1-26-101749-1&searchclause=%22category:security%22%20%22availability,%20security%22%20category:security" >sunsolve.sun.com/search/document&middot;&middot;&middot;security</A><br><BLOCKQUOTE>Note: <B>It is recommended that affected versions be removed from your system.</B> For more information, please see the installation notes on the respective java.sun.com download pages.</BLOCKQUOTE><br>From &raquo;<A HREF="http://www.java.com/en/download/faq/5000070400.xml" >www.java.com/en/download/faq/5000070400.xml</A><br><BLOCKQUOTE>Can I remove older versions of the JRE after installing a newer version?<br><br>It is recommended that you keep older versions of the JRE on your system. If you are running low on disk space, you can uninstall older versions of the JRE.</BLOCKQUOTE> <br><br>Pathetic. Why can't they at <B>least</B> give one straight answer ?:mad:]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14862389</guid>
<pubDate>Tue, 22 Nov 2005 16:49:25 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14854577</link>
<description><![CDATA[<A HREF="/useremail/u/537492"><b>antiserious</b></A> :  <br>... not to hijack the thread, but this version (1.5.0_05) was the MOST difficult to install I've ever had ... I removed and installed 3 times, finally had to use THEE admin account (even my normally-used admin account would not work) and allow IT to create the folder (it rejected every folder I made, under any account, with that goofy 1722 error) ...<br> <br>... I hate wrestling with software installs, it really makes me question the product's integrity and security ... and it seems Sun has some fubar'd web pages as well ...<br> <br>... anyway, thanks for the heads-up Jane ... I REALLY hope there's not another one for a while, but I'm suspicious now ...<br> <br><SMALL>--<br>... "Do You Know Where Your Towel Is ?" ...</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14854577</guid>
<pubDate>Mon, 21 Nov 2005 17:27:18 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14854045</link>
<description><![CDATA[<A HREF="/useremail/u/1140294"><b>Blackbird</b></A> : I'm curious... for us few dinosaurs out here still running older Windows versions that cannot use the Java 5.0 family, is Sun's "latest" 1.4.2_10 version also deemed by our resident gurus to still be a risk for these infections if that is all that we have installed? :huh:<br><SMALL>--<br>If God wanted us to work with electrons, He'd make them big enough to see...</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14854045</guid>
<pubDate>Mon, 21 Nov 2005 16:07:11 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14852843</link>
<description><![CDATA[<A HREF="/useremail/u/580201"><b>phriday613</b></A> : Adding my thumbs up to this topic.<br><br>Informed others about this. Im going to keep a close eye on this.<br><br>Thanks!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14852843</guid>
<pubDate>Mon, 21 Nov 2005 13:18:25 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14845873</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : Anyway, my problem's solved, and thanks CJ and Cudni for the suggestions.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14845873</guid>
<pubDate>Sun, 20 Nov 2005 12:03:44 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14845864</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : That would be<br>&raquo;<A HREF="http://www.java.com/en/download/faq/5000070400.xml" >www.java.com/en/download/faq/5000070400.xml</A><br><br>Or close to it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14845864</guid>
<pubDate>Sun, 20 Nov 2005 12:02:06 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14845651</link>
<description><![CDATA[<A HREF="/useremail/u/247350"><b>3SGTE</b></A> : Thanks, Done!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14845651</guid>
<pubDate>Sun, 20 Nov 2005 11:24:21 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14845586</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Hi dandelion!  Unfortunately they still do have a FAQ page recommending keeping old versions (which is the <I>other</I> thing we griped about they said they would address...I guess not).  Anyway, that's dangerous because those older versions are vulnerable if you happen to hit a website using that exploit, it will call up that older version of Sun Java and *poof* you're exploited.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14845586</guid>
<pubDate>Sun, 20 Nov 2005 11:10:46 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14845570</link>
<description><![CDATA[<A HREF="/useremail/u/805291"><b>dandelion</b></A> : Thanks for the information, I had kept one of the older ones and have since uninstalled it. I believe at one point, Sun Java had recommended keeping an old one due to the new one building off the older one (sorry, no longer have the link for that recommendation).<br><SMALL>--<br><A HREF="http://www.bbrteamhelix.net/">want to know what I'm doing? </A><A HREF="http://dandelion.mortalcity.com/">dandelion's place</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14845570</guid>
<pubDate>Sun, 20 Nov 2005 11:06:21 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14845554</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  3SGTE <A HREF="/useremail/u/247350"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Here's mine.<br> </DIV>Those are all older verisons.  You need to update to the latest and get rid of those old ones. (Especially those old 1.4.2 versions!)<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14845554</guid>
<pubDate>Sun, 20 Nov 2005 11:02:59 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14845489</link>
<description><![CDATA[<A HREF="/useremail/u/247350"><b>3SGTE</b></A> : Here's mine.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/14845489?c=926355&ret=L2ZvcnVtL3IxNDczODI3NS54bWw%3D"><IMG TITLE="14123 bytes" BORDER=0 WIDTH=413 HEIGHT=65 SRC="/r0/download/926355~746ac3fe2bf33c3a0a07b05a23c46e47/java.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14845489</guid>
<pubDate>Sun, 20 Nov 2005 10:45:50 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14845009</link>
<description><![CDATA[<A HREF="/useremail/u/1058031"><b>Zennest</b></A> : Thanks for the warning. I had old version installed my computer (J2SE 1.4.2_03).  I am just curious, do we really need Java? :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14845009</guid>
<pubDate>Sun, 20 Nov 2005 08:31:33 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14844773</link>
<description><![CDATA[<A HREF="/useremail/u/631004"><b>Telly Boot</b></A> : Yes, I've rebooted and every possible re... I can think of. I'm going to do some more research, but I don't want to divert further from CJ's original excellent target, which was the 'old version hoarding' of the Sun Java updates being a hidden security risk.<br><SMALL>--<br>Dawn,n,The time when men of reason go to bed. (Ambrose Bierce.)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14844773</guid>
<pubDate>Sun, 20 Nov 2005 05:18:13 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14844266</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : Excerpt<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/14844266?c=926270&ret=L2ZvcnVtL3IxNDczODI3NS54bWw%3D"><IMG TITLE="17239 bytes" BORDER=0 WIDTH=460 HEIGHT=140 SRC="/r0/download/926270~535345019272aa8f02303cf8f067d9c5/box1.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14844266</guid>
<pubDate>Sun, 20 Nov 2005 01:25:20 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14844252</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : Have you rebooted your machine since you downloaded Version 5.0 update 5?<br><br>My machine defaulted to it because i didn't reboot.<br><br>Try that, then run the tests.  <br><br>(And the Java pages say you only have to recycle the browser!  see next post for excerpt)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14844252</guid>
<pubDate>Sun, 20 Nov 2005 01:23:42 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14844219</link>
<description><![CDATA[<A HREF="/useremail/u/631004"><b>Telly Boot</b></A> : <div class="bquote"><SMALL>said by  mdoc1 <A HREF="/useremail/u/1291360"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Test result box<br> </DIV>Microsoft Corp. 1.1.4 is the Microsoft ( obsolete) Java. My machine was defaulting to it, despite having the control panel box ticked as you showed. I spent quite a bit of time trying to get the Sun Java to run, and even posted a thread on the subject a year ago, with no solution found. However my Homer Simpson method of using an obsolete tool to remove an obsolete MS Java component now causes my machine to default to an MS prompt when I go to the speed test check: to download the obsolete version which page/download does not exist. So much for that cunning workaround. I'm running Win2K, and everything has always been fully patched. Perchance I should finally upgrade to XP and that will deal with it. (Grumble! )<br><SMALL>--<br>Dawn,n,The time when men of reason go to bed. (Ambrose Bierce.)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14844219</guid>
<pubDate>Sun, 20 Nov 2005 01:16:44 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14843903</link>
<description><![CDATA[<A HREF="/useremail/u/1140294"><b>Blackbird</b></A> : <div class="bquote"><SMALL>said by  jig <A HREF="/useremail/u/279131"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>the apps i've heard about tend to be interdepartmental form submission and database access apps. like a college's contracts and grants system for accounting... so, each computer in the contracts and grants division needs to have the appropriate jre installed, but they also use those computers for personal and general surfing... </DIV> If one simply must continue using security-vulnerable apps software on a high-importance computer, it becomes critically important to seal that software off from exploitation from the outside world. In your example, as a first protective measure, that probably means blocking all Internet usage from those old-Java-containing computers. There's serious risk in mixing "business with browsing" on mission-critical platforms anyway. One should also assure that the main network itself is protected as much as possible against infection that could attack elsewhere and spread over the network to exploit old Java on these critical computers. I'd consider blocking all old java folders on each affected computer from being shared or accessed over the network - but, of course, that would present operational problems if the software needing to invoke the old Java is on a remote network machine.<br><br>In the end, the safest path is probably to rewrite the relevant code modules to be version-neutral and upgrade the computers to immune Java versions. That may be costly to the school... but running the risk of chronic infections of the Winfixer/Vundo/Virtumonde variety can be even more costly.<br><SMALL>--<br>If God wanted us to work with electrons, He'd make them big enough to see...</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14843903</guid>
<pubDate>Sun, 20 Nov 2005 00:00:26 EDT</pubDate>
</item>

<item>
<title>Version of Java???</title>
<link>http://www.dslreports.com/forum/remark,14843826</link>
<description><![CDATA[<A HREF="/useremail/u/122916"><b>amysheehan</b></A> : Please disregard....dup....<br><br>:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14843826</guid>
<pubDate>Sat, 19 Nov 2005 23:47:51 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14843764</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : Cudni:<br><br>Your URL worked after I rebooted my machine (I never rebooted in all this time).<br><br>&raquo;<A HREF="/speedtest?test=1">/speedtest?test=1</A><br><br>I discovered the need to reboot after I found the Java checkbox in the Advanced tab of Internet Options in IE.  It said, "Use JRE 1.5.0_05 for (requires restart)"  <br><br>When I saw that, I rebooted and your URL gave the correct results.<br><br>But the verification page at the Java site STILL FAILED.  The Java people I assume already knows this, as indicated in their FAQ, which says they are investigating.<br><br>For the benefit of everyone here: The correct current version is JRE 1.5.0_05 as indicated in the Internet Options box.  For the Add/Remove box, it should say JRE (normal users version) or J2SE (developer's version) Runtime Environment version 5.0 upgrade 5.<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/14843764?c=926226&ret=L2ZvcnVtL3IxNDczODI3NS54bWw%3D"><IMG TITLE="52671 bytes" BORDER=0 WIDTH=406 HEIGHT=459 SRC="/r0/download/926226~9a5ac6bb5ba971bc6b19e1f3e05f6f87/box3.jpg"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/14843764?c=926227&ret=L2ZvcnVtL3IxNDczODI3NS54bWw%3D"><IMG TITLE="11188 bytes" BORDER=0 WIDTH=403 HEIGHT=123 SRC="/r0/download/926227~53ec64cbc220535fce8159187ae5e91e/box4.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14843764</guid>
<pubDate>Sat, 19 Nov 2005 23:36:09 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14843704</link>
<description><![CDATA[<A HREF="/useremail/u/638673"><b>kruser</b></A> : CJ,<br>I've always wondered about this!<br><br>Adobe Acrobat was the same in Add/Remove, it always had the older versions listed but I think they have fixed that.<br><br>Thanks for the info!<br>I had two after I updated to the most current.<br><br>I would have had many more but I'd recently done a clean install of XP.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14843704</guid>
<pubDate>Sat, 19 Nov 2005 23:25:28 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14843481</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : Test result box<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/14843481?c=926195&ret=L2ZvcnVtL3IxNDczODI3NS54bWw%3D"><IMG TITLE="23422 bytes" BORDER=0 WIDTH=464 HEIGHT=229 SRC="/r0/download/926195~b1ebb536890c69432446070805f3947b/box2.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14843481</guid>
<pubDate>Sat, 19 Nov 2005 22:39:06 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14843470</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : And THEN after I tried to "Get Java" (see above post) I get the page for downloading version 5.0 upgrade 5 software.  I attempted it anyway, and I get that same verification test page again, but THIS time with a different result, saying i do NOT have version 5.0 upgrade 5!  See the box.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14843470</guid>
<pubDate>Sat, 19 Nov 2005 22:37:39 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14843435</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : Yes but this is the result:<br><br>it shows i have a version different than the JRE installed in Install/Remove box!<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/14843435?c=926188&ret=L2ZvcnVtL3IxNDczODI3NS54bWw%3D"><IMG TITLE="7474 bytes" BORDER=0 WIDTH=350 HEIGHT=90 SRC="/r0/download/926188~535345019272aa8f02303cf8f067d9c5/box1.jpg"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14843435</guid>
<pubDate>Sat, 19 Nov 2005 22:31:21 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14843346</link>
<description><![CDATA[<A HREF="/useremail/u/917630"><b>Cudni</b></A> : Does this one, verification test, works<br>&raquo;<A HREF="/speedtest?test=1">/speedtest?test=1</A><br><br>Cudni<br><SMALL>--<br>.. ....nothing but a well informed optimist</BR>Help yourself so God can help you</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14843346</guid>
<pubDate>Sat, 19 Nov 2005 22:16:40 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14843342</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : Telly try this test routine:<br>www.java.com/en/download/help/testvm.xml<br><br>This page shows the verification failure problem is being investigated by Java people, and the cause of the failure is unknown:<br>&raquo;www.java.com/en/download/help/50000413..]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14843342</guid>
<pubDate>Sat, 19 Nov 2005 22:16:21 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14843323</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : Yes CJ that's easy... I have J2SE runtime environment 5.0 update 5<br><br>That's all the JRE I have installed, and the the online test routine (that you and I gave URLs for) fails the verification test.<br><br>As for the site dropping the cookie, I dunno if that's the problem or not.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14843323</guid>
<pubDate>Sat, 19 Nov 2005 22:12:39 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14843155</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Hi Telly Boot,<br><br>I swear I have read your post 5 times and I still am clueless.  Microsoft put out a patch on their version which protects folks still using that one, but since you used a removal tool for it that I'm not familiar with at all, I wish I could help but I don't know what's the problem really.<br>Maybe something to do with this statement at the MajorGeeks link you posted?<br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Editors Note: The MSJVM Removal Tool is no longer hosted on Microsoft download servers. Because the MSJVM Removal Tool affects the whole system, and because these effects are not reversible, it was decided that this utility would be made available only to system administrators, to network administrators, and to other IT professionals. Unless you just found this<HR></BLOCKQUOTE><br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14843155</guid>
<pubDate>Sat, 19 Nov 2005 21:42:51 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14841863</link>
<description><![CDATA[<A HREF="/useremail/u/631004"><b>Telly Boot</b></A> : I'm having the same problem as MDOC, in that it is installed, and I have the little icon (blue coffee cup) but it isn't verified by Sun's tester, -nor can I run a Speed Test.<br>I tried the 'control panel > Java > advanced' tip by Corinne to see if that would help, but that didn't work. My machine appeared to be defaulting to the old MSVM 'Java' and this is something I tried to fix a year ago- but gave up. So, yes, I had four or five Sun Java versions installed as a result of carefully updating...! This time I knew to remove them and...tracked down the old MS Java removal tool ( MS don't support it any more) here:<br>&raquo;<A HREF="http://www.majorgeeks.com/download.php?det=4158" >www.majorgeeks.com/download.php?det=4158</A><br>and manually removed MSJVM.<br>However I wouldn't recommend this action since my machine now prompts me to get java- since it and Sun detect none- despite having installed and re-installed the latest Sun Java version. I guess I have to go in and remove the last vestiges of MSJVM, since they don't make it any more- and so it can't be reinstalled.<br>Oh Well, at least I don't have any vulnerable versions...DOH!<br>So my question would be, ( and sorry for this diversion) if a machine insists on running the old MSJVM and won't run the Sun Java, is that 'resident' MSJVM still a vulnerability - on top of the old Java "updates" ?<br>Edit: running IE, and yes, got the Sun cookie.<br><SMALL>--<br>Dawn,n,The time when men of reason go to bed. (Ambrose Bierce.)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14841863</guid>
<pubDate>Sat, 19 Nov 2005 17:48:35 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14841773</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  Duchess44 <A HREF="/useremail/u/502781"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>How do we scan for this?  Is there a program like antivirus or something?<br> </DIV>The vulnerability you mean?  Just look in Add/Remove programs to see what versions you have installed.  Get rid of any versions older than the latest 5.0 update 5.<br><br>If you mean scan for Vundo infection, many Antivirus Antispyware AntiTrojan programs detect it, but most are not able to remove it on an already infected computer.<br><br>As one poster above noted, SpySweeper is able to remove it on an infected PC.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14841773</guid>
<pubDate>Sat, 19 Nov 2005 17:33:00 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14841749</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : As for the test page not working, it's probably just as easy to look in your Control Panel under Add/Remove programs and verify what versions you have installed there.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14841749</guid>
<pubDate>Sat, 19 Nov 2005 17:28:54 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14841712</link>
<description><![CDATA[<A HREF="/useremail/u/279131"><b>jig</b></A> : <div class="bquote"><SMALL>said by  mdoc1 <A HREF="/useremail/u/1291360"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>I think rather there is something wrong with the test routine in the page.  Yes, I am using IE and ActiveX is enabled. </DIV> just to add, i believe you also need to allow the site to drop a cookie on you. i'm running pretty tight here and i'm hesitant to test against my own setup, sorry.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14841712</guid>
<pubDate>Sat, 19 Nov 2005 17:23:56 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14841016</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : I have 1.5.0_04 and it says ITS THE LATEST<br><br>Oh well]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14841016</guid>
<pubDate>Sat, 19 Nov 2005 15:20:16 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14840496</link>
<description><![CDATA[<A HREF="/useremail/u/502781"><b>Duchess44</b></A> : How do we scan for this?  Is there a program like antivirus or something?<br><SMALL>--<br>&raquo;<A HREF="http://fofantasy.com" >fofantasy.com</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14840496</guid>
<pubDate>Sat, 19 Nov 2005 13:44:45 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14840481</link>
<description><![CDATA[<A HREF="/useremail/u/502781"><b>Duchess44</b></A> : I have version 1.5.0_05.  I believe this is the latest one.<br>RObin<br><SMALL>--<br>&raquo;<A HREF="http://fofantasy.com" >fofantasy.com</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14840481</guid>
<pubDate>Sat, 19 Nov 2005 13:42:29 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14840470</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : The response to feedback here is probably better than at Java.  :p]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14840470</guid>
<pubDate>Sat, 19 Nov 2005 13:40:41 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14840440</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : Nice little feedback box there.. I think a lot people should provide some feedback there.. It might actually get them to <B>do something</B> about this and fix the darned updater...<br><SMALL>--<br>Lost in Texas</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14840440</guid>
<pubDate>Sat, 19 Nov 2005 13:36:21 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14840422</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : And THIS one actually recommends that you *keep* the older versions of JRE.  And this is a *new* addition to their FAQ!  :hmm:<br><br>Edited:<br><br>go here and click on the first FAQ entry which is marked new:<br><br>&raquo;<A HREF="http://www.java.com/en/download/faq/index_general.xml" >www.java.com/en/download/faq/ind&middot;&middot;&middot;eral.xml</A><br><br>(the entry says:<br>"Can I install the older version of the JRE after installing a newer version?  new")]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14840422</guid>
<pubDate>Sat, 19 Nov 2005 13:32:12 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14840385</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : Nope, that's the one that failed.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14840385</guid>
<pubDate>Sat, 19 Nov 2005 13:23:57 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14840363</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Try this one.<br>&raquo;<A HREF="http://www.java.com/en/download/windows_automatic.jsp" >www.java.com/en/download/windows&middot;&middot;&middot;atic.jsp</A><br><br>It works for me (just tested it) :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14840363</guid>
<pubDate>Sat, 19 Nov 2005 13:20:26 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14840311</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : I think rather there is something wrong with the test routine in the page.  Yes, I am using IE and ActiveX is enabled.<br><br>This other page tells me my JVM part of the software works!<br>&raquo;<A HREF="http://www.java.com/en/download/help/testvm.xml" >www.java.com/en/download/help/testvm.xml</A><br><br>The above link ultimately came from this link, given by a BBR member here:<br>&raquo;<A HREF="http://www.javatester.org/installing.html" >www.javatester.org/installing.html</A><br><br>But this page shows the problem is being investigated by Java people, and the cause of the failure is unknown:<br>&raquo;<A HREF="http://www.java.com/en/download/help/5000041300.xml" >www.java.com/en/download/help/5000041300.xml</A><br><br>And it also shows a link to the very JVM test page that verified the JRE software for me.  <br><br>Ah, well.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14840311</guid>
<pubDate>Sat, 19 Nov 2005 13:06:57 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14840160</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  mdoc1 <A HREF="/useremail/u/1291360"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>...and when i do this, it just sits for 20 seconds and then up pops another page saying the software is not detected.<br>  </DIV>It might be that you are not using IE?  And you need to allow scripts to run and ActiveX for it to detect.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14840160</guid>
<pubDate>Sat, 19 Nov 2005 12:34:23 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14840113</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : CJ, the verification test I'm referring to is in this page:<br><br>&raquo;<A HREF="http://www.java.com/en/download/installed.jsp" >www.java.com/en/download/installed.jsp</A><br><br>...which, if you have the software installed, will show this text:<br><br>JAVA SOFTWARE for Your Computer<br><br>VERIFY YOUR JAVA SOFTWARE INSTALLATION<br><br>If you have recently completed your Java software installation, please ensure that you have completed the steps detailed in the installation instructions, including restarting your browser before testing your installation. <br><br>To test your installation, please click the "Verify Installation" button.<br> <br>[Verify Installation]<br><br>...and when i do this, it just sits for 20 seconds and then up pops another page saying the software is not detected.<br> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14840113</guid>
<pubDate>Sat, 19 Nov 2005 12:27:00 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14840035</link>
<description><![CDATA[<A HREF="/useremail/u/658312"><b>danny9</b></A> : Thanks Calamity Jane, once again for your help and concern in helping others.<br>I don't have Java installed at this time but always learn alot from your posts.<br>It's nice and comforting knowing there are people like you always willing to help.<br>You are amazing!<br><SMALL>--<br>To Think or not to Think: That is the real question. VoicePulse 07/29/04</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14840035</guid>
<pubDate>Sat, 19 Nov 2005 12:12:23 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14840031</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  mdoc1 <A HREF="/useremail/u/1291360"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br> Failed verification again.<br> </DIV>Not sure what you mean by failed verification.  What is the exact message you are getting?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14840031</guid>
<pubDate>Sat, 19 Nov 2005 12:11:57 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14839962</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : Three "oops" in rapid succession... that's pretty good :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14839962</guid>
<pubDate>Sat, 19 Nov 2005 11:58:43 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14839898</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : Spoke too soon.  After the successful verification test, I removed all previous versions of JRE.  Then retested the verification.  That failed.  I removed the JRE 5.0, then re-installed.  Failed verification again.<br><br>Any recommendation?<br><br>I don't really need Java; I can live without it.  I've seen the JRE website contents and the structure alone reflects a very messy management mindset to their software.  Utter confusion.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14839898</guid>
<pubDate>Sat, 19 Nov 2005 11:47:55 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14839642</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  mdoc1 <A HREF="/useremail/u/1291360"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>  All is well now.  </DIV>Glad to hear it, mdoc :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14839642</guid>
<pubDate>Sat, 19 Nov 2005 11:00:41 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14839530</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : Oops, again.  It failed because I didn't restart my browser.  All is well now.  <br><br> <br><br> ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14839530</guid>
<pubDate>Sat, 19 Nov 2005 10:38:57 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14839391</link>
<description><![CDATA[<A HREF="/useremail/u/1291360"><b>mdoc1</b></A> : Oops, I have 3 versions, each one 300MB:<br><br>Java Runtime Environment, SE v1.4.2_03<br>Java Runtime Environment, SE v1.4.2_05<br>Java Runtime Environment, SE v1.4.2_06<br><br>And I've been infected with a strain of winfixer (named Winfixer 2005, created Sept '05, and this did not have the usual BHO MSEvents line in HijackThis log).  I just removed it last week successfully with Spy Sweeper (trial version); this was a one-step process.<br><br>And i just tried to install JRE 5.0 Update 5, it installed successfully but the test (onsite on JRE website) that tests for presence of JRE 5.0 failed.  <br>Thanks.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14839391</guid>
<pubDate>Sat, 19 Nov 2005 10:07:15 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14839131</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  mers2 <A HREF="/useremail/u/974615"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br> Has there been any response from Sun on this issue?  <br> </DIV>No response except for the one back in February where they acknowledged older vulnerable versions on a PC could be a risk for infection.  They still have not responded to the recent request for what progress they have made to correct the issue. <br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14839131</guid>
<pubDate>Sat, 19 Nov 2005 09:08:12 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14838799</link>
<description><![CDATA[<A HREF="/useremail/u/279131"><b>jig</b></A> : the apps i've heard about tend to be interdepartmental form submission and database access apps. like a college's contracts and grants system for accounting...<br><br>there are tons of rules involved, and the original development took a long time, and the developers tended to not write things in compartmentalized ways, partially due to the very customized nature of the app, partially due to naivete.<br><br>so, each computer in the contracts and grants division needs to have the appropriate jre installed, but they also use those computers for personal and general surfing... and as far as i know there is no way to selectively block access to specific versions of java. i think that would be the ideal situation for groups such as these, to have a tool where they could deny access to older versions of java except when interacting with x. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14838799</guid>
<pubDate>Sat, 19 Nov 2005 06:46:22 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14838308</link>
<description><![CDATA[<A HREF="/useremail/u/1140294"><b>Blackbird</b></A> : <div class="bquote"><SMALL>said by  Dude111 <A HREF="/useremail/u/853361"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br> Why would anyone leave a previous version installed once they upgrade???? ... </DIV> I think the link  nirvansk815 <A HREF="/useremail/u/413587"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> provided earlier in the thread answers that question, albeit only very generally: <br>&raquo;<A HREF="http://www.java.com/en/download/faq/5000070400.xml" >www.java.com/en/download/faq/5000070400.xml</A><br><br>Because Sun Java operates in a broad digital universe, they're probably concerned that app or applet coding dependent on the specifics of some older version of Java will break if that old version and its files are removed from the host computer... and they don't want to take flak for breaking it.<br><br>So the challenge seems to be to convince Sun that the exploitation risks of retaining old Java versions on a computer outweigh the risks of breaking some legitimate app/applet by removing them. It would probably help all of us a lot to understand what such "breakable" apps might include - and whether their breakage mechanisms use valid Java coding techniques in the first place. <br><SMALL>--<br>If God wanted us to work with electrons, He'd make them big enough to see...</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14838308</guid>
<pubDate>Sat, 19 Nov 2005 01:59:00 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14837564</link>
<description><![CDATA[<A HREF="/useremail/u/853361"><b>Dude111</b></A> : I have 1.5.0_04 :)<br><br>Why would anyone leave a previous version installed once they upgrade???? They are so big,i always ditch the old one (To save space on my disk)<br><br>If your unsure of your version numba,you can <A HREF="http://www.javatester.org/version.html"><U>Click here</U></A> to find out :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14837564</guid>
<pubDate>Fri, 18 Nov 2005 23:12:50 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14837531</link>
<description><![CDATA[<A HREF="/useremail/u/974615"><b>mers2</b></A> : If I'm not doing the work on the computer myself, I am now telling people to ignore Sun's instructions and uninstall every prior version on their box before installing the current update.  Has there been any response from Sun on this issue?  <br><SMALL>--<br>God put me on this Earth to accomplish a certain number of things. Right now, I am so far behind I will never die.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14837531</guid>
<pubDate>Fri, 18 Nov 2005 23:07:31 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14826229</link>
<description><![CDATA[<A HREF="/useremail/u/590688"><b>psloss</b></A> : Thanks for posting about this, by the way, CalamityJane.  Gonna have to be on the lookout for this now.<br><br>Philip Sloss<br><SMALL>--<br>Feedback? e-mail: stuff@lupwa.org</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14826229</guid>
<pubDate>Thu, 17 Nov 2005 13:18:00 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14826160</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Thanks for the info and confirm CajunTek.<br><br>I just finished another Vundo infection in this thread:<br>&raquo;<A HREF="/forum/remark,14814560">Virtumundo.c HJT Log</A><br><br>He had two versions of Sun Java.<br>J2SE Runtime Environment 5.0 Update 5<br><B>Java 2 Runtime Environment, SE v1.4.2_05</B> <br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14826160</guid>
<pubDate>Thu, 17 Nov 2005 13:09:02 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14821985</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : <div class="bquote"><SMALL>said by  CalamityJane <A HREF="/useremail/u/679515"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Glad to hear it goalieskates!  :)  Remember to uninstall old versions after an update too.<br><br>Ok folks, here is yet another Vundo/Winfixer infectee with older versions of Java installed underneath the most current version:<br>&raquo;<A HREF="/forum/remark,14816218">HJT Log: Win Fixer/Virtumondo problem?</A><br>Java 2 Runtime Environment SE v1.4.2.06<br>J2SE Runtime Environment 5.0 Update 2<br>J2SE Runtime Environment 5.0 Update 5 <br><br>SunMicrosystems really needs to FIX this! :mad:<br> </DIV>Yep CJ I've now seen 5 just like that.. all with uptodate java in front :) and all the old version hiding in the back..:huh:<br><SMALL>--<br>Lost in Texas</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14821985</guid>
<pubDate>Wed, 16 Nov 2005 21:06:28 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14820308</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Glad to hear it goalieskates!  :)  Remember to uninstall old versions after an update too.<br><br>Ok folks, here is yet another Vundo/Winfixer infectee with older versions of Java installed underneath the most current version:<br>&raquo;<A HREF="/forum/remark,14816218">HJT Log: Win Fixer/Virtumondo problem?</A><br>Java 2 Runtime Environment SE v1.4.2.06<br>J2SE Runtime Environment 5.0 Update 2<br>J2SE Runtime Environment 5.0 Update 5 <br><br>SunMicrosystems really needs to FIX this! :mad:<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14820308</guid>
<pubDate>Wed, 16 Nov 2005 17:20:40 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14816214</link>
<description><![CDATA[<A HREF="/useremail/u/1075487"><b>goalieskates</b></A> : Just another thank you, Calamity Jane. I had several previous versions installed. All gone now! :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14816214</guid>
<pubDate>Wed, 16 Nov 2005 07:06:15 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14806711</link>
<description><![CDATA[<A HREF="/useremail/u/777093"><b>Dustyn</b></A> : Great post  CalamityJane <A HREF="/useremail/u/679515"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>!<br>This seems to be bringing a lot of worth while attention to the fact that Sun Java never seems to remove previous versions while updating. :p<br><br>VERSION: Sun Java Runtime Environment Version 5.0 Update 5<br><br>This is what I have on my system and I make sure to always completely remove the previous version. I don't use the auto-update feature as it has proved to be unreliable. <br><br>Actually, when has it ever worked correctly?! :o :D<br><SMALL>--<br>"You have no idea what I am capable of. People who have tried to cross me, have lived to regret it...~<A HREF="http://www.michellestafford.com/images/ms_burg_1.jpg">Michelle Stafford</A> (Phyllis)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14806711</guid>
<pubDate>Mon, 14 Nov 2005 22:33:47 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14806285</link>
<description><![CDATA[<A HREF="/useremail/u/921899"><b>NanDog</b></A> : Yup, both removed and now have the current ver.<br><br>Thanks, Janie, for keeping your nose to the security grindstone! :D<br><br>I think I spend way too much time making sure this box is clean and secure but I think you make <B><I>me</I></B> look like a piker!  (And you're doing this more for others than for yourself!!)<br><br>Many thanks!<br><SMALL>--<br>See ya across the Rainbow Bridge, my good and faithful friend!</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14806285</guid>
<pubDate>Mon, 14 Nov 2005 21:44:26 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14805439</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  ravencajun <A HREF="/useremail/u/1056836"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>So should I now go to add remove and remove the top 2(1.4.2_05 and 5.0update 2) and only leave the J2SE 5.0update5 ??<br><br>Thanks for always keeping us safe!!<br> </DIV>Yes :)  And you're welcome.  Glad we could help, as always.<br><br>Don't worry about the voting folks.  We're way beyond that and the poll part was flawed the way it was written.  Right now we're just trying to get the word out about the old verisons vulnerability so ya'll are protected.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14805439</guid>
<pubDate>Mon, 14 Nov 2005 20:07:52 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14805417</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Glad to hear it, sailor!<br><br>And thank you for the reminder about the Google toolbar ...I need to put that in my instructions for folks to remember to uncheck the box if they don't want it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14805417</guid>
<pubDate>Mon, 14 Nov 2005 20:04:22 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14805302</link>
<description><![CDATA[<A HREF="/useremail/u/1056836"><b>ravencajun</b></A> : OH darn I am sorry I voted too and have not had the infection. I voted that I do not have 1.4.2.03.<br><br>This is what shows up in my add remove area<br>Java 2 SE v1.4.2_05<br><br>J2SE 5.0update 2<br>J2SE 5.0update5<br><br>So should I now go to add remove and remove the top 2(1.4.2_05 and 5.0update 2) and only leave the J2SE 5.0update5 ??<br><br>Thanks for always keeping us safe!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14805302</guid>
<pubDate>Mon, 14 Nov 2005 19:50:47 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14805222</link>
<description><![CDATA[<A HREF="/useremail/u/889509"><b>sailor</b></A> : <div class="bquote"><SMALL>said by  CalamityJane <A HREF="/useremail/u/679515"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR><div class="bquote"><SMALL>said by  sailor <A HREF="/useremail/u/889509"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>I have no idea what Sun Java even is but I believe I need it to see streaming live stock quotes that I use and that it came with me Dell...<br><br>I just looked into my Add/Remove Programs and I see 2 lines as follows:<br><br>JAVA 2 RUNTIME ENVIROMENT SE V1.4.2_03  136.00MB<br><br>JAVA 2 RUNTIME ENVIROMENT SE V.14.2_06  108.00MB<br><br>Please advise what I should do, if anything...<br>Thanks..<br><br>(Virus scan comes up clean..No problems with computer)<br> </DIV>Sailor,<br><br>You have the vulnerable versions on your system and are at risk.  You need to get the most current version and then remove the older versions.<br><br>The most current version of Sun Java is: Java Runtime Environment Version 5.0 Update 5<br>Please go to this link to verify your version to get the updates needed:<br>&raquo;<A HREF="http://www.java.com/en/download/windows_automatic.jsp" >www.java.com/en/download/windows&middot;&middot;&middot;atic.jsp</A><br>You'll need to use IE and allow ActiveX for this update. Follow the instructions on that page to verify Your Java software and get the updated version.<br><br>Then go to your Control Panel and look in Add/Remove programs and highlight each of these two and press *remove* one at a time:<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>JAVA 2 RUNTIME ENVIROMENT SE V1.4.2_03  136.00MB<br><br>JAVA 2 RUNTIME ENVIROMENT SE V.14.2_06  108.00MB<HR></BLOCKQUOTE><br><br> </DIV>Calamity Jane,<br><br>I wish to thank you for bringing this to the attention of the community and for replying to my post to you. I appreciate your very detailed step by step instructions including the link you provided for me to be able to get the current version and then delete the 2 that were in my Add/Remove Programs...<br><br>During the steps for the Java latest installation, I followed the instructions per your reply and I was able to UN-Check the box that Sun had automatically checked for the Google toolbar to be installed on my computer....I have no desire for it and was able to see that they had checked it due to I was taking each step slowly per your instructions, I was able to catch it and take the check out of the box to prevent Sun from adding the Google toolbar to my IE...<br><br>So due to your professional assistance, I was able to Update to the latest Java and then delete the other 2....For this, I thank you!!<br><br>Sailor]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14805222</guid>
<pubDate>Mon, 14 Nov 2005 19:40:01 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14800482</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  NanDog <A HREF="/useremail/u/921899"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>In any case, I had both v1.4.2_04 and _05.<br> </DIV>You removed them, right?  Because yes, those are vulnerable versions.<br><br> <BLOCKQUOTE><SMALL>said by  RobertLudlum <A HREF="/useremail/u/1143581"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><HR>What is surprising to me is that malware can exploit the existing older version.<HR></BLOCKQUOTE>  Exactly!  Sun needs to fix this problem.  Older versions left behind can be called up by the malware and infect your system.  Sun has acknowledged this but hasn't done anything about it!  <br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14800482</guid>
<pubDate>Mon, 14 Nov 2005 07:44:04 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14800460</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  sailor <A HREF="/useremail/u/889509"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>I have no idea what Sun Java even is but I believe I need it to see streaming live stock quotes that I use and that it came with me Dell...<br><br>I just looked into my Add/Remove Programs and I see 2 lines as follows:<br><br>JAVA 2 RUNTIME ENVIROMENT SE V1.4.2_03  136.00MB<br><br>JAVA 2 RUNTIME ENVIROMENT SE V.14.2_06  108.00MB<br><br>Please advise what I should do, if anything...<br>Thanks..<br><br>(Virus scan comes up clean..No problems with computer)<br> </DIV>Sailor,<br><br>You have the vulnerable versions on your system and are at risk.  You need to get the most current version and then remove the older versions.<br><br>The most current version of Sun Java is: Java Runtime Environment Version 5.0 Update 5<br>Please go to this link to verify your version to get the updates needed:<br>&raquo;<A HREF="http://www.java.com/en/download/windows_automatic.jsp" >www.java.com/en/download/windows&middot;&middot;&middot;atic.jsp</A><br>You'll need to use IE and allow ActiveX for this update. Follow the instructions on that page to verify Your Java software and get the updated version.<br><br>Then go to your Control Panel and look in Add/Remove programs and highlight each of these two and press *remove* one at a time:<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>JAVA 2 RUNTIME ENVIROMENT SE V1.4.2_03  136.00MB<br><br>JAVA 2 RUNTIME ENVIROMENT SE V.14.2_06  108.00MB<HR></BLOCKQUOTE><br><br>Don't worry about the voting guys.  Right now the main thing is to get the word out so you all know how to correct the problem<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14800460</guid>
<pubDate>Mon, 14 Nov 2005 07:35:58 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14800407</link>
<description><![CDATA[<A HREF="/useremail/u/1143581"><b>RobertLudlum</b></A> : <div class="bquote"><SMALL>said by  TK421 <A HREF="/useremail/u/1127059"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Updating Java is just one of those things many people don't think about... after all, why fix what ain't broke? Even Sun Java's built-in automatic update does not work reliably.<br><br>Yet the surprising fact (for many, I suspect) is that previous Java versions remain on the box after updating to the latest version. Sun does not remove old versions apparently so the update won't delete cached applets (most users won't have any anyway).<br><br> </DIV>I noticed this a while back, but I generally keep the last version around for a few hours/days while I test the newest one is working properly.<br><br>What is surprising to me is that malware can exploit the existing older version. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14800407</guid>
<pubDate>Mon, 14 Nov 2005 07:18:33 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14799019</link>
<description><![CDATA[<A HREF="/useremail/u/1058588"><b>bpm3k</b></A> : Oops...  I love polls.  I voted before I read your "please don't vote if you have not been infected with Vundo" part.<br><br><B>Remove one</B> "I don't have any version of Sun Java" vote.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14799019</guid>
<pubDate>Sun, 13 Nov 2005 22:50:53 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14798904</link>
<description><![CDATA[<A HREF="/useremail/u/921899"><b>NanDog</b></A> : Oooops...mea culpa!<br><br>I too did not notice until after I voted that you just wanted victims of Winfixer et al, to vote.<br><br>May I suggest that you put that caveat before the vote section?<br><br>In any case, I had both v1.4.2_04 and _05.<br><SMALL>--<br>See ya across the Rainbow Bridge, my good and faithful friend!</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14798904</guid>
<pubDate>Sun, 13 Nov 2005 22:30:22 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14798858</link>
<description><![CDATA[<A HREF="/useremail/u/889509"><b>sailor</b></A> : I have no idea what Sun Java even is but I believe I need it to see streaming live stock quotes that I use and that it came with me Dell...<br><br>I just looked into my Add/Remove Programs and I see 2 lines as follows:<br><br>JAVA 2 RUNTIME ENVIROMENT SE V1.4.2_03  136.00MB<br><br>JAVA 2 RUNTIME ENVIROMENT SE V.14.2_06  108.00MB<br><br>Please advise what I should do, if anything...<br>Thanks..<br><br>(Virus scan comes up clean..No problems with computer)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14798858</guid>
<pubDate>Sun, 13 Nov 2005 22:21:05 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14798625</link>
<description><![CDATA[<A HREF="/useremail/u/499139"><b>GercekSeytan</b></A> : <div class="bquote"><SMALL>said by  mazhurg <A HREF="/useremail/u/1000066"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>... remove me :o<br> </DIV>Ditto. :o :uhh:]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14798625</guid>
<pubDate>Sun, 13 Nov 2005 21:44:41 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14797921</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : There was absolutely no shame in that Bump CJ.. and their shouldn't have been.. This thing is worse than the Bube.. epidemic...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14797921</guid>
<pubDate>Sun, 13 Nov 2005 19:45:46 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14797903</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : *Shameless bump*<br><br>But we're still seeing oodles of Vundo/Winfixer/Virtumonde infectees due to this vulnerability.<br><br>Folks, <B>Update your Sun Java and remove any older versions</B>  They are in your control panel under Add/Remove Programs.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14797903</guid>
<pubDate>Sun, 13 Nov 2005 19:43:31 EDT</pubDate>
</item>

<item>
<title>Re: Potential Vulnerability with Sun Java auto upd</title>
<link>http://www.dslreports.com/forum/remark,14792278</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : I requested our Moderator,  Wildcatboy <A HREF="/useremail/u/231170"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> to edit the the title to to this thread, in case ya'll are wondering.  :)<br><br>It worked :D<br><br>Anyone with Sun Java installed....<B>please uninstall old versions of Sun Java and then get the latest updates</B><br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14792278</guid>
<pubDate>Sat, 12 Nov 2005 20:27:39 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14792228</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : See CJ's last response.. Her advice is as usual.. GOLDEN!!<br><SMALL>--<br>Lost in Texas</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14792228</guid>
<pubDate>Sat, 12 Nov 2005 20:21:00 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14792185</link>
<description><![CDATA[<A HREF="/useremail/u/1288776"><b>angel_ve</b></A> : Thanks a lot CajunTek the problem seem to be solved. I'll keep posting if it comes back. What advise can be given to non tech  people to avoid this problem??]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14792185</guid>
<pubDate>Sat, 12 Nov 2005 20:13:47 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14791677</link>
<description><![CDATA[<A HREF="/useremail/u/1288776"><b>angel_ve</b></A> : I posted the log under:<br><br>&raquo;<A HREF="/forum/remark,14791668">HJT Log Virtumonde</A><br><br>Thanks a lot for your help]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14791677</guid>
<pubDate>Sat, 12 Nov 2005 18:46:03 EDT</pubDate>
</item>

<item>
<title>Sun Java not always listed in Add/Remove Programs</title>
<link>http://www.dslreports.com/forum/remark,14790754</link>
<description><![CDATA[<A HREF="/useremail/u/662867"><b>SanJoseNerd</b></A> : After uninstalling two old versions of Sun Java using Add/Remove Programs, I discovered a third even older version that was <B>not</B> listed in Add/Remove Programs.  I had to uninstall it manually in C:\WINDOWS\Downloaded Program Files.<br><br>This older version was probably pre-installed by Dell, which might explain its absence from Add/Remove Programs.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14790754</guid>
<pubDate>Sat, 12 Nov 2005 16:00:18 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14789237</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : Start a new thread, post a hijackthis log.. We can help you clean it up.. There is another method (or two).. and another thing.. why not register here?<br><SMALL>--<br>Lost in Texas</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14789237</guid>
<pubDate>Sat, 12 Nov 2005 11:38:31 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14789229</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I got infected. I have 1.4.1 (SAS Private Version) and 1.4.2_03 HOW DO I GET RID OF IT!?!?!?! Symantec tool not working!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14789229</guid>
<pubDate>Sat, 12 Nov 2005 11:36:45 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14788775</link>
<description><![CDATA[<A HREF="/useremail/u/1288723"><b>Fieryblizzrd</b></A> : I'm running version 1.4.1 and having problems removing Virtumondo...  I'm planning on posting my HJT log soon in hopes someone can point out the entries I need to fix and utilities I need to run.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14788775</guid>
<pubDate>Sat, 12 Nov 2005 10:10:34 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please Read</title>
<link>http://www.dslreports.com/forum/remark,14761671</link>
<description><![CDATA[<A HREF="/useremail/u/1008110"><b>toolman12</b></A> : Just a side note for those of you that have McAfee like I do on a corporate laptop.  By default the On-Access Scanner does not have "detect potentially unwanted programs" and "detect joke programs" enabled by default.  According to the McAfee website this would have been the magic bullet that would have prevented me from getting the Winfixer/Vundo attack in the first place.  You will have to go to "Advanced Settings" under properties to check these settings.  Doh! ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14761671</guid>
<pubDate>Tue, 08 Nov 2005 17:51:07 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14757975</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  CajunTek <A HREF="/useremail/u/855835"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Update to CJ.. On the Vundo infections that I have worked with where the user had 1.5.. They also had one or more of the 1.4x versions as well..<br> </DIV>Thank you, Cajun, for checking that out.  That bears out the theory that the older versions are being exploited when they are not removed after an update :huh: <br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14757975</guid>
<pubDate>Tue, 08 Nov 2005 08:22:30 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14757607</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : Update to CJ.. On the Vundo infections that I have worked with where the user had 1.5.. They also had one or more of the 1.4x versions as well..<br><br>One thing to be concerned about.. When this is the case, I have yet to have the symantec fix work, The attribune fix has worked everytime.. (Sometimes in conjunction with Ewido to clean up the details)..<br><br>da cajun<br><SMALL>--<br>Lost in Texas</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14757607</guid>
<pubDate>Tue, 08 Nov 2005 05:55:01 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14757119</link>
<description><![CDATA[<A HREF="/useremail/u/914341"><b>chachazz</b></A> : May find C:\Programs:<br>Folder(version)\lib\applet\WMPNS.jar<br>which I remove manually.<br><SMALL>--<br><B><I>Chachazz</B></I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14757119</guid>
<pubDate>Tue, 08 Nov 2005 01:25:33 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14756478</link>
<description><![CDATA[<A HREF="/useremail/u/996768"><b>jbob</b></A> : Same here but some did indeed did have files present but since I've been doing this for a while now I do not remember what was there anymore.  When I uninstall now I simply just delete the remaining folders afterwards without looking.  Perhaps I'll load a test machine with an older version, uninstall it and check to see what is remaining.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14756478</guid>
<pubDate>Mon, 07 Nov 2005 23:31:20 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14756374</link>
<description><![CDATA[<A HREF="/useremail/u/360338"><b>jvmorris</b></A> : Are there actual <I>files</I> present in these folders, or just the folders themselves?  (I've no idea myself because I only had one version of the Sun JVM on any of the machines present here.)<br><SMALL>--<br>Regards,    Joseph V. Morris</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14756374</guid>
<pubDate>Mon, 07 Nov 2005 23:14:55 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14756318</link>
<description><![CDATA[<A HREF="/useremail/u/996768"><b>jbob</b></A> : Just an FYI but an uninstall of older versions leaves some folders intact.  Not sure how this would affect things though or really of the contents.  I noticed many months back of these upgrade issues when I noticed multiple Sun folders including multiple uninstall remnants in Add/Remove Programs.  After I uninstall in preparation for an updated version of Sun Java now I go and delete all the leftover folders just in case. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14756318</guid>
<pubDate>Mon, 07 Nov 2005 23:05:28 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please Read</title>
<link>http://www.dslreports.com/forum/remark,14755848</link>
<description><![CDATA[<A HREF="/useremail/u/327578"><b>hayc59</b></A> : Thanks Chazz ans updated as soon as I read this little<br>ditty ;):D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14755848</guid>
<pubDate>Mon, 07 Nov 2005 22:09:19 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14755794</link>
<description><![CDATA[<A HREF="/useremail/u/914341"><b>chachazz</b></A> : Just a note -<br>When posting Sun Java updates, I usually follow the update details with the following suggestion:<br><br>Download the 'Offline' Update file.<br>Uninstall all older versions of Sun Java.<br>Run a cache cleaner and registry cleaner(optional)<br>Reboot.<br>Install new version.<br>Reboot.<br><br>The rebooting process seems to be necessary to ensure a good clean install and operation of the new version. I've never had a problem updating Java.<br><br><U>Current Java:</U><br>(JRE 5.0 Update 5 includes the JVM technology)<br>J2SE(TM) Development Kit 5.0 Update 5<br>jdk-1_5_0_05-windows-i586-p.exe  <br>  <br><br> hayc59 <A HREF="/useremail/u/327578"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> looks like you need to update(?). ;)<br><SMALL>--<br><B><I>Chachazz</B></I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14755794</guid>
<pubDate>Mon, 07 Nov 2005 22:02:27 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please Read</title>
<link>http://www.dslreports.com/forum/remark,14755642</link>
<description><![CDATA[<A HREF="/useremail/u/327578"><b>hayc59</b></A> : I also accidently voted...sorry<br>can someone post some good setting for this?<br>after looking at Corrines post did not know<br>all those setting were available<br>thanks<br><SMALL>--<br>&atilde;r&ecirc; &yen;&Oslash;u &ecirc;xp&ecirc;ri&ecirc;nc&ecirc;D  <BR><A HREF="http://www.fdnylodd.com/BloodofHeroes.html">9/11/01 Never Forget</A></B></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14755642</guid>
<pubDate>Mon, 07 Nov 2005 21:45:19 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please Read</title>
<link>http://www.dslreports.com/forum/remark,14755477</link>
<description><![CDATA[<A HREF="/useremail/u/327578"><b>hayc59</b></A> : Sun J2SE 1.4.2_03 is the version I have!!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14755477</guid>
<pubDate>Mon, 07 Nov 2005 21:25:27 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please Read</title>
<link>http://www.dslreports.com/forum/remark,14755211</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : omgwtf! I had so many instances of java, removing all but the latest must have given me back about half a gig of disk space.<br><br>:o<br><br><I>*lobs a grenade at Sun*</I>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14755211</guid>
<pubDate>Mon, 07 Nov 2005 20:57:43 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14755014</link>
<description><![CDATA[<A HREF="/useremail/u/1127059"><b>TK421</b></A> : Updating Java is just one of those things many people don't think about... after all, why fix what ain't broke? Even Sun Java's built-in automatic update does not work reliably.<br><br>Yet the surprising fact (for many, I suspect) is that previous Java versions remain on the box after updating to the latest version. Sun does not remove old versions apparently so the update won't delete cached applets (most users won't have any anyway).<br><br>This thread is a great reminder to keep all components current, but even more than that, it sheds light on a possible vulnerability that is easily overlooked.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14755014</guid>
<pubDate>Mon, 07 Nov 2005 20:33:15 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14754674</link>
<description><![CDATA[<A HREF="/useremail/u/465492"><b>Jrb2</b></A> :  <BLOCKQUOTE><SMALL>quote:</SMALL><HR>But what has happened is this thread is doing a service to all our members in getting the word out about this vulnerability of older versions left on PCs after updating that Sun will not fix!<br><HR></BLOCKQUOTE><br><br>And may I add a huge thank-you and thumbs-up to you Janie (and of course to others involved) in making everyone aware about this!!! ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14754674</guid>
<pubDate>Mon, 07 Nov 2005 19:52:57 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14754349</link>
<description><![CDATA[<A HREF="/useremail/u/1282181"><b>mrsplants</b></A> : Yes I updated to   update5  and then removed runtime update1.. thanks:)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14754349</guid>
<pubDate>Mon, 07 Nov 2005 19:04:23 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14754249</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : SqueeksDad...{{{Hugs}}}  That's ok.  Most folks missed that part too - not to worry.  Comments are welcome from those who did have the infection as well as those who didn't.<br><br>Right now we're trying to get the word out to everyone about updating and removing old versions at this point. I may just ask WCB to go ahead and change the title and edit out the poll anyway (numbers are kinda skewered) ;)<br><br>But what has happened is this thread is doing a service to all our members in getting the word out about this vulnerability of older versions left on PCs after updating that Sun will not fix!:mad:<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14754249</guid>
<pubDate>Mon, 07 Nov 2005 18:52:37 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14754151</link>
<description><![CDATA[<A HREF="/useremail/u/688534"><b>SqueeksDad</b></A> : Darn IT!! Calamity I voted cuz I had more than 3 versions installed but did NOT have an infection, I just didn't see that part til it was too late. Sorry!<br><SMALL>--<br>Ways to Relieve Stress #10. Make up a language and ask people for directions.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14754151</guid>
<pubDate>Mon, 07 Nov 2005 18:39:43 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14753960</link>
<description><![CDATA[<A HREF="/useremail/u/1065964"><b>Corrine</b></A> : After updating Sun Java, I could connect (dialup) but kept getting "page cannot be displayed" regardless of the browser I tried. My friend Mitch gave me the solution: <br><br><div class="code"><PRE><span class="codetext">Go to Start &gt; Control Panel &gt; Java &gt; Advanced &gt; &lt;APPLET&gt;  tag support &gt; </SPAN></PRE></DIV>Place a check in the box next to the listed browser(s). <br><SMALL>--<br>Corrine, Administrator Freedomlist; <br>Proud Charter Member ASAP Since 2004 (Alliance of Security Analysis Professionals)</SMALL><br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14753960</guid>
<pubDate>Mon, 07 Nov 2005 18:15:32 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14751365</link>
<description><![CDATA[<A HREF="/useremail/u/940628"><b>Pole883</b></A> : Have a great week!!<br><br>Be well........]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14751365</guid>
<pubDate>Mon, 07 Nov 2005 13:03:25 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14750750</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Thanks for the feedback, Sarah!  Kinda confirms what we've been seeing.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14750750</guid>
<pubDate>Mon, 07 Nov 2005 11:48:05 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14750714</link>
<description><![CDATA[<A HREF="/useremail/u/282410"><b>Sarah</b></A> : <div class="bquote"><SMALL>said by  CalamityJane <A HREF="/useremail/u/679515"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>we <I>think</I> Vundo is installing by using an exploit of older versions of Sun Java when you just visit an infected webpage. Many of the systems I have cleaned up were uptodate with AV/AT/AS software and windows updates and well secured systems, except for the blasted old version of Sun Java still installed. </DIV>That does explain my infection, at least. I had the 1.4.2_03 version installed and nothing else (it is/was a fairly new computer and that's what was installed when I got it). I'd read that it came through a link in a spam e-mail, which I knew wasn't right since I don't even think about opening spam, let alone clicking a link...<br><SMALL>--<br><B>BEAT IT, BILL!</B><BR><I>(The devil makes work for idle hands, but Stanford makes work for <A HREF="http://www.bbrteamhelix.net/">idle CPUs!</A>)</I></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14750714</guid>
<pubDate>Mon, 07 Nov 2005 11:44:27 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14749425</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Yes, that is the webpage we have been complaining about and asked Sun to fix that because older versions are <B>vulnerable</B> to exploits when left on the system.  <br>&raquo;<A HREF="http://secunia.com/advisories/15671/" >secunia.com/advisories/15671/</A><br>Sun has acknowledged this as far back as Feburary of this year, and said they would investigate fixing the webpages and the issue with the auto updates not removing older versions.  But to date, they have not :(<br><br>Most users are not aware that because of this their systems may not be secure. <br><br>The most current update is listed in the original post.  And all older versions of Sun Java should be removed in Add/Remove programs.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14749425</guid>
<pubDate>Mon, 07 Nov 2005 07:14:20 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please Read</title>
<link>http://www.dslreports.com/forum/remark,14748757</link>
<description><![CDATA[<A HREF="/useremail/u/413587"><b>nirvansk815</b></A> : What about this:<br><br><SMALL><HR>" General Questions <br><br>     <br>Printable Version  <br><br>Can I remove older versions of the JRE after installing a newer version? <br><br>The latest version of the Java Runtime Environment (JRE) contains updates to previous versions. There might be some applications or applets written and tested against a specific version of the JRE. <br><br>It is recommended that you keep older versions of the JRE on your system. If you are running low on disk space, you can uninstall older versions of the JRE. <br><br>To remove older versions of JRE, go to Windows Java Runtime Environment uninstallation instructions page. <br>  <br>"<HR></SMALL><br>&raquo;<A HREF="http://www.java.com/en/download/faq/5000070400.xml" >www.java.com/en/download/faq/5000070400.xml</A><br><br>Who's right?<br><SMALL>--<br>There's so much to be thankful for...How can anyone be sad?</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14748757</guid>
<pubDate>Mon, 07 Nov 2005 01:21:12 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please Read</title>
<link>http://www.dslreports.com/forum/remark,14748623</link>
<description><![CDATA[<A HREF="/useremail/u/677891"><b>duaneinva</b></A> : I got hit with Winfixer/Vundo 1 1/2 weeks ago, and wondered how the heck I got it.  I practice safe computing, and yet I got it.  :(<br><br>I knew I had *something* when my laptop stopped going into sleep mode when the lid was closed.  The light on the mouse went out, then came BACK ON.  All I knew is that I did not install anything at that time.<br><br>I finally got rid of it by using Hijackthis and another program that allowed the suspect .dll file to be deleted on bootup, but it was a pain.<br><br>Edit:  Using the latest Spybot and McAfee Virus -- neither of them detected it. :(<br><br>BTW, I had 1.4.2_03 Java installed, until I just installed the 1.50 Update 5.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14748623</guid>
<pubDate>Mon, 07 Nov 2005 00:43:50 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14748502</link>
<description><![CDATA[<A HREF="/useremail/u/767055"><b>heels_fan</b></A> : I have 5.0 update 1,2 and 5. should i delete update 1 and 2?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14748502</guid>
<pubDate>Mon, 07 Nov 2005 00:13:26 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please Read</title>
<link>http://www.dslreports.com/forum/remark,14748407</link>
<description><![CDATA[<A HREF="/useremail/u/104544"><b>jose3030</b></A> : Wow, I noticed this fact on my own today.<br><br>Uninstalled 3&4 and installed 5 today.  I still have to reboot-- but that will come later. :) ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14748407</guid>
<pubDate>Sun, 06 Nov 2005 23:57:02 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14746697</link>
<description><![CDATA[<A HREF="/useremail/u/360338"><b>jvmorris</b></A> : Well, to just continue in that vein . . . what's with a Sun JVM update needing ActiveX to work?  It's my recollection that one of the never-ending 'advantages' of relying on Java (and especially Sun Java) was that you wouldn't need ActiveX.  But, now I <I>still</I> find a Sun worksite depending on ActiveX!  It got worse; without cross-site cookies and referrers enabled, I couldn't even <B>get</B> to the update!  This is supposed to be a 'more secure' solution?  I don't think so!<br><SMALL>--<br>Regards,    Joseph V. Morris</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14746697</guid>
<pubDate>Sun, 06 Nov 2005 19:52:32 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14746638</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  Vvian Kalyss <A HREF="/useremail/u/887018"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Thank you :)<br><br>I removed the 4 extra ones and rebooted, and noticed the hdd space freed. It seems that they are all self-contained and don't even share common files? I thought updating something meant modifying the older files, apparently they decided to play it safe and just made a new install every time. Bloatware :D<br> </DIV>And that is exactly the problem!  A malicious website could call up one of the older versions and infect your PC.  Sun Java updates do NOT remove older vulnerable versions, even though we have bugged them about it :(<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14746638</guid>
<pubDate>Sun, 06 Nov 2005 19:42:15 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14746590</link>
<description><![CDATA[<A HREF="/useremail/u/887018"><b>Vvian Kalyss</b></A> : Thank you :)<br><br>I removed the 4 extra ones and rebooted, and noticed the hdd space freed. It seems that they are all self-contained and don't even share common files? I thought updating something meant modifying the older files, apparently they decided to play it safe and just made a new install every time. Bloatware :D<br><SMALL>--<br>Mikami Vvian, resident Girlfriend of Steel, care of the Tokyo-3 Middle Daughters Club</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14746590</guid>
<pubDate>Sun, 06 Nov 2005 19:35:18 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14746528</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : What Jack b said.<br><br>In Add/Remove programs click on these and press *remove*<br>J2SE Runtime Environment 5.0 - 97.99Mb<br>J2SE Runtime Environment 5.0 Update 2 - 143.00Mb<br>J2SE Runtime Environment 5.0 Update 4 - 144.00Mb<br>Java 2 Runtime Environment, SE v1.4.2_04 - 130.00Mb<br><br>And leave this one alone:<br>J2SE Runtime Environment 5.0 Update 5 - 151.00Mb as that IS the most current version.<br><br>(Anyone notice the size of those suckers? :o )<br><br>Leaving those old versions on your PC leaves your vulnerable to exploits.  And remember to remove old versions manually on subsequent updates of Sun Java.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14746528</guid>
<pubDate>Sun, 06 Nov 2005 19:25:14 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14746472</link>
<description><![CDATA[<A HREF="/useremail/u/198601"><b>jack b</b></A> : The most current version of Sun Java is Java Runtime Environment Version 5.0 Update 5<br>(J2SE Runtime Environment 5.0 Update 5) <br><br>You can safely dump all the others.<br><SMALL>--<br><I>~Help find a cure for Cancer~ <BR> ~Proud Member of <A HREF="/forum/disco">Team Discovery</A> ~</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14746472</guid>
<pubDate>Sun, 06 Nov 2005 19:16:12 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please Read</title>
<link>http://www.dslreports.com/forum/remark,14746445</link>
<description><![CDATA[<A HREF="/useremail/u/887018"><b>Vvian Kalyss</b></A> : No vote, am not infected (afaik...). Just curious, where does the version info show up? IE -> Tools -> Sun Java Console, just displays some text. Under Add/Remove programs (Control Panel) however I see 5 items:<br><br>J2SE Runtime Environment 5.0 - 97.99Mb<br>J2SE Runtime Environment 5.0 Update 2 - 143.00Mb<br>J2SE Runtime Environment 5.0 Update 4 - 144.00Mb<br>J2SE Runtime Environment 5.0 Update 5 - 151.00Mb<br>Java 2 Runtime Environment, SE v1.4.2_04 - 130.00Mb<br><br>Does that mean this machine has 5? If so, should I pick one (which one?) and uninstall the rest?<br><br>Confusing :(<br><br>Edit: Didn't notice the pop-under on that page. It checked and said I had the latest version. Didn't say anything about other existing versions though.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14746445</guid>
<pubDate>Sun, 06 Nov 2005 19:11:46 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14745743</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  toolman12 <A HREF="/useremail/u/1008110"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br> Not sure where I picked up vundo.  Maybe off a shared drive?  I thought I had a pretty secure system on a fairly secure network.  Oh well, so much for that theory.  </DIV>No, we <I>think</I> Vundo is installing by using an exploit of older versions of Sun Java when you just visit an infected webpage. Many of the systems I have cleaned up were uptodate with AV/AT/AS software and windows updates and well secured systems, except for the blasted old version of Sun Java still installed.<br><br>Glad you got rid of it.  At least you know where to come if you find that you didn't and that newer version of Sun Java should be safe (for now).  Just remember when you update Sun Java to remove the old version manually.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14745743</guid>
<pubDate>Sun, 06 Nov 2005 16:58:16 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14745698</link>
<description><![CDATA[<A HREF="/useremail/u/1008110"><b>toolman12</b></A> : Calamity - Surprisingly enough I was able to remove it by doing a system restore to a point about 3 weeks back.  I then ran the Symantec tool twice following the instructions provided and it did not detect vundo.  Everything seems to be working just great now.  I did not expect things to go back to normal so easy, but I think I was just lucky.  Not sure where I picked up vundo.  Maybe off a shared drive?  I thought I had a pretty secure system on a fairly secure network.  Oh well, so much for that theory.  <br><br>Thanks for your very informative post on the subject.  I'm sure more folks will be picking this thing up as time goes on. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14745698</guid>
<pubDate>Sun, 06 Nov 2005 16:50:06 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14744529</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : @toolman12 & lgkahn,<br><br>Are you still having a problem with it?  Did you try the Symantec Removal tool?<br>&raquo;<A HREF="/faq/security">Security</A> &raquo;<A HREF="/faq/13331">How Do I Remove Trojan Vundo/Winfixer/Virtumonde?</A><br><br>If, after running that you are still having a problem (in some cases it won't work), please post a new topic in the forum so we can help you.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14744529</guid>
<pubDate>Sun, 06 Nov 2005 13:24:57 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14744481</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  CajunTek <A HREF="/useremail/u/855835"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Yep. I suspect your right and I've asked the OP to check.. No response yet..<br> </DIV>Thanks! :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14744481</guid>
<pubDate>Sun, 06 Nov 2005 13:17:45 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14744385</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : Yep. I suspect your right and I've asked the OP to check.. No response yet..<br><SMALL>--<br>Lost in Texas</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14744385</guid>
<pubDate>Sun, 06 Nov 2005 13:02:10 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please Read</title>
<link>http://www.dslreports.com/forum/remark,14743933</link>
<description><![CDATA[<A HREF="/useremail/u/782768"><b>dliw</b></A> : Thank you for this thread  CalamityJane <A HREF="/useremail/u/679515"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>.  <IMG SRC="http://bestsmileys.com/thumbs/7.gif">  Now have Update 5 installed. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14743933</guid>
<pubDate>Sun, 06 Nov 2005 11:47:08 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14743709</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  CajunTek <A HREF="/useremail/u/855835"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll<br>I don't know if the user also had older versions as well..<br></DIV>Right, Hijackthis only shows the most current version installed so multiple versions won't show.  If you can find out what other versions may have also been on that PC?  The thing is, if they had an older version on there as well, the malware could call up the vulnerable version.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14743709</guid>
<pubDate>Sun, 06 Nov 2005 11:06:03 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14743685</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : Another Note..<br><br>I have been involved in removing 5 virtumondo infections<br><br>All but 1 had 1.4.2_0X version of java except 1 it had 1.5.. <br><br>So I am unsure if 1.5 is bullet proof..<br><br>Here are the relevant HJT lines<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll<br>I don't know if the user also had older versions as well..<br><br>It was a double infection as well..<br><SMALL>--<br>Lost in Texas</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14743685</guid>
<pubDate>Sun, 06 Nov 2005 11:01:48 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please Read</title>
<link>http://www.dslreports.com/forum/remark,14743638</link>
<description><![CDATA[<A HREF="/useremail/u/1008110"><b>toolman12</b></A> : <div class="bquote"><SMALL>said by  jig <A HREF="/useremail/u/279131"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>just for sanity,<br><br>is Winfixer/ Vundo / Virtumonde wasy to scan for? do either spybot, adaware, or avg find it?<br> </DIV>I had the latest version of Spybot and it did not detect or remove it. I was, however, able to see the BHO using Spybot's advanced tools.  The latest version of McAfee did not detect it.  I did find that the online spyware scan at TrendMicro detected it and claimed to remove it, but vundo kept coming back.  Probably because I did not turn off system restore in WinXP.  <br><br>Just for the record, I did only have J2SE 1.4.2_03 installed and nothing else.  Very interesting.  I'm now upgraded and 1.4.2_03 is gone. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14743638</guid>
<pubDate>Sun, 06 Nov 2005 10:53:06 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14743620</link>
<description><![CDATA[<A HREF="/useremail/u/1159642"><b>lgkahn</b></A> : a friends laptop had no java... fixvundo 1.4 found it but wouldn't remove it..<br><br>had to boot to safe mode and run procexp to kill the hjkii.dll or whatever it was called in the winlogon and explorer threads.. (otherwise registry keys couldn't be removed) then remove registry keys with hijakthis then use killbox to schedule the dll to be removed on next boot (even after killing the dll threads) the file was still locked and couldn't be removed or renamed inSAFE MODE)...this thing is really nasty and after all the research and time it would have been quicker to re-install...<br><br>good reason to keep weekly backups...<br><br>the person or people that did this should be shot and hung up by their nuts.<br><br>I saved a copy of the dll and even the latest symantec/norton 2005 is still not detecting it.. I submitting it to them and never got a reply.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14743620</guid>
<pubDate>Sun, 06 Nov 2005 10:49:41 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14743162</link>
<description><![CDATA[<A HREF="/useremail/u/461260"><b>deadi</b></A> : The 2 machines that I have cleaned both had 1.4.2. This is what came installed. I have noticed the old version will remain in add/remove programs if you do not manually remove it when upgrading. You also need to check IE under "Tools", "Options", "View Objects". You might see multiple versions  there also. Both have been updated to the latest. Have not heard from either. <br><br>Another good sign of infection, the pc will run veeery slow.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14743162</guid>
<pubDate>Sun, 06 Nov 2005 08:48:21 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14743013</link>
<description><![CDATA[<A HREF="/useremail/u/855835"><b>CajunTek</b></A> : Good poll CJ.. Only a comment no vote.. No winfixer or virtumondo here.. and only one java.. Version 1.5.0 (build 1.5.0_05-b05) <br><br>Keep doing what ya do..<br><br>(Formerly MerlynTech.. but I'm CajunTek everywhere else so....)<br><SMALL>--<br>Lost in Texas</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14743013</guid>
<pubDate>Sun, 06 Nov 2005 07:50:03 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14742978</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : @Siljaline - you're welcome.  I'm sure Mow will keep bugging them!<br><br>@jig:  Most victims either see the winfixer popups or their AV/AT/AS program has alerted them on the Vundo/Virtumonde infection, but they are lagging in complete removal.  The Symantec tool right now seems to be getting it since it was updated to v. 1.4.  If they have a double infection of it, the tool doesn't work and we have to use HJT & VundoFix (a different tool, little more complicated).  The popups it creates are really the biggest sign of an infection.<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14742978</guid>
<pubDate>Sun, 06 Nov 2005 07:30:29 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please Read</title>
<link>http://www.dslreports.com/forum/remark,14742795</link>
<description><![CDATA[<A HREF="/useremail/u/279131"><b>jig</b></A> : <br>just for sanity,<br><br>is Winfixer/ Vundo / Virtumonde wasy to scan for? do either spybot, adaware, or avg find it?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14742795</guid>
<pubDate>Sun, 06 Nov 2005 04:01:44 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please Read</title>
<link>http://www.dslreports.com/forum/remark,14742164</link>
<description><![CDATA[<A HREF="/useremail/u/703015"><b>siljaline</b></A> : Thanks for the poll CJ, redundant installs now removed.<br>If only Sun would fix this issue, I'll bug Mow to keep bugging them to clean up the update process.<br><br>Regards,<br><SMALL>--<br>siljaline MS - MVP Windows (IE/OE) & Security, AH-VSOP</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14742164</guid>
<pubDate>Sun, 06 Nov 2005 00:26:26 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14740157</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Thanks for your comments, mers2!<br><br>Yes, we want comments - but the actual voting is for Vundo infectees only (just to clarify).  Don't want anyone to feel they can't comment or ask a question or lend input :)<br><br>{{{Hugs}}}<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14740157</guid>
<pubDate>Sat, 05 Nov 2005 18:37:55 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14740124</link>
<description><![CDATA[<A HREF="/useremail/u/974615"><b>mers2</b></A> : Remove me as well.  Since I saw others vote who I know haven't been infected, I did as well.  Voted using a different version then 1.4.2_03 (1.5) and I only have the one version as I am obsessive about keeping a clutter free system. :)<br><SMALL>--<br>God put me on this Earth to accomplish a certain number of things. Right now, I am so far behind I will never die.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14740124</guid>
<pubDate>Sat, 05 Nov 2005 18:31:55 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14740069</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  mazhurg <A HREF="/useremail/u/1000066"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><BLOCKQUOTE>Reminder:But please don't vote if you have not been infected with Vundo</BLOCKQUOTE><br><br>Sorry, my fingers got way ahead of my comprehension tonight... Please remove my vote under other versions.<br><br>:o<br> </DIV>No problem.  And thanks for posting to let us know.<br><br>ALL comments welcome, we just only want the Vundo infectees voting.<br><br>Feel free to leave your comments or questions here though :)<br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14740069</guid>
<pubDate>Sat, 05 Nov 2005 18:23:09 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14740037</link>
<description><![CDATA[<A HREF="/useremail/u/1000066"><b>mazhurg</b></A> : <BLOCKQUOTE>Reminder:But please don't vote if you have not been infected with Vundo</BLOCKQUOTE><br><br>Sorry, my fingers got way ahead of my comprehension tonight... Please remove my vote under other versions.<br><br>:o]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14740037</guid>
<pubDate>Sat, 05 Nov 2005 18:17:37 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14740011</link>
<description><![CDATA[<A HREF="/useremail/u/1000066"><b>mazhurg</b></A> : ... remove me :o]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14740011</guid>
<pubDate>Sat, 05 Nov 2005 18:14:24 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14739996</link>
<description><![CDATA[<A HREF="/useremail/u/1003137"><b>garys_2k</b></A> : <div class="bquote"><SMALL>said by  CalamityJane <A HREF="/useremail/u/679515"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><BR><BR>Reminder:<B>But please don't vote if you have not been infected with Vundo</B>  We're trying to educate folks, too but Steve would like to get an idea of what versions were running on current/previously infected with Vundo/Winfixer PCs <I>only</I><br> </DIV>DOH! So sorry! I voted "None installed" becasue that's what I have, but I wasn't infected. Deduct my vote, and sorry for the confusion on my part.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14739996</guid>
<pubDate>Sat, 05 Nov 2005 18:12:20 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14739843</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><SMALL>said by  DevilFrank <A HREF="/useremail/u/839734"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>I did&acute;nt install Sun-Java and don&acute;t miss it as yet.<br> </DIV>Ok!  Comments are most welcome from all! :)  <br><br>Reminder:<B>But please don't vote if you have not been infected with Vundo</B>  We're trying to educate folks, too but Steve would like to get an idea of what versions were running on current/previously infected with Vundo/Winfixer PCs <I>only</I><br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR>Microsoft MVP/Windows Security 2003-2006<BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14739843</guid>
<pubDate>Sat, 05 Nov 2005 17:49:49 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14739797</link>
<description><![CDATA[<A HREF="/useremail/u/839734"><b>DevilFrank</b></A> : I did&acute;nt install Sun-Java and don&acute;t miss it as yet.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14739797</guid>
<pubDate>Sat, 05 Nov 2005 17:41:17 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14739777</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : You're welcome, JV!  I had a couple of old versions still on here too.  Until Sun fixes these issues, it's hard to remember to go in and manually remove the older versions after a Sun Java Update :mad:<br><br>They don't state that about removing older versions on their download webpages either.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14739777</guid>
<pubDate>Sat, 05 Nov 2005 17:37:23 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14739689</link>
<description><![CDATA[<A HREF="/useremail/u/360338"><b>jvmorris</b></A> : CJ,<br><br>Not a victim, but I want to thank you for bringing the subject up anyway.  Each of the machines here only had one installation of the Sun JVM -- and each one was a different version! :o  <br><br>Got them all in synch now.  Thanks again.<br><SMALL>--<br>Regards,    Joseph V. Morris</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14739689</guid>
<pubDate>Sat, 05 Nov 2005 17:23:37 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please Read</title>
<link>http://www.dslreports.com/forum/remark,14739405</link>
<description><![CDATA[<A HREF="/useremail/u/163741"><b>fuzz</b></A> : Had 3 and 4 installed, saw this thread, installed update 5 then removed 3 and 4.<br><SMALL>--<br>fuzz</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14739405</guid>
<pubDate>Sat, 05 Nov 2005 16:36:54 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14739181</link>
<description><![CDATA[<A HREF="/useremail/u/555588"><b>LoPhatPhuud</b></A> : Thanks for the poll CJ!<br><br>I am one of those nuts that hates sysytem clutter. First time I found out that the old versions of Sun JRE were not removed, I did it manually. I only have the most recent version installed. All others gone.<br><SMALL>--<br>When angry count four; when very angry, swear.<BR>Microsoft MVP Windows-Security 2005<BR><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14739181</guid>
<pubDate>Sat, 05 Nov 2005 15:56:17 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14738624</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : You're welcome, Mike.  Thanks for voting and I hope the extra info was a help :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14738624</guid>
<pubDate>Sat, 05 Nov 2005 14:07:58 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14738337</link>
<description><![CDATA[<A HREF="/useremail/u/940628"><b>Pole883</b></A> : :D;)<br><br>Thanks Jane!!<br><br>Mike]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14738337</guid>
<pubDate>Sat, 05 Nov 2005 13:08:26 EDT</pubDate>
</item>

<item>
<title>Re: Winfixer/ Vundo / Virtumonde Victims : Please</title>
<link>http://www.dslreports.com/forum/remark,14738275</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Thanks for the votes so far.  Please do reply here with what versions you have if there is more than one, please :)<br><br>Thanks!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14738275</guid>
<pubDate>Sat, 05 Nov 2005 12:53:37 EDT</pubDate>
</item>

<item>
<title>Potential Vulnerability with Sun Java auto update</title>
<link>http://www.dslreports.com/forum/remark,14738046</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : [mpoll]<B>Which version of Sun Java is installed?</B>,Sun J2SE 1.4.2_03 is installed in Add/Remove Programs in the Control Panel, More than one version is installed, More than 2 versions are installed, version 1.4.2_03 is NOT installed, I don't have any version of Sun Java[/mpoll]<br><br>We have noticed a large number of Winfixer/ Vundo / Virutmonde Victims have an older version of Sun Java (v. J2SE 1.4.2_03) installed in Add/Remove Programs in the Control Panel. Other older or newer versions may also be installed, however, we are wanting to know if you have this version on your system.<br><br>If you've been a victim of this malware (or have been helping one), would you please take the time to answer the poll ?<br>Also, if you have more than one version installed, please list them in a reply to this thread.<br><br><B><I>Why do we want to know?</I></B><br><br>Fellow MS MVP Steve Wechsler (aka MowGreen) wrote to Sun Microsystems (makers of Sun Java) to express the concerns raised in the Security Community that autoupdaters of Sun Java do not uninstall previous (vulnerable) versions of the program.  He asked for clarification that if a User utilizes the automatic update mechanism of the JRE the previous vulnerable version is left on the system, and that those previous vulnerable versions can still be called by malware. The folks at Sun Microsystems wrote back confirming this is true and they would be investigating updating the java.com pages and the auto update uninstallation issue.  That was back in February and to date, none of these issues has been resolved.<br><br>Therefore all users are encouraged to please check in your Control Panel, under Add/Remove programs and uninstall any older versions of Sun Java.  And in the future, remember to remove older versions of Java when you automatically update to a newer version to avoid exploitation of older versions left on your system.<br><br>The most current version of Sun Java can be found and downloaded from here:<br><br>&raquo;<A HREF="http://java.com/en/download/windows_xpi.jsp" >java.com/en/download/windows_xpi.jsp</A><br><br>To check your version to see if it is the latest version, Please go here:<br><br>&raquo;<A HREF="http://www.java.com/en/download/installed.jsp" >www.java.com/en/download/installed.jsp</A><br><br>Follow the instructions on that page to verify Your Java software<br><br><B>Please remember to uninstall all old versions of Sun Java</B><br><br>According to the bulletins, CERT also warns about java bug being exploited and you can read more about it here:<br><br>&raquo;<A HREF="http://isc.sans.org/diary.php?storyid=1039" >isc.sans.org/diary.php?storyid=1039</A><br><br><B>The current *fix* for Vundo/Virtumonde/Winfixer can be found here:</B><br><br>&raquo;<A HREF="/faq/seclean">Security Cleanup FAQ</A> &raquo;<A HREF="/faq/13619">Trojan Vundo/Virtumonde/Winfixer Removal</A><br><br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR><br>Microsoft MVP/Windows Security 2003-2006<br><br><BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,14738046</guid>
<pubDate>Sat, 05 Nov 2005 12:00:50 EDT</pubDate>
</item>

</channel>
</rss>
