TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
JAVA_BYTEVER.A
Overview

Malware type: JavaScript

Aliases: Trojan.Java.ClassLoader.d (Kaspersky), Trojan.ByteVerify (Symantec), JS/OpenConnect.J.3 (Avira), Troj/Femad-E (Sophos),

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

Medium

Distribution potential:

Low

Description: 

This malware is a component of a malicious Java archive file (JAR) that resides in a malicious Web site. System affected by the malware JS_FORTNIGHT.B are redirected to this Web site.

This malware calls and executes another malware, JAVA_JJBLACK.C, which results in modifications to the browser and registry settings of the infected system.

This is Trend Micro's detection for JAVA classes that exploit a known vulnerability in Microsoft Virtual Machine in Windows Operating Systems and Internet Explorer. This flaw allows malicious users to execute codes of his or her choice when a user visits an infected Web site. Notably, users of Sun JVM are not affected by this malware.

For more information on the said vulnerability, please refer to the following Web pages:

For additional information about this threat, see:
Solution
Technical Details

Description created: May. 23, 2003 9:25:02 PM GMT -0800
Description updated: Mar. 8, 2005 12:56:26 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.