LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-30-2006, 11:17 PM   #1
686plus
Member
 
Registered: Nov 2004
Location: Portland, Oregon
Distribution: Ubuntu
Posts: 114

Rep: Reputation: 17
clamav detected Java.Downloader.OpenStream.A - what now?


Hello~

I'm running FC5 with Gnome. I ran clamav with the following results:

Code:
//home/chris/.java/deployment/cache/javapi/v1.0/jar/javainstaller.jar-5aa0b436-7d48e07f.zip: Java.Downloader.OpenStream.A FOUND
LibClamAV Error: cli_untar: only standard TAR files are currently supported
LibClamAV Warning: Multipart MIME message contains no boundaries
LibClamAV Warning: Ignoring empty field in " charset="

----------- SCAN SUMMARY -----------
Known viruses: 48836
Engine version: 0.88.1
Scanned directories: 18419
Scanned files: 157213
Infected files: 1
Data scanned: 6560.12 MB
Time: 4288.509 sec (71 m 28 s)

I googled the virus and found its a Windows virus (surprise?). This is the first virus I've gotten on Linux box. Can I just delete it? Where should I go from here?
 
Old 05-01-2006, 04:09 PM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
considering that you are sure it's a windows virus (you are sure, right?), and considering it's located in your home directory, i'd say you just need to clear your ~/.java directory and you'd be set...

how'd you get this, through firefox?? to prevent this kinda stuff from getting downloaded i recommend you either disable java in your firefox or install the noscript extension so that java only works on sites you trust... http://www.noscript.net/

just my ...

PS: i did a quick google and this seems to be more like windows spyware than a virus...

Last edited by win32sux; 05-01-2006 at 04:49 PM.
 
Old 05-01-2006, 04:10 PM   #3
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
considering that you are sure it's a windows virus (you are sure, right?), and considering it's located in your home directory, i'd say you just need to clear your ~/.java directory and you'd be set...

how'd you get this, through firefox?? to prevent this kinda stuff from getting downloaded i recommend you either disable java in your firefox or install the noscript extension so that java only works on sites you trust... http://www.noscript.net/

just my ...

PS: i did a quick google and this seems to be more like windows spyware than a virus...

EDIT: sorry about the double post - i hit the submit button and waited for like 15 seconds but nothing happened so i hit it again thinking i hadn't hit it right and well here's the result... i guess the website is under heavy load and stuff, cuz even this edit is taking a huge amount of time to get through...

Last edited by win32sux; 05-01-2006 at 04:50 PM.
 
Old 05-01-2006, 04:25 PM   #4
Emerson
LQ Sage
 
Registered: Nov 2004
Location: Saint Amant, Acadiana
Distribution: Gentoo ~amd64
Posts: 7,661

Rep: Reputation: Disabled
I'm pretty sure it is written for MS Java and harmless with Sun Java even under Windows.
 
Old 05-01-2006, 04:53 PM   #5
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
also, it wouldn't hurt to check your ~/.bash_profile to make sure none of this is/was getting auto-loaded from there... this is in case the malware somehow found a way to break-out of the java sandbox or something like that - which is quite unlikely if you are running the latest stable version of java...
 
Old 05-02-2006, 12:32 AM   #6
686plus
Member
 
Registered: Nov 2004
Location: Portland, Oregon
Distribution: Ubuntu
Posts: 114

Original Poster
Rep: Reputation: 17
Thanks for all the responses. I've deleted ~/.java and my bash profile looks normal.

I use only firefox. Though, I admit I had been browsing some internet backwoods more than usual this week looking for some perl and php scripts and researching some political extremist groups. That was the only thing different in my usage... that could have been the issue.

Thanks for the noscripts extension tip. I had previously disabled that stuff, but a lot of browsing I do is for work and involves local government websites. They tend to be pretty poor and filled with poorly implemented junk. So I turned it back on.

As far as Java goes, after many unsuccessful attempts following the advice of others, I used Stan Finley's instructions http://stanton-finley.net/fedora_cor...otes.html#Java
That used jre 5 update 6.

Thanks again.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Best Binary Downloader ausm MEPIS 1 11-16-2005 03:52 PM
Batch downloader? Libd20 Linux - Software 2 04-20-2005 08:38 PM
Downloader for redhat essoft478 Linux - Software 4 11-10-2004 09:27 PM
downloader.... duker_d_cooker Linux - General 1 03-10-2004 02:41 AM
Java VM not detected apollonius Linux - General 0 10-01-2001 10:27 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:28 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration