WinPatrol states Sun Java has Virus-Yes or No?

Discussion in 'Software' started by msjones, Jul 25, 2010.

  1. msjones

    msjones Private E-2

    Hello,

    My os is Vista and my security program is Microsoft Security Essentials. I also use WinPatrol, MABAM, SAS and CCleaner.

    I searched for further information on a Sun Java Active X entry in WinPatrol: deployjava1.dll. WinPatrol's information database has flagged it as a virus:

    Virus Alert – DEPLOYJAVA1.DLL

    Deployjava1.dll will be found in your Windows\System or System32 folder. It installs with Rootkit.TDSS.Gen and Backdoor:Win32/Nuwar.A . Rootkit.TDSS.gen installs as a rootkit. It displays random popups, attempts to redirect browser searches and may disable your antivirus software. Backdoor.Win32/Nuwar.A runs on system startup and may allow a remote user to access your system. You'll find more information at http://www.pctools.com/mrc/infections/id/Rootkit.TDSS/ and at http://www.sophos.com/security/analyses/viruses-and-spyware/w32nuwara.html.


    At the time I checked the Active X I was running Sun Java 6.20. I uninstalled it and installed 6.21 and the Active X still remains. MSE, SAS and MBAM found nothing. Further Google research was inconclusive and a Twitter to BillP resulted in a suggestion to scan the link using VirusTotal, which also was negative.

    In the meantime I have removed the item. Does anyone have any information regarding this Active X?
     
  2. pwillener

    pwillener MajorGeek

    I have deployJava1.dll in my %WINDIR%\system32 folder, and it seems legitimate to me. The description shows "Java(TM) Platform SE binary" and the version is "6.0.210.6", which is consistent with JRE 6u21. The size is 413KB.

    If the deployJava1.dll file you have is different, then there may be a problem.
     
  3. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    As stated above if your depolyjava1.dll is in the C:\windows\system32 folder it is a legit location for that file to be, I have it there also.

    What you likely have is WinPatrol falsely flagging this up as malware (called a False Positive) and you may have to wait until WinPatrol get a new corrected definition file released.

    The W32/Nuwar-A malware for instance randomely generates names for itself unlike leaving a file called deployjava1.dll your link mentions this in its more info tab and also you should if infected with this malware have a startup called kernels32.exe in your startup list, look in your WinPatrol startup tab.

    Now you may have a problem if the deployjava1.dll was located in %Temp%\deployJava1.dll

    As for what it is it looks like without looking further into it a developer deployment file from Sun Java, if it is needed or not, doesnt look as clear, but you will soon know if your Java apps and webpages stop working, what I do remember is Sun from Java 20 closed off a few security bugs and moving that file could have been one of such fixes.

    What stands out is nothing else is flagging it as nasty so far.
     
  4. pwillener

    pwillener MajorGeek

    Not quite sure how CCleaner comes into this discussion...? It's just a cleaning tool; it does not prevent anything from downloading or installing.
     
  5. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi pwillener

    I think Keylogger Victim is mistaking cookies as being a problem and can be allowed or disallowed via CCleaner in which CCleaner will only allow you to "keep" cookies you wish to, this allows you to say keep the login cookie from your favoured website or forum from being deleted when you run CCleaner and that is all. It has no blocking capabilities.

    Cookies for those reading are not an issue and for a good write up on this please read section 12 of this guide HERE


    Back to the question of deployjava1.dll and if it is malware or not, I decided to do a test today and installed a clean Virtual PC as I needed to test a couple of apps in XP SP3 and decided to also install Java 6 update 21 to see what was happening in relation to this file, this was a bare-ish install and the two whiteout apps are something I'm testing and not for release yet, so no malware what so ever.

    These are no Java installed and the win32 folder has no deployjava1.dll
    http://img97.imageshack.us/img97/2899/57392152.jpghttp://img820.imageshack.us/img820/6674/96132209.jpg

    These are with Java 6 update 21 installed, with deployjava1.dll showing in Windows32 folder in red circle.
    http://img695.imageshack.us/img695/9735/36778075.jpghttp://img137.imageshack.us/img137/3451/72124347.jpg

    All I can say from this is WinPatrol has a false positive.
     
  6. msjones

    msjones Private E-2

    Thank you everyone for your responses.

    I uninstalled Sun Java 6/20 and installed 6/21. WinPatrol again showed deployjava, however this time it was not flagged as a virus. To be on the safe side, I disabled and removed it. As it has been stated, it probably was a false positive by MSE.

    I have run several scans with different softwares and thankfully nothing was found.

    Again, thank you all.
     
  7. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    Dont think Microsoft Security Essentials is the issue, it was WinPatrol that flagged it for you, wasnt it?
    I run MSE on two laptops and its not flagged that, dont use WinPatrol though.


    But glad nothing is being flagged now :)
     
  8. msjones

    msjones Private E-2

    Yes, I returned to correct my mistake, however it was too late. I meant WinPatrol not MSE.

    Thank you.
     
  9. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Ah no probs msjones :) what I was going to say if it was MSE then I could flag this up at Microsoft and the MSE team, that they where flagging up a legit file.

    Do let us know if this crops up again, its more likely if WinPatrol flags it up again (but not now as malware) it will be when Java updates next time as that file will be regenerated in the same location again.

    So just we weary of that, and again cheers for coming back with your info it helps me and others.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds