This Bugzilla instance is a read-only archive of historic NetBeans bug reports. To report a bug in NetBeans please follow the project's instructions for reporting issues.

Bug 130318 - Latest build may contain 007guard malware
Summary: Latest build may contain 007guard malware
Status: RESOLVED INVALID
Alias: None
Product: installer
Classification: Unclassified
Component: Code (show other bugs)
Version: 6.x
Hardware: All All
: P1 blocker (vote)
Assignee: issues@installer
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2008-03-17 18:18 UTC by kvgeorge1
Modified: 2008-04-16 11:00 UTC (History)
1 user (show)

See Also:
Issue Type: DEFECT
Exception Reporter:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description kvgeorge1 2008-03-17 18:18:23 UTC
I just downloaded the latest build of NB 6.1 IDE (200803170003) and when I started the IDE, I could not launch the 
browser for my webproject because the port was in-use (8084 for Tomcat).  When I looked at the connections being used 
via NETSTAT, I noticed that my machine was making connections to 007guard.com for port 8084, along with other ports on 
the machine.  This happened only after I installed the latest NB download.

Please check the build to ensure that there is no SpyWare/MalWare on the build.
Comment 1 kvgeorge1 2008-03-18 00:21:27 UTC
My apologies, it turns out that this is not the case.  I did further digging and what was happening is that the 
installation did not use the configured settings for 6.1 beta for the apache installation and therefore was complaining 
that the admin was not setup correctly in the configuration and at one time I did see a bind request failure because 
8084 was already in-use (probably from a failed launch earlier).

Unfortunately, WINDOWS uses the first address in the HOSTS file for a particular definition (in this case 007guard.com) 
was in my HOSTS file to prevent this particular malware from installing.  However, when doing a NetStat - 007guard.com 
appeared to be opening connections to external addresses.

In my search to understand 007guard.com, there is a detailed article that this particular malware rides on java 
sources/binary packages and was most probably the cause of the condition.

I sincerely apologize if I caused any panic and concern over this - it was totally my issue from the start.