Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Hi all,
I suspect my computer somehow got a Trojan horse or some type of virus. The symptoms are: when trying to follow links off from the main pages of major sites like yahoo.com or google.com, the Web pages cannot not be loaded. After rebooting the machine, I could follow a few links and then the hassle started all over.
I had to download the Opera browser to see that the connection was being closed from the server -unlike IE or Netscape, Opera shows an error message "Server www.yahoo.com closed the connection".
Rebooting the machine and killing hjmwavd.exe from TaskMgr took care of the problems.
Any ideas how this executable could have spread, what it is doing, and how to prevent such infections in the future are gladly accepted.
If you send an email address, I can email you the file as an attachment. Below are the reg keys I found on my computer related to this file.
Thanks,
Peter
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Update Machine"="hjmwavd.exe"[HKEY_LOCAL_MACHINE\SOFTWARE\Krypton\"C:-WINDOWS-System32-hjmwavd.exe" ]
"K-Key"=hex:96,ec,60,6a,72,07,5e,d2[HKEY_LOCAL_MACHINE\SOFTWARE\Krypton\C:-WINDOWS-System32-hjmwavd.exe 1720 "C:-WINDOWS-system32-wuamgrd.exe"]
"K-Key"=hex:b0,f6,ea,5d,9a,80,b3,c5[HKEY_LOCAL_MACHINE\SOFTWARE\Krypton\wuamgrd.exe]
"K-Key"=hex:03,51,f0,e7,d4,ea,1f,76[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Update Machine"="hjmwavd.exe"[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Update Machine"="hjmwavd.exe"
"won update"="wapdate.exe"[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Update Machine"="hjmwavd.exe"
"won update"="wapdate.exe"[HKEY_USERS\S-1-5-21-2052111302-1580436667-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Update Machine"="hjmwavd.exe"

you need to delete all of those.
To prevent this happening again get a good firewall like zone alarm. The personal edition is free.
www.download.com

hjmwavd.exe and wapdate.exe,these look like Worm.agobot or Worm.sdbot.Can you send two files with compressed files to me?my email:virus@shanguo.com

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |