Computing.Net > Forums > Windows XP > what is ja.exe?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

what is ja.exe?

Reply to Message Icon

Name: sherryt
Date: September 9, 2006 at 21:36:48 Pacific
OS: xp home,sp2
CPU/Ram: 3200+ AMD Athlon /512 mb
Product: compaq
Comment:

i just noticed ja.exe running in task manager. Never saw it there before. what is it?


XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN



Sponsored Link
Ads by Google

Response Number 1
Name: Johnw
Date: September 9, 2006 at 22:57:39 Pacific

Response Number 2
Name: sherryt
Date: September 10, 2006 at 06:11:04 Pacific
Reply:

i had already done the google search. I dont really understand what it is or where it came from though.

XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN


0

Response Number 3
Name: Martin Crandall
Date: September 10, 2006 at 07:36:23 Pacific
Reply:

WOW!!!!!!!!

9th listing down is a nice FAKE M$ download site. It even has links to the real M$ site.

Although it looks legit, the websites real name is "sourceofallevil.com".

What have you done so far? AV, Spyware scans? With what products?

How many Running Processes?

_________________________
Embrace paranoia, they ARE out to get you!


0

Response Number 4
Name: sherryt
Date: September 10, 2006 at 08:29:52 Pacific
Reply:

I search for the file on my comp. Not there. I stopped the ja.exe from running in my task manager.
I ran freedom anti spyware and found 96 culprits and deleted them. Then it found 5 listed as unknown dialers. i deleted those.
cowbunga.exe kept coming up in my program file under games, i uninstalled that and also found it in my registry and deleted it there.
My anti virus program stopped working. I had to unintall it and redownload it.
Also my keyboard buttons stopped working. I did a system restore. didnt help.
is there any place else i should look for this so i know i got it all?


XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN


0

Response Number 5
Name: sherryt
Date: September 10, 2006 at 08:59:03 Pacific
Reply:

i just ran ewido and it found an infected file in
file: hpsysdrv.exe
path: C:\windows\system
infection: Downloader.Agent.awf

is it safe to click clean ?

XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN


0

Related Posts

See More



Response Number 6
Name: Martin Crandall
Date: September 10, 2006 at 09:32:12 Pacific
Reply:

http://www.liutilities.com/products/wintaskspro/processlibrary/hpsysdrv/

_________________________
Embrace paranoia, they ARE out to get you!


0

Response Number 7
Name: Johnw
Date: September 11, 2006 at 02:35:36 Pacific
Reply:


Downloader.Agent is your infection, ewido is your tool to find infections, anything it finds, delete.
Downloader.Agent
http://www.google.com.au/search?hl=en&q=Downloader.Agent&btnG=Search&meta=


0

Response Number 8
Name: sherryt
Date: September 11, 2006 at 06:25:15 Pacific
Reply:

ewido found the purity trojan. sdexe.exe
and and !update, in doc and settings,i deleted those.
the problem being is that all the other files, 6 in all that ewido found were all system files, such as the one i listed above, hpsysdrv.exe, and ISUSPM.exe, sgtray.exe and 3 others. I did not delete these. I'm just alittle leary about deleting everything that alot of these programs find, especially if they look to be system files. I have done this before and done some damage. If anyone can assure me that its definately/positively ok to clean the files
ewido finds, then i'll rerun the scan. I need to be sure and i'm not saying anyone here doesnt know what theyre talking about. I'm saying ive had experience with these scanners before and know the damage they can cause, by misrepresenting what a file is.
I did a google on downloader agent awf and didnt find a whole lot related to my problems. They refer to it as downloader w32 agent awf. I'll continue to look.
hijack this came up clean, i went to their site and did the analysis. I reran freedom, both the anti virus and the anti spyware, it came up clean. Trend micros online scan didnt find this either.
Any thoughts on what i might do at this point?

XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN


0

Response Number 9
Name: dahli
Date: October 25, 2006 at 14:15:51 Pacific
Reply:

Hello sherryt,

Do you still have ja.exe on your computer?

Steve


0

Response Number 10
Name: sherryt
Date: October 29, 2006 at 15:28:08 Pacific
Reply:

No, i think i got rid of it with everything i did.

XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN


0

Response Number 11
Name: dahli
Date: October 29, 2006 at 15:38:59 Pacific
Reply:

go to Start > Run and type:

cmd.exe

and ok. Copy and paste the below string after the prompt > and hit Enter.

dir /s /a "c:\ja*.*" > c:\find.txt & start notepad c:\find.txt

Your drive will be scanned and when finished, Notepad will pop up with some information. Copy and paste it in this thread.

Also, Go [url=http://noahdfear.geekstogo.com/FindAWF.exe]here[/url] and download and run FindAWF.

When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt here

Steve


0

Response Number 12
Name: sherryt
Date: October 30, 2006 at 06:56:52 Pacific
Reply:

this was from the scan-

Volume in drive C is PRESARIO
Volume Serial Number is 44F9-5DE4

Directory of c:\Documents and Settings\Administrator\Application Data\Sun

10/20/2004 08:39 AM <DIR> Java
0 File(s) 0 bytes

Directory of c:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment

10/20/2004 08:39 AM <DIR> javaws
0 File(s) 0 bytes

Directory of c:\Documents and Settings\Administrator\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}

10/20/2004 08:39 AM 9,207,808 Java 2 Runtime Environment, SE v1.4.2_03.msi
1 File(s) 9,207,808 bytes

Directory of c:\Documents and Settings\All Users\Application Data\Zero Knowledge\Freedom\FormFillerScripts

09/11/2006 02:23 AM 91 jackpot.com.dat
1 File(s) 91 bytes

Directory of c:\Documents and Settings\Compaq_Owner\.housecall6.6

09/10/2006 11:04 AM <DIR> jars
0 File(s) 0 bytes

Directory of c:\Documents and Settings\Compaq_Owner\Application Data\Sun

10/20/2004 08:39 AM <DIR> Java
0 File(s) 0 bytes

Directory of c:\Documents and Settings\Compaq_Owner\Application Data\Sun\Java\Deployment

10/20/2004 08:39 AM <DIR> javaws
0 File(s) 0 bytes

Directory of c:\Documents and Settings\Compaq_Owner\Application Data\Sun\Java\Deployment\cache

09/11/2006 09:15 AM <DIR> javapi
0 File(s) 0 bytes

Directory of c:\Documents and Settings\Compaq_Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0

10/29/2006 04:19 PM <DIR> jar
0 File(s) 0 bytes

Directory of c:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}

10/20/2004 08:39 AM 9,207,808 Java 2 Runtime Environment, SE v1.4.2_03.msi
1 File(s) 9,207,808 bytes

Directory of c:\Documents and Settings\Compaq_Owner\Local Settings\Temp

10/29/2006 04:19 PM 2,496 java_install_reg.log
1 File(s) 2,496 bytes

Directory of c:\Documents and Settings\Compaq_Owner\Local Settings\Temp\pft6.tmp\KBD\static

10/18/2006 07:54 AM <DIR> JA
0 File(s) 0 bytes

Directory of c:\Documents and Settings\Compaq_Owner\My Documents\AIM Logs\Mystery101X

09/05/2005 11:35 PM <DIR> jammin i seh
0 File(s) 0 bytes

Directory of c:\Documents and Settings\Compaq_Owner\My Documents\AIM Logs\x2shay2you

06/29/2005 04:48 AM <DIR> jammin i seh
0 File(s) 0 bytes

Directory of c:\Documents and Settings\Compaq_Owner\My Documents\My Pictures

02/07/2006 10:44 AM 22,814 jack.gif
1 File(s) 22,814 bytes

Directory of c:\Documents and Settings\Default User\Application Data\Sun

10/20/2004 08:39 AM <DIR> Java
0 File(s) 0 bytes

Directory of c:\Documents and Settings\Default User\Application Data\Sun\Java\Deployment

10/20/2004 08:39 AM <DIR> javaws
0 File(s) 0 bytes

Directory of c:\Documents and Settings\Default User\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}

10/20/2004 08:39 AM 9,207,808 Java 2 Runtime Environment, SE v1.4.2_03.msi
1 File(s) 9,207,808 bytes

Directory of c:\hp\drivers\modem_motorola

08/11/2004 07:23 PM 64,276 japanese.chm
1 File(s) 64,276 bytes

Directory of c:\hp\KBD\STATIC

10/18/2006 07:55 AM <DIR> JA
0 File(s) 0 bytes

Directory of c:\Program Files

04/26/2006 06:28 PM <DIR> Java
0 File(s) 0 bytes

Directory of c:\Program Files\Adobe\Acrobat 6.0\Reader

09/16/2006 08:51 AM <DIR> Javascripts
0 File(s) 0 bytes

Directory of c:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\PictureTasks\Templates

05/14/2003 10:53 PM 6,690 japanesepostcard_35.pdf
05/14/2003 10:53 PM 6,719 japanesepostcard_fit.pdf
05/14/2003 10:53 PM 6,814 japanesepostcard_indx.pdf
05/14/2003 10:53 PM 6,742 japanesepostcard_wal.pdf
4 File(s) 26,965 bytes

Directory of c:\Program Files\Common Files

10/20/2004 08:39 AM <DIR> Java
0 File(s) 0 bytes

Directory of c:\Program Files\Crossword Compiler\Puzzles

04/03/2005 07:53 AM <DIR> Java
0 File(s) 0 bytes

Directory of c:\Program Files\Crossword Compiler\Templates

04/03/2005 07:53 AM <DIR> Java
0 File(s) 0 bytes

Directory of c:\Program Files\HP\Digital Imaging\DocProc

09/25/2002 01:29 PM 2 Jap.ytr
09/25/2002 01:32 PM 1,572,948 JAPCLAS.DIC
09/25/2002 01:32 PM 132,285 JAPLANG.DIC
09/25/2002 01:32 PM 1,968,677 JAPPP.DIC
4 File(s) 3,673,912 bytes

Directory of c:\Program Files\HP PhotoSmart\210_215 Camera\PhotoImpression\Fantasy\SPORTS

11/29/1999 11:51 AM 242,592 JAVELIN.psf
1 File(s) 242,592 bytes

Directory of c:\Program Files\Java\jre1.5.0_06\bin

11/10/2005 12:22 PM 24,698 jaas_nt.dll
11/10/2005 12:22 PM 118,890 java.dll
11/10/2005 10:27 AM 49,248 java.exe
11/10/2005 12:03 PM 45,171 javacpl.exe
11/10/2005 10:27 AM 49,250 javaw.exe
11/10/2005 12:22 PM 147,456 JavaWebStart.dll
11/10/2005 12:03 PM 127,078 javaws.exe
11/10/2005 12:22 PM 32,881 java_crw_demo.dll
11/10/2005 12:22 PM 24,679 jawt.dll
9 File(s) 619,351 bytes

Directory of c:\Program Files\Java\jre1.5.0_06\lib

04/26/2006 06:28 PM <DIR> javaws
03/02/2006 03:51 PM 765,482 javaws.jar
1 File(s) 765,482 bytes

Directory of c:\Program Files\Java\jre1.5.0_06\lib\security

04/26/2006 06:28 PM 2,221 java.policy
04/26/2006 06:28 PM 10,151 java.security
04/26/2006 06:28 PM 132 javaws.policy
3 File(s) 12,504 bytes

Directory of c:\Program Files\Java\jre1.5.0_06\lib\zi\America

04/26/2006 06:28 PM 233 Jamaica
1 File(s) 233 bytes

Directory of c:\Program Files\Java\jre1.5.0_06\lib\zi\Asia

04/26/2006 06:28 PM 129 Jakarta
04/26/2006 06:28 PM 85 Jayapura
2 File(s) 214 bytes

Directory of c:\WINDOWS

10/20/2004 01:00 AM <DIR> java
0 File(s) 0 bytes

Directory of c:\WINDOWS\Sun

02/04/2005 08:03 AM <DIR> Java
0 File(s) 0 bytes

Directory of c:\WINDOWS\system32

11/10/2005 10:27 AM 49,248 java.exe
04/11/2003 01:04 AM 139,264 JavaAccessBridge.dll
11/10/2005 10:27 AM 49,250 javaw.exe
11/10/2005 12:03 PM 127,078 javaws.exe
04/11/2003 01:04 AM 28,672 JAWTAccessBridge.dll
5 File(s) 393,512 bytes

Directory of c:\WINDOWS\system32\config\systemprofile\Application Data\Sun

10/20/2004 08:39 AM <DIR> Java
0 File(s) 0 bytes

Directory of c:\WINDOWS\system32\config\systemprofile\Application Data\Sun\Java\Deployment

10/20/2004 08:39 AM <DIR> javaws
0 File(s) 0 bytes

Directory of c:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}

10/20/2004 08:39 AM 9,207,808 Java 2 Runtime Environment, SE v1.4.2_03.msi
1 File(s) 9,207,808 bytes

Directory of c:\WINDOWS\Temp

10/23/2006 10:31 PM 25,600 ja.exe
1 File(s) 25,600 bytes

Total Files Listed:
39 File(s) 42,681,274 bytes
23 Dir(s) 188,117,598,208 bytes free


XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN


0

Response Number 13
Name: sherryt
Date: October 30, 2006 at 07:12:50 Pacific
Reply:

this is the awf scan results


Find AWF report by noahdfear ©2006


21504 byte files found
~~~~~~~~~~~~~

21504 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~

25600 byte files found
~~~~~~~~~~~~~

25600 C:\WINDOWS\SMINST\RECGUARD.exe
25600 C:\WINDOWS\SYSTEM\HPSYSDRV.exe
25600 C:\WINDOWS\TEMP\JA.exe
25600 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
25600 C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\SGTRAY.exe


25600 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~

C:\WINDOWS\SMINST\RECGUARD.exe
C:\WINDOWS\SYSTEM\hpsysdrv.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\sgtray.exe


26450 byte files found
~~~~~~~~~~~~~

26450 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~

bak folders found
~~~~~~~~~~~


Directory of C:\PROGRA~1\QUICKT~1\BAK

10/20/2004 09:47 AM 98,304 qttask.exe
1 File(s) 98,304 bytes

Directory of C:\WINDOWS\SMINST\BAK

04/14/2004 10:43 PM 233,472 RECGUARD.exe
1 File(s) 233,472 bytes

Directory of C:\WINDOWS\SYSTEM\BAK

05/07/1998 06:04 PM 52,736 hpsysdrv.exe
1 File(s) 52,736 bytes

Directory of C:\WINDOWS\SYSTEM32\BAK

09/12/2003 10:13 PM 98,304 ps2.exe
1 File(s) 98,304 bytes

Directory of C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\BAK

04/17/2004 09:41 PM 196,608 ISUSPM.exe
1 File(s) 196,608 bytes

Directory of C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK

08/19/2003 10:01 AM 110,592 sgtray.exe
1 File(s) 110,592 bytes

Directory of C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\BAK

08/04/2004 07:00 AM 158,208 MSConfig.exe
1 File(s) 158,208 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

98304 Oct 20 2004 "C:\Program Files\QuickTime\bak\qttask.exe"
25600 Oct 11 2006 "C:\WINDOWS\SMINST\RECGUARD.exe"
233472 Apr 14 2004 "C:\WINDOWS\SMINST\bak\RECGUARD.exe"
25600 Oct 11 2006 "C:\WINDOWS\system\hpsysdrv.exe"
52736 May 7 1998 "C:\WINDOWS\system\bak\hpsysdrv.exe"
98304 Sep 12 2003 "C:\hp\drivers\keyboard\PS2.exe"
98304 Sep 12 2003 "C:\WINDOWS\system32\bak\ps2.exe"
25600 Oct 11 2006 "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe"
196608 Apr 17 2004 "C:\Program Files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe"
25600 Oct 11 2006 "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe"
110592 Aug 19 2003 "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe"
158208 Aug 4 2004 "C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe"
158208 Aug 4 2004 "C:\WINDOWS\pchealth\helpctr\binaries\bak\MSConfig.exe"


end of report


XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN


0

Response Number 14
Name: dahli
Date: October 30, 2006 at 10:37:09 Pacific
Reply:

Please open My Computer>c:\>Windows>temp

right-click ja.exe
send to - Compressed/zipped folder

Email the compressed file to me.


Steve


0

Response Number 15
Name: sherryt
Date: October 30, 2006 at 11:46:01 Pacific
Reply:

the file has been sent...

XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN


0

Response Number 16
Name: dahli
Date: October 30, 2006 at 23:01:56 Pacific
Reply:

Go here:

http://www.mytempdir.com/1028211

Download fixawf.bat

Double-click fixawf.bat

Run findawf and post the log

Steve


0

Response Number 17
Name: sherryt
Date: October 31, 2006 at 13:18:16 Pacific
Reply:

hers the log

Find AWF report by noahdfear ©2006


21504 byte files found
~~~~~~~~~~~~~

21504 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~

25600 byte files found
~~~~~~~~~~~~~

25600 C:\WINDOWS\SYSTEM\HPSYSDRV.exe
25600 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
25600 C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\SGTRAY.exe


25600 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~

C:\WINDOWS\SYSTEM\hpsysdrv.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\sgtray.exe


26450 byte files found
~~~~~~~~~~~~~

26450 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~

bak folders found
~~~~~~~~~~~


Directory of C:\PROGRA~1\QUICKT~1\BAK

10/20/2004 09:47 AM 98,304 qttask.exe
1 File(s) 98,304 bytes

Directory of C:\WINDOWS\SMINST\BAK

04/14/2004 10:43 PM 233,472 RECGUARD.exe
1 File(s) 233,472 bytes

Directory of C:\WINDOWS\SYSTEM\BAK

05/07/1998 06:04 PM 52,736 hpsysdrv.exe
1 File(s) 52,736 bytes

Directory of C:\WINDOWS\SYSTEM32\BAK

09/12/2003 10:13 PM 98,304 ps2.exe
1 File(s) 98,304 bytes

Directory of C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\BAK

04/17/2004 09:41 PM 196,608 ISUSPM.exe
1 File(s) 196,608 bytes

Directory of C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK

08/19/2003 10:01 AM 110,592 sgtray.exe
1 File(s) 110,592 bytes

Directory of C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\BAK

08/04/2004 07:00 AM 158,208 MSConfig.exe
1 File(s) 158,208 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

98304 Oct 20 2004 "C:\Program Files\QuickTime\bak\qttask.exe"
233472 Apr 14 2004 "C:\WINDOWS\SMINST\RECGUARD.exe"
233472 Apr 14 2004 "C:\WINDOWS\SMINST\bak\RECGUARD.exe"
25600 Oct 11 2006 "C:\WINDOWS\system\hpsysdrv.exe"
52736 May 7 1998 "C:\WINDOWS\system\bak\hpsysdrv.exe"
98304 Sep 12 2003 "C:\hp\drivers\keyboard\PS2.exe"
98304 Sep 12 2003 "C:\WINDOWS\system32\bak\ps2.exe"
25600 Oct 11 2006 "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe"
196608 Apr 17 2004 "C:\Program Files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe"
25600 Oct 11 2006 "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe"
110592 Aug 19 2003 "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe"
158208 Aug 4 2004 "C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe"
158208 Aug 4 2004 "C:\WINDOWS\pchealth\helpctr\binaries\bak\MSConfig.exe"


end of report


XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows XP Forum Home


Sponsored links

Ads by Google


Results for: what is ja.exe?

what is svchost.exe www.computing.net/answers/windows-xp/what-is-svchostexe-/102772.html

What is autodown.exe? www.computing.net/answers/windows-xp/what-is-autodownexe/104657.html

what is thnall1z.exe and how do I.. www.computing.net/answers/windows-xp/what-is-thnall1zexe-and-how-do-i/139663.html