Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
i just noticed ja.exe running in task manager. Never saw it there before. what is it?
XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN

i had already done the google search. I dont really understand what it is or where it came from though.
XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN

WOW!!!!!!!!
9th listing down is a nice FAKE M$ download site. It even has links to the real M$ site.
Although it looks legit, the websites real name is "sourceofallevil.com".
What have you done so far? AV, Spyware scans? With what products?
How many Running Processes?
_________________________
Embrace paranoia, they ARE out to get you!

I search for the file on my comp. Not there. I stopped the ja.exe from running in my task manager.
I ran freedom anti spyware and found 96 culprits and deleted them. Then it found 5 listed as unknown dialers. i deleted those.
cowbunga.exe kept coming up in my program file under games, i uninstalled that and also found it in my registry and deleted it there.
My anti virus program stopped working. I had to unintall it and redownload it.
Also my keyboard buttons stopped working. I did a system restore. didnt help.
is there any place else i should look for this so i know i got it all?
XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN

i just ran ewido and it found an infected file in
file: hpsysdrv.exe
path: C:\windows\system
infection: Downloader.Agent.awfis it safe to click clean ?
XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN

http://www.liutilities.com/products/wintaskspro/processlibrary/hpsysdrv/
_________________________
Embrace paranoia, they ARE out to get you!

Downloader.Agent is your infection, ewido is your tool to find infections, anything it finds, delete.
Downloader.Agent
http://www.google.com.au/search?hl=en&q=Downloader.Agent&btnG=Search&meta=

ewido found the purity trojan. sdexe.exe
and and !update, in doc and settings,i deleted those.
the problem being is that all the other files, 6 in all that ewido found were all system files, such as the one i listed above, hpsysdrv.exe, and ISUSPM.exe, sgtray.exe and 3 others. I did not delete these. I'm just alittle leary about deleting everything that alot of these programs find, especially if they look to be system files. I have done this before and done some damage. If anyone can assure me that its definately/positively ok to clean the files
ewido finds, then i'll rerun the scan. I need to be sure and i'm not saying anyone here doesnt know what theyre talking about. I'm saying ive had experience with these scanners before and know the damage they can cause, by misrepresenting what a file is.
I did a google on downloader agent awf and didnt find a whole lot related to my problems. They refer to it as downloader w32 agent awf. I'll continue to look.
hijack this came up clean, i went to their site and did the analysis. I reran freedom, both the anti virus and the anti spyware, it came up clean. Trend micros online scan didnt find this either.
Any thoughts on what i might do at this point?XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN

No, i think i got rid of it with everything i did.
XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN

go to Start > Run and type:
cmd.exe
and ok. Copy and paste the below string after the prompt > and hit Enter.
dir /s /a "c:\ja*.*" > c:\find.txt & start notepad c:\find.txt
Your drive will be scanned and when finished, Notepad will pop up with some information. Copy and paste it in this thread.
Also, Go [url=http://noahdfear.geekstogo.com/FindAWF.exe]here[/url] and download and run FindAWF.
When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt here
Steve

this was from the scan-
Volume in drive C is PRESARIO
Volume Serial Number is 44F9-5DE4Directory of c:\Documents and Settings\Administrator\Application Data\Sun
10/20/2004 08:39 AM <DIR> Java
0 File(s) 0 bytesDirectory of c:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment
10/20/2004 08:39 AM <DIR> javaws
0 File(s) 0 bytesDirectory of c:\Documents and Settings\Administrator\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
10/20/2004 08:39 AM 9,207,808 Java 2 Runtime Environment, SE v1.4.2_03.msi
1 File(s) 9,207,808 bytesDirectory of c:\Documents and Settings\All Users\Application Data\Zero Knowledge\Freedom\FormFillerScripts
09/11/2006 02:23 AM 91 jackpot.com.dat
1 File(s) 91 bytesDirectory of c:\Documents and Settings\Compaq_Owner\.housecall6.6
09/10/2006 11:04 AM <DIR> jars
0 File(s) 0 bytesDirectory of c:\Documents and Settings\Compaq_Owner\Application Data\Sun
10/20/2004 08:39 AM <DIR> Java
0 File(s) 0 bytesDirectory of c:\Documents and Settings\Compaq_Owner\Application Data\Sun\Java\Deployment
10/20/2004 08:39 AM <DIR> javaws
0 File(s) 0 bytesDirectory of c:\Documents and Settings\Compaq_Owner\Application Data\Sun\Java\Deployment\cache
09/11/2006 09:15 AM <DIR> javapi
0 File(s) 0 bytesDirectory of c:\Documents and Settings\Compaq_Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0
10/29/2006 04:19 PM <DIR> jar
0 File(s) 0 bytesDirectory of c:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
10/20/2004 08:39 AM 9,207,808 Java 2 Runtime Environment, SE v1.4.2_03.msi
1 File(s) 9,207,808 bytesDirectory of c:\Documents and Settings\Compaq_Owner\Local Settings\Temp
10/29/2006 04:19 PM 2,496 java_install_reg.log
1 File(s) 2,496 bytesDirectory of c:\Documents and Settings\Compaq_Owner\Local Settings\Temp\pft6.tmp\KBD\static
10/18/2006 07:54 AM <DIR> JA
0 File(s) 0 bytesDirectory of c:\Documents and Settings\Compaq_Owner\My Documents\AIM Logs\Mystery101X
09/05/2005 11:35 PM <DIR> jammin i seh
0 File(s) 0 bytesDirectory of c:\Documents and Settings\Compaq_Owner\My Documents\AIM Logs\x2shay2you
06/29/2005 04:48 AM <DIR> jammin i seh
0 File(s) 0 bytesDirectory of c:\Documents and Settings\Compaq_Owner\My Documents\My Pictures
02/07/2006 10:44 AM 22,814 jack.gif
1 File(s) 22,814 bytesDirectory of c:\Documents and Settings\Default User\Application Data\Sun
10/20/2004 08:39 AM <DIR> Java
0 File(s) 0 bytesDirectory of c:\Documents and Settings\Default User\Application Data\Sun\Java\Deployment
10/20/2004 08:39 AM <DIR> javaws
0 File(s) 0 bytesDirectory of c:\Documents and Settings\Default User\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
10/20/2004 08:39 AM 9,207,808 Java 2 Runtime Environment, SE v1.4.2_03.msi
1 File(s) 9,207,808 bytesDirectory of c:\hp\drivers\modem_motorola
08/11/2004 07:23 PM 64,276 japanese.chm
1 File(s) 64,276 bytesDirectory of c:\hp\KBD\STATIC
10/18/2006 07:55 AM <DIR> JA
0 File(s) 0 bytesDirectory of c:\Program Files
04/26/2006 06:28 PM <DIR> Java
0 File(s) 0 bytesDirectory of c:\Program Files\Adobe\Acrobat 6.0\Reader
09/16/2006 08:51 AM <DIR> Javascripts
0 File(s) 0 bytesDirectory of c:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\PictureTasks\Templates
05/14/2003 10:53 PM 6,690 japanesepostcard_35.pdf
05/14/2003 10:53 PM 6,719 japanesepostcard_fit.pdf
05/14/2003 10:53 PM 6,814 japanesepostcard_indx.pdf
05/14/2003 10:53 PM 6,742 japanesepostcard_wal.pdf
4 File(s) 26,965 bytesDirectory of c:\Program Files\Common Files
10/20/2004 08:39 AM <DIR> Java
0 File(s) 0 bytesDirectory of c:\Program Files\Crossword Compiler\Puzzles
04/03/2005 07:53 AM <DIR> Java
0 File(s) 0 bytesDirectory of c:\Program Files\Crossword Compiler\Templates
04/03/2005 07:53 AM <DIR> Java
0 File(s) 0 bytesDirectory of c:\Program Files\HP\Digital Imaging\DocProc
09/25/2002 01:29 PM 2 Jap.ytr
09/25/2002 01:32 PM 1,572,948 JAPCLAS.DIC
09/25/2002 01:32 PM 132,285 JAPLANG.DIC
09/25/2002 01:32 PM 1,968,677 JAPPP.DIC
4 File(s) 3,673,912 bytesDirectory of c:\Program Files\HP PhotoSmart\210_215 Camera\PhotoImpression\Fantasy\SPORTS
11/29/1999 11:51 AM 242,592 JAVELIN.psf
1 File(s) 242,592 bytesDirectory of c:\Program Files\Java\jre1.5.0_06\bin
11/10/2005 12:22 PM 24,698 jaas_nt.dll
11/10/2005 12:22 PM 118,890 java.dll
11/10/2005 10:27 AM 49,248 java.exe
11/10/2005 12:03 PM 45,171 javacpl.exe
11/10/2005 10:27 AM 49,250 javaw.exe
11/10/2005 12:22 PM 147,456 JavaWebStart.dll
11/10/2005 12:03 PM 127,078 javaws.exe
11/10/2005 12:22 PM 32,881 java_crw_demo.dll
11/10/2005 12:22 PM 24,679 jawt.dll
9 File(s) 619,351 bytesDirectory of c:\Program Files\Java\jre1.5.0_06\lib
04/26/2006 06:28 PM <DIR> javaws
03/02/2006 03:51 PM 765,482 javaws.jar
1 File(s) 765,482 bytesDirectory of c:\Program Files\Java\jre1.5.0_06\lib\security
04/26/2006 06:28 PM 2,221 java.policy
04/26/2006 06:28 PM 10,151 java.security
04/26/2006 06:28 PM 132 javaws.policy
3 File(s) 12,504 bytesDirectory of c:\Program Files\Java\jre1.5.0_06\lib\zi\America
04/26/2006 06:28 PM 233 Jamaica
1 File(s) 233 bytesDirectory of c:\Program Files\Java\jre1.5.0_06\lib\zi\Asia
04/26/2006 06:28 PM 129 Jakarta
04/26/2006 06:28 PM 85 Jayapura
2 File(s) 214 bytesDirectory of c:\WINDOWS
10/20/2004 01:00 AM <DIR> java
0 File(s) 0 bytesDirectory of c:\WINDOWS\Sun
02/04/2005 08:03 AM <DIR> Java
0 File(s) 0 bytesDirectory of c:\WINDOWS\system32
11/10/2005 10:27 AM 49,248 java.exe
04/11/2003 01:04 AM 139,264 JavaAccessBridge.dll
11/10/2005 10:27 AM 49,250 javaw.exe
11/10/2005 12:03 PM 127,078 javaws.exe
04/11/2003 01:04 AM 28,672 JAWTAccessBridge.dll
5 File(s) 393,512 bytesDirectory of c:\WINDOWS\system32\config\systemprofile\Application Data\Sun
10/20/2004 08:39 AM <DIR> Java
0 File(s) 0 bytesDirectory of c:\WINDOWS\system32\config\systemprofile\Application Data\Sun\Java\Deployment
10/20/2004 08:39 AM <DIR> javaws
0 File(s) 0 bytesDirectory of c:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
10/20/2004 08:39 AM 9,207,808 Java 2 Runtime Environment, SE v1.4.2_03.msi
1 File(s) 9,207,808 bytesDirectory of c:\WINDOWS\Temp
10/23/2006 10:31 PM 25,600 ja.exe
1 File(s) 25,600 bytesTotal Files Listed:
39 File(s) 42,681,274 bytes
23 Dir(s) 188,117,598,208 bytes free
XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN

this is the awf scan results
Find AWF report by noahdfear ©2006
21504 byte files found
~~~~~~~~~~~~~21504 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~25600 byte files found
~~~~~~~~~~~~~25600 C:\WINDOWS\SMINST\RECGUARD.exe
25600 C:\WINDOWS\SYSTEM\HPSYSDRV.exe
25600 C:\WINDOWS\TEMP\JA.exe
25600 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
25600 C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\SGTRAY.exe
25600 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~C:\WINDOWS\SMINST\RECGUARD.exe
C:\WINDOWS\SYSTEM\hpsysdrv.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\sgtray.exe
26450 byte files found
~~~~~~~~~~~~~26450 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~bak folders found
~~~~~~~~~~~
Directory of C:\PROGRA~1\QUICKT~1\BAK10/20/2004 09:47 AM 98,304 qttask.exe
1 File(s) 98,304 bytesDirectory of C:\WINDOWS\SMINST\BAK
04/14/2004 10:43 PM 233,472 RECGUARD.exe
1 File(s) 233,472 bytesDirectory of C:\WINDOWS\SYSTEM\BAK
05/07/1998 06:04 PM 52,736 hpsysdrv.exe
1 File(s) 52,736 bytesDirectory of C:\WINDOWS\SYSTEM32\BAK
09/12/2003 10:13 PM 98,304 ps2.exe
1 File(s) 98,304 bytesDirectory of C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\BAK
04/17/2004 09:41 PM 196,608 ISUSPM.exe
1 File(s) 196,608 bytesDirectory of C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK
08/19/2003 10:01 AM 110,592 sgtray.exe
1 File(s) 110,592 bytesDirectory of C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\BAK
08/04/2004 07:00 AM 158,208 MSConfig.exe
1 File(s) 158,208 bytes
Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~98304 Oct 20 2004 "C:\Program Files\QuickTime\bak\qttask.exe"
25600 Oct 11 2006 "C:\WINDOWS\SMINST\RECGUARD.exe"
233472 Apr 14 2004 "C:\WINDOWS\SMINST\bak\RECGUARD.exe"
25600 Oct 11 2006 "C:\WINDOWS\system\hpsysdrv.exe"
52736 May 7 1998 "C:\WINDOWS\system\bak\hpsysdrv.exe"
98304 Sep 12 2003 "C:\hp\drivers\keyboard\PS2.exe"
98304 Sep 12 2003 "C:\WINDOWS\system32\bak\ps2.exe"
25600 Oct 11 2006 "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe"
196608 Apr 17 2004 "C:\Program Files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe"
25600 Oct 11 2006 "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe"
110592 Aug 19 2003 "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe"
158208 Aug 4 2004 "C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe"
158208 Aug 4 2004 "C:\WINDOWS\pchealth\helpctr\binaries\bak\MSConfig.exe"
end of report
XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN

Please open My Computer>c:\>Windows>temp
right-click ja.exe
send to - Compressed/zipped folderEmail the compressed file to me.
Steve

Go here:
http://www.mytempdir.com/1028211
Download fixawf.bat
Double-click fixawf.bat
Run findawf and post the log
Steve

hers the log
Find AWF report by noahdfear ©2006
21504 byte files found
~~~~~~~~~~~~~21504 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~25600 byte files found
~~~~~~~~~~~~~25600 C:\WINDOWS\SYSTEM\HPSYSDRV.exe
25600 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
25600 C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\SGTRAY.exe
25600 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~C:\WINDOWS\SYSTEM\hpsysdrv.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\sgtray.exe
26450 byte files found
~~~~~~~~~~~~~26450 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~bak folders found
~~~~~~~~~~~
Directory of C:\PROGRA~1\QUICKT~1\BAK10/20/2004 09:47 AM 98,304 qttask.exe
1 File(s) 98,304 bytesDirectory of C:\WINDOWS\SMINST\BAK
04/14/2004 10:43 PM 233,472 RECGUARD.exe
1 File(s) 233,472 bytesDirectory of C:\WINDOWS\SYSTEM\BAK
05/07/1998 06:04 PM 52,736 hpsysdrv.exe
1 File(s) 52,736 bytesDirectory of C:\WINDOWS\SYSTEM32\BAK
09/12/2003 10:13 PM 98,304 ps2.exe
1 File(s) 98,304 bytesDirectory of C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\BAK
04/17/2004 09:41 PM 196,608 ISUSPM.exe
1 File(s) 196,608 bytesDirectory of C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK
08/19/2003 10:01 AM 110,592 sgtray.exe
1 File(s) 110,592 bytesDirectory of C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\BAK
08/04/2004 07:00 AM 158,208 MSConfig.exe
1 File(s) 158,208 bytes
Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~98304 Oct 20 2004 "C:\Program Files\QuickTime\bak\qttask.exe"
233472 Apr 14 2004 "C:\WINDOWS\SMINST\RECGUARD.exe"
233472 Apr 14 2004 "C:\WINDOWS\SMINST\bak\RECGUARD.exe"
25600 Oct 11 2006 "C:\WINDOWS\system\hpsysdrv.exe"
52736 May 7 1998 "C:\WINDOWS\system\bak\hpsysdrv.exe"
98304 Sep 12 2003 "C:\hp\drivers\keyboard\PS2.exe"
98304 Sep 12 2003 "C:\WINDOWS\system32\bak\ps2.exe"
25600 Oct 11 2006 "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe"
196608 Apr 17 2004 "C:\Program Files\Common Files\InstallShield\UpdateService\bak\ISUSPM.exe"
25600 Oct 11 2006 "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe"
110592 Aug 19 2003 "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe"
158208 Aug 4 2004 "C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe"
158208 Aug 4 2004 "C:\WINDOWS\pchealth\helpctr\binaries\bak\MSConfig.exe"
end of report
XP Home sp2., Compaq Presario SR1330NX, 512mb ram, AMD Athlon, LAN

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |