[quote name=\'guestolo\' date=\'Apr 28 2005, 09:27 PM\']With windows set to show hidden files and folders
Navigate to your C:\WINDOWS\system32\ folder
Open the folder and look for this bad guy
C:\WINDOWS\system32\j?vaw.exe
The ? mark will not show but it may be in disguise as a legit file by the name of javaw.exe
You don't appear to have Sun Java installed but look for that file name
Right click on javaw.exe and left click properties
If the approximate size is about 415kb and a date of
08/02/2005
Send it to the recycle bin
Then come back here and post a fresh hijackthis log and double click on Export.bat again and post the findings
[post=\"37735\"]<{POST_SNAPBACK}>[/post]
[/quote]
hi, have found javaw.exe in system32 ,
type of file ,application, size 408kb, created on 20/2/05, but modified on 8/2/05 ,dont understand how that can be. But when tried to send to recycle bin, says cannot delete, access is denied, make sure disk is not full or write protected and is not currently in use .
[quote name=\'jacko\' date=\'May 1 2005, 05:03 PM\']HI, FOUND THE FILE IN WINDOWS , ITS AN APPLICATION,SIZE 36KB,CREATED ON 2/9/04 ,MODIFIED ON 19/9/03. HAVE DONE THE SCAN ON JOTTIS ,SCANNER RESULT ATTACHED. THANKS ,HOPE THIS HELPS ,PLEASE LET ME KNOW WHAT IT IS BECAUSE IM CURIOUS NOW.
Jotti's malware scan 2.99-TRANSITION_TO_3.00
File to upload & scan: Virus
Service
Service load:
0% 100%
File: ShowWnd.exe
Status:
OK
MD5 b8e7353996d0757e2b8f47be702074be
Packers detected:
-
Scanner results
AntiVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
Found nothing
mks_vir
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
VBA32
Found nothing
Powered by
images/antivir.png images/avast.png images/avg.gif images/bitdefender.png images/clamav-logo1.png images/drweb.gif images/f-prot.png images/fortinet.gif images/kaspersky.png images/mks.png images/nod32.gif images/norman.png images/vba32.png
Disclaimer
[post=\"38395\"]<{POST_SNAPBACK}>[/post]
[/quote]