Pelican Parts Forums

Pelican Parts Forums (http://forums.pelicanparts.com/)
-   Off Topic Discussions (http://forums.pelicanparts.com/off-topic-discussions/)
-   -   File driving me nuts in XP....virus? (http://forums.pelicanparts.com/off-topic-discussions/331291-file-driving-me-nuts-xp-virus.html)

lendaddy 02-19-2007 04:39 PM

File driving me nuts in XP....virus?
 
So out of nowhere this file starts trying to access the internet on my laptop (which I deny), so I run full virus scans and all that and get a couple small issues that I fix but that file remains. Now here's the kicker...Googling the file name gets zero hits!!!!

jjfwaaaa.exe

Anyway, I have found two instances on my machine-

JJFWAAAA.EXE-2AF94DA7.pf (found in my "C:\WINDOWS\Prefetch" folder)

&

jjfwaaaa (found in my "C:\WINDOWS\system32" folder)

What the heck is this thing? And how is it possible that Google and Yahoo can find nothing of it?

legion 02-19-2007 05:00 PM

Don't know what it is. I don't have it. It could be part of some program you have installed.

lendaddy 02-19-2007 05:02 PM

Is there a way to search my computer for other files created at the same time?

Zeke 02-19-2007 05:04 PM

just for the heck of it, I copied that and ran a search. negative. this machine runs XP Media Edition.

lendaddy 02-19-2007 05:06 PM

OK, a search for files modified at the same time turns up a bunch from my "Spyboy search and destroy" program update.

Basquiat 02-19-2007 05:18 PM

okay. been there done that. first turn of your windows restore feature. Otherwise, even once you think it's gone, it will be back. second, go here
http://www.geekstogo.com/forum/Malware_Removal_HiJackThis_Logs_Go_Here-f37.html

Follow the instructions exactly as the are written. They have REAL malware removal tools there.
All the software that they use is freeware as well. Let us know how it's going after you get done.
Goodluck. Man did I go through this once.

lendaddy 02-19-2007 05:22 PM

Quote:

Originally posted by Basquiat
okay. been there done that. first turn of your windows restore feature. Otherwise, even once you think it's gone, it will be back. second, go here
http://www.geekstogo.com/forum/Malware_Removal_HiJackThis_Logs_Go_Here-f37.html

Follow the instructions exactly as the are written. They have REAL malware removal tools there.
All the software that they use is freeware as well. Let us know how it's going after you get done.
Goodluck. Man did I go through this once.

Thanks, but are you saying I have a problem for certain?

Basquiat 02-19-2007 05:54 PM

about 95% sure you have a browser hijacking virus. That .exe file is an executable file. It's probably part of the problem. To get rid of it you'll need to reboot in safe mode, however it won't go away because these files populate in numerous areas. When you try to delete it from one spot, it sort of moves to another. Actually what happens (and i'm not a pro on this stuff by any means) is that root files are added all over the place, so when one gets zapped the other is still alive to do the same thing.
the Geekstogo folks will help you for free. The software DL's that they have, are actually really effective. They also tell you which "anti-virus" programs to avoid. There are tons of them! They are actually viruses themselves.
Anyway, this is a super resource and it's totally free.

Basquiat 02-19-2007 05:58 PM

ps your spybot programs are fine. They just have a similar code thingy to real viruses. Standard anti-virus software seems to ALWAYS be behind the virus curve. By the time they have it figured out, it's too late.

angelny911 02-19-2007 07:25 PM

http://www.symantec.com/index.htm

go to this site and cut and paste it to there search and it will help you get rid of it ,they also have a program that will check your system for spyware , trojans and anti-virus

Angel

slodave 02-19-2007 07:41 PM

Often, these little pests have random names. Because of this Google and Yahoo won't have info. If you right-click on the file and select properties, sometimes it shows a version tab. If it does, you may get lucky and see who made the file. If it does not show the version tab, then it more than likely does not belong.

Dave

Joeaksa 02-19-2007 11:40 PM

Did a google search and came up with nothing. That is not good as if it was a valid Windows file something would have popped up.

Proceed as if its a virus or spyware.

lendaddy 02-20-2007 04:12 AM

Thanks guys, I, on the path Basquiat gave me (thanks again). I'll let you know more when I finish.

angelny911 02-20-2007 07:25 AM

lendaddy try the symtec site i sent you it will lead you in the right direction

lendaddy 02-20-2007 07:34 AM

Thanks angel, but I've got 8 hours into the other path and my files are being reviewed by advisors now (free too which is neat). I'm getting there:D


All times are GMT -8. The time now is 10:45 PM.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website


DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.