Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Is this spyware?

Thread Tools
 
Search this Thread
 
Old 03 June 2005, 03:56 PM
  #1  
DJ140
Scooby Regular
Thread Starter
 
DJ140's Avatar
 
Join Date: Oct 2001
Location: North Yorks, MY03 PPP, now run a Mondeo ST TDCI 06
Posts: 1,032
Likes: 0
Received 0 Likes on 0 Posts
Unhappy Is this spyware?

My Norton IS keeps advising me to block a file called: jwkavzph.exe.

Is this spyware/virus and if so, although I keep telling the firewall to always block this file, why does the warning keep appearing?!

Dan
Old 03 June 2005, 04:03 PM
  #2  
bioforger
Scooby Regular
iTrader: (1)
 
bioforger's Avatar
 
Join Date: Jan 2002
Location: Pig Hill, Wiltsh1te
Posts: 16,995
Received 5 Likes on 5 Posts
Default

Find the file and do a properties on it, to see if u can determine what its for. Does look iffy though. Or to completely contradict myself it could be a harmless file, java runtime file maybe?
Old 03 June 2005, 04:48 PM
  #3  
16vmarc
Scooby Regular
 
16vmarc's Avatar
 
Join Date: May 2004
Location: Shell Garage, York
Posts: 10,059
Likes: 0
Received 0 Likes on 0 Posts
Default

Maybe it keeps appearing because its still there and all Norton doing is stopping it from running?
Old 03 June 2005, 07:06 PM
  #4  
Nicks VR4
Scooby Regular
 
Nicks VR4's Avatar
 
Join Date: May 2003
Posts: 1,165
Likes: 0
Received 0 Likes on 0 Posts
Default

Some Virus's can randomly create a .exe file

Make sure you are up to date with you Virus Signatures

If not sure you can submit to VirusTotal and they can scan the file using various Anti Virus Software

http://www.virustotal.com/flash/index_en.html

Nick
Old 04 June 2005, 09:15 AM
  #5  
DJ140
Scooby Regular
Thread Starter
 
DJ140's Avatar
 
Join Date: Oct 2001
Location: North Yorks, MY03 PPP, now run a Mondeo ST TDCI 06
Posts: 1,032
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by 16vmarc
Maybe it keeps appearing because its still there and all Norton doing is stopping it from running?
I've booted in safe mode and edited the file to stop it being run, properties, security, deny access and it still keeps trying to start. IS there nothing I can do other than re-install Windows etc.

There must be a program that can disable this file.

Dan
Old 04 June 2005, 09:22 AM
  #6  
alistair
Scooby Senior
 
alistair's Avatar
 
Join Date: Oct 1998
Posts: 2,015
Likes: 0
Received 0 Likes on 0 Posts
Default

Have you tried the Microsoft Anti - Spyware program that you can download for free ?

It found & removed a number of things on my PC that everything else had either missed or couldn't remove.
Old 04 June 2005, 09:27 AM
  #7  
DJ140
Scooby Regular
Thread Starter
 
DJ140's Avatar
 
Join Date: Oct 2001
Location: North Yorks, MY03 PPP, now run a Mondeo ST TDCI 06
Posts: 1,032
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by alistair
Have you tried the Microsoft Anti - Spyware program that you can download for free ?

It found & removed a number of things on my PC that everything else had either missed or couldn't remove.
Tried Spyware. It removes the files everytime I run it, but they keep coming back.

I've had to block this file 6 times in the last 20 minutes.
Old 05 June 2005, 12:40 AM
  #8  
fast bloke
Scooby Regular
 
fast bloke's Avatar
 
Join Date: Nov 2000
Posts: 26,619
Likes: 0
Received 0 Likes on 0 Posts
Default

looks suspiciously like a spyware I had recently - kept trying to install kavsys.exe with a couple of letters changed every time so zonealarm got confused. The very helpful chappies at www.geekstogo.com had me sorted in no time (without a rebuild )
Old 06 June 2005, 12:30 PM
  #9  
MarkV
Scooby Regular
 
MarkV's Avatar
 
Join Date: Jun 2005
Posts: 113
Likes: 0
Received 0 Likes on 0 Posts
Default

Hi

good free download is a prog called Spybot - just put in search engine and it will give loads of options to download. This prog will sweep your system and identify and enable you to get rid of all sorts of nasties such a tracking cookies etc.

Mark
Old 06 June 2005, 01:37 PM
  #10  
Wurzel
Scooby Senior
iTrader: (1)
 
Wurzel's Avatar
 
Join Date: Nov 2000
Location: Wildberg, Germany/Reading, UK
Posts: 9,708
Likes: 0
Received 73 Likes on 54 Posts
Cool

Yes it is and it is a particularly nasty one if it is what I think it is.

do you have a file in \windows or \windows\system32 called Nail.exe

if yes then you are infected with the better,internet aurora spyware which is a real **** to get rid of, but not impossible. It appears about 3 times in the registery.

search the registery for nail.exe and delete it, you will also find it in the shell key which should just have explorer in it not the nail bit.

you also need to find the file and set all permissions to deny and do the same for the erronious file you mentioned. you will also need to kill the file process in task manager.

you will also need to delete an entire reg key called aurora.

once you have set permissions to deny and deleted all the files you need to reboot.

if you do not set permissions to deny then the erronious file will continue to respawn itself and if you try to delete nail.exe it will also respawn itself.

Also look in teh directory C:\system volume information it is a hidden system directory so you will need to unhide it and add yourself to the permissions list.
look in here at the RP directories for any .exe files that have TODO in teh file description and delete them. your norton should tell you if these directories are infected before you mess around in this directory.

hope this helps.

ps NONE of the spyware killers will remove this, you need to do it manually.

This is the company responsible for it!!

"New York, New York – April 26, 2005 – Direct Revenue today announced the launch of its newest ad client, Aurora™. "

Last edited by Wurzel; 06 June 2005 at 01:48 PM.
Old 06 June 2005, 01:42 PM
  #11  
SJ_Skyline
Scooby Senior
 
SJ_Skyline's Avatar
 
Join Date: Apr 2002
Location: Limbo
Posts: 21,922
Likes: 0
Received 1 Like on 1 Post
Default

If you have no joy with the above or they say they have removed the program only for it to reappear then it could be CWS which is a particular nasty little s0d to get rid of.

CWSShredder removal tool
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Rumplestiltskin!
Computer & Technology Related
14
11 January 2005 12:34 AM
stevem2k
Computer & Technology Related
14
08 January 2005 08:13 PM
BuRR
Computer & Technology Related
4
05 December 2003 08:03 PM



Quick Reply: Is this spyware?



All times are GMT +1. The time now is 11:18 AM.