Author Topic: hundreds of javaws.exe  (Read 4028 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
hundreds of javaws.exe
« on: November 12, 2015, 02:37:40 AM »
I logged onto my Windows 7 PC today and found that it had restarted overnight to install some updates. After maybe 4 or 5 minutes, I noticed the computer was being really slow, and something was taking up 95% of of my RAM. I opened task manager to see that there were literally hundreds of copies of javaws.exe running in the background. After a few minutes spent trying to look up the problem, I reset the computer and did a boot scan with Avast, which found nothing. The problem happened again after I logged back on, so I used JavaRa to uninstall all versions of Java, and the problem stopped. I then performed a scan with Malwarebytes, and it found nothing. I recognize that this may not apply to my computer, but someone mentioned a keylogger when addressing a similar problem, so I'm a bit worried.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: hundreds of javaws.exe
« Reply #1 on: November 12, 2015, 02:57:53 AM »
You can never be too safe when it comes to keyloggers. https://forum.avast.com/index.php?topic=53253.0
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Rednose

  • Pirate Party Member
  • Avast Überevangelist
  • Massive Poster
  • *****
  • Posts: 3738
  • Bits of Freedom : https://www.bof.nl
    • Nederlandstalig Avast! forum
Re: hundreds of javaws.exe
« Reply #2 on: November 12, 2015, 03:14:37 AM »
Hi alienbutt99, welcome to the forum :)

Please follow the directions from the link Michael posted above, and attach the requested logs in your next reply.
As soon as an expert is online and available he/she will help you.

Greetz, Red.
OS: Win 10 / iOS 17 / Debian 12 / Tails 6
Real Time: Avast Premium Security
On Demand: Malwarebytes
VPN: NordVPN ( NordLynx ) with Threat Protection ( Lite )

REDACTED

  • Guest
Re: hundreds of javaws.exe
« Reply #3 on: November 12, 2015, 04:39:32 AM »
Sorry about that. Here are all the requested files.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: hundreds of javaws.exe
« Reply #4 on: November 12, 2015, 03:41:37 PM »
Nothing evident showing, what may have happened is that the Java update task got caught in a loop

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
BHO: No Name -> {41edcba0-cb7c-463e-8b52-9b09edbb8534} -> No File
BHO-x32: No Name -> {41edcba0-cb7c-463e-8b52-9b09edbb8534} -> No File
BHO-x32: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Task: {ED848FB3-CD50-47AE-9A68-3C618C4E5FC3} - System32\Tasks\off
Task: {F4B7394E-6CB4-4BA0-8C70-FFEF7FAF0096} - \Optimizer Pro Schedule -> No File <==== ATTENTION
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: hundreds of javaws.exe
« Reply #5 on: November 12, 2015, 11:16:21 PM »
Done. Here's the log.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: hundreds of javaws.exe
« Reply #6 on: November 13, 2015, 01:42:52 PM »
How is the computer behaving now ?

REDACTED

  • Guest
Re: hundreds of javaws.exe
« Reply #7 on: November 13, 2015, 04:30:14 PM »
It seems fine. No problems so far. Should I try to reinstall Java?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: hundreds of javaws.exe
« Reply #8 on: November 13, 2015, 04:36:55 PM »
Do you actually need Java ?  I have not had it on my system for a few years now

REDACTED

  • Guest
Re: hundreds of javaws.exe
« Reply #9 on: November 13, 2015, 04:40:56 PM »
A lot of games still use Java, but I guess I don't really need it, so nevermind.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: hundreds of javaws.exe
« Reply #10 on: November 13, 2015, 06:57:27 PM »
Try for a while without it, if you do find you need it then re-install.  But, java is one of the most commonly attacked programmes

REDACTED

  • Guest
Re: hundreds of javaws.exe
« Reply #11 on: November 13, 2015, 07:00:55 PM »
Will do. Thanks for your help!