Author Topic: I need help getting rid of a malware/virus??? jlwjwpashdw.exe.  (Read 3181 times)

0 Members and 1 Guest are viewing this topic.

aerolls

  • Guest
I have this virus/malware??? called jlwjwpashdw.exe. that I can't seem to get out of my computer. It's basically a Windows Shield program that comes alive when I restart my computer. I have a PC a Dell. I've run my Avast and Malware anti-virus programs and nothing.

Is there another way to search for this file, find it, quarantine and/or delete it.

Please I need your help,

I'm not very computer savy

Thank You,

Adrian

YoKenny

  • Guest
Re: I need help getting rid of a malware/virus??? jlwjwpashdw.exe.
« Reply #1 on: August 20, 2010, 10:43:14 PM »
It helps to know your operating system and Service Pack level. ;)
RAM on the system is useful as well. ;)

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: I need help getting rid of a malware/virus??? jlwjwpashdw.exe.
« Reply #2 on: August 20, 2010, 10:50:11 PM »
TRy this - it will let me see where the file is and then delete it

OTL - Download or alternative link here and here to your desktop

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%\*.*
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\Fonts\*.exe
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lnk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%PROGRAMFILES%\Internet Explorer\*.dat
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Desktop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them if you need to start a new topic.

aerolls

  • Guest
Re: I need help getting rid of a malware/virus??? jlwjwpashdw.exe.
« Reply #3 on: August 20, 2010, 10:52:54 PM »
It helps to know your operating system and Service Pack level. ;)
RAM on the system is useful as well. ;)

I'm using Windows XP
Home Edition Version 2002
Service Pack 3

2.52 GHz, 512 MB of RAM



aerolls

  • Guest
Re: I need help getting rid of a malware/virus??? jlwjwpashdw.exe.
« Reply #4 on: August 20, 2010, 11:10:42 PM »
SO this is what I found out:

This is where it's it:

Documents and Settings\Adrian\Local Settings\Application Data\hkpcipvag\jlwjwpashdw.exe/htmlMain.htm#

How do I delete this?


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: I need help getting rid of a malware/virus??? jlwjwpashdw.exe.
« Reply #5 on: August 20, 2010, 11:13:14 PM »
If you run OTL with the custom scan as in my previous post I will be able to remove that and any other elements