Jump to content

unknown file...


Recommended Posts

Posted

Any idea what this file is ?

C:\hdfjawja.sys

hrs flags are on.

Gogl comes up blank.

Virustotal reports nothing unusual.

 

...can't find my darned hex editor to see what's in it...

 

TIA

 

regards, Richard

Guest PA Bear [MS MVP]
Posted

Why do you ask, Richard?

 

What anti-virus application or security suite is installed? What

anti-spyware applications (other than Defender)? What third-party firewall

(if any)?

--

~Robear Dyer (PA Bear)

MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002

AumHa VSOP & Admin http://aumha.net

DTS-L http://dts-l.net/

 

 

RxK wrote:<span style="color:blue">

> Any idea what this file is ?

> C:hdfjawja.sys

> hrs flags are on.

> Gogl comes up blank.

> Virustotal reports nothing unusual.

>

> ..can't find my darned hex editor to see what's in it...

>

> TIA

>

> regards, Richard </span>

Guest db ´¯`·.. >
Posted

http://tinyurl.com/4zvcq5

 

 

 

--

 

db·´¯`·...¸><)))º>

 

"RxK" <nospam@hotmail.com> wrote in message

news:e0oplMPnIHA.4536@TK2MSFTNGP06.phx.gbl...<span style="color:blue">

> Any idea what this file is ?

> C:hdfjawja.sys

> hrs flags are on.

> Gogl comes up blank.

> Virustotal reports nothing unusual.

>

> ..can't find my darned hex editor to see what's in it...

>

> TIA

>

> regards, Richard

>

>

> </span>

Posted

....can anyone recommend a malware free hex-editor download, ...mine seems to

have vansiehd into thin air !

 

TIA

 

regards, Richard

 

 

"RxK" <nospam@hotmail.com> wrote in message

news:e0oplMPnIHA.4536@TK2MSFTNGP06.phx.gbl...<span style="color:blue">

> Any idea what this file is ?

> C:hdfjawja.sys

> hrs flags are on.

> Gogl comes up blank.

> Virustotal reports nothing unusual.

>

> ..can't find my darned hex editor to see what's in it...

>

> TIA

>

> regards, Richard

>

>

> </span>

Posted

BiiiiIIIIIIIIg thanks Pegasus, am much obliged :-)

.....I recognised it {..by desktop icon } ...straight aways when I

right-clicked the XVI32.exe file "Send to Desktop | Create Shortcut,"

....that's the hex editor I'd used for ages, ...well older version I suppose,

.....the I used to have - and couldn't find - how perceptive of you !

 

regards, Richard

 

 

"Pegasus (MVP)" <I.can@fly.com.oz> wrote in message

news:OFhQA5SnIHA.4684@TK2MSFTNGP06.phx.gbl...<span style="color:blue">

>

> "RxK" <nospam@hotmail.com> wrote in message

> news:uDzKWTPnIHA.3572@TK2MSFTNGP02.phx.gbl...<span style="color:green">

>> ...can anyone recommend a malware free hex-editor download, ...mine seems

>> to have vansiehd into thin air !

>>

>> TIA

>></span>

>

> http://www.chmaas.handshake.de/delphi/free...xvi32/xvi32.htm

> </span>

Posted

RxK wrote:<span style="color:blue">

> Any idea what this file is ?

> C:hdfjawja.sys

> hrs flags are on.

> Gogl comes up blank.

> Virustotal reports nothing unusual.

>

> ..can't find my darned hex editor to see what's in it...

>

> TIA

>

> regards, Richard</span>

 

I submitted a file to virus total and came up blank as well, a week later I

resubmitted it and got several hits, something new needs time to be

discovered, try it again.

 

--

Mike Pawlak

Posted

....after more time on this hdfjawja.sys file,

http://www.all-nettools.com/forum/archive/....php/t-242.html

....seems to have one with a similar filename - the contents of the file seem

to be several strings like:-

!ATYN1FZMH4DPG3QSBU81LSO6AD0CRMF3ZTJE4VHK

 

I'm wondering if it's something to do with PerfectDisk.

 

....regards, Richard

 

 

 

"RxK" <nospam@hotmail.com> wrote in message

news:e0oplMPnIHA.4536@TK2MSFTNGP06.phx.gbl...<span style="color:blue">

> Any idea what this file is ?

> C:hdfjawja.sys

> hrs flags are on.

> Gogl comes up blank.

> Virustotal reports nothing unusual.

>

> ..can't find my darned hex editor to see what's in it...

>

> TIA

>

> regards, Richard

>

>

> </span>

Posted

....after a bit more research, I'll be keeping a closer eye on BCwipe, when I

use it, I think it's this program that drops a sys file into my boot-drive

root-directory !

 

regards, Richard

 

 

"RxK" <nospam@hotmail.com> wrote in message

news:OzuLicwnIHA.1204@TK2MSFTNGP03.phx.gbl...<span style="color:blue">

> ...after more time on this hdfjawja.sys file,

> http://www.all-nettools.com/forum/archive/....php/t-242.html

> ...seems to have one with a similar filename - the contents of the file

> seem to be several strings like:-

> !ATYN1FZMH4DPG3QSBU81LSO6AD0CRMF3ZTJE4VHK

>

> I'm wondering if it's something to do with PerfectDisk.

>

> ...regards, Richard

>

>

>

> "RxK" <nospam@hotmail.com> wrote in message

> news:e0oplMPnIHA.4536@TK2MSFTNGP06.phx.gbl...<span style="color:green">

>> Any idea what this file is ?

>> C:hdfjawja.sys

>> hrs flags are on.

>> Gogl comes up blank.

>> Virustotal reports nothing unusual.

>>

>> ..can't find my darned hex editor to see what's in it...

>>

>> TIA

>>

>> regards, Richard

>>

>>

>></span>

>

> </span>

Guest Volodymyr M. Shcherbyna
Posted

I'd start from decompiler rather then from hex editor. IDA Pro is an

excellent utility. If you have to chance to get it, you can at least use

Depends Walker to see the import table of driver to analyze in general what

it does.

 

--

V.

This posting is provided "AS IS" with no warranties, and confers no

rights.

"RxK" <nospam@hotmail.com> wrote in message

news:ehCnJyXnIHA.5208@TK2MSFTNGP04.phx.gbl...<span style="color:blue">

> BiiiiIIIIIIIIg thanks Pegasus, am much obliged :-)

> ....I recognised it {..by desktop icon } ...straight aways when I

> right-clicked the XVI32.exe file "Send to Desktop | Create Shortcut,"

> ...that's the hex editor I'd used for ages, ...well older version I

> suppose, ....the I used to have - and couldn't find - how perceptive of

> you !

>

> regards, Richard

>

>

> "Pegasus (MVP)" <I.can@fly.com.oz> wrote in message

> news:OFhQA5SnIHA.4684@TK2MSFTNGP06.phx.gbl...<span style="color:green">

>>

>> "RxK" <nospam@hotmail.com> wrote in message

>> news:uDzKWTPnIHA.3572@TK2MSFTNGP02.phx.gbl...<span style="color:darkred">

>>> ...can anyone recommend a malware free hex-editor download, ...mine

>>> seems to have vansiehd into thin air !

>>>

>>> TIA

>>></span>

>>

>> http://www.chmaas.handshake.de/delphi/free...xvi32/xvi32.htm

>></span>

>

> </span>

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...