PDA

View Full Version : Java/Agent.DW removal help needed



superb1000
2011-11-21, 17:57
hi

yesterday after seeing a C++ compiler installed on a location where it should not be, i did a full scan on my system with nod32.

Nod 32 found:


C:\Documents and Settings\HP_Administrateur\Application Data\Sun\Java\Deployment\cache\6.0\10\2db2554a-465fab38 Java/Agent.DW

C:\Documents and Settings\HP_Administrateur\Application Data\Sun\Java\Deployment\cache\6.0\34\27cc5822-684aa012 variation of Java/Agent.DW

C:\Documents and Settings\HP_Administrateur\Application Data\Sun\Java\Deployment\cache\6.0\41\76f3af69-56e3630d variation of Java/Agent.DW

As nod 32 did not remove it itself, What i did is remove the Cache directory and all it's content.
but I would like to know if there is not something else left that nod 32 has not seen or maybe a rootkit installed.

what tool should I use first in this case ?

bye
philx

tashi
2011-11-21, 18:11
Hello superb1000,

In case you missed it please see the sticky which includes guidelines for this forum and instructions in post #2 on how to provide the preliminary "DDS" logs used for analysis.
"BEFORE You POST"(Please read this Procedure Before Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

If this is a personal computer start a new topic providing the DDS logs as shown in that FAQ and a volunteer analyst will advise you when available. :)

Best regards.