unknown file...  
Author Message
pchapoullie





PostPosted: Sat Apr 12 16:22:57 PDT 2008 Top

Windows XP >> unknown file... Any idea what this file is ?
C:\hdfjawja.sys
hrs flags are on.
Gogl comes up blank.
Virustotal reports nothing unusual.

..can't find my darned hex editor to see what's in it...

TIA

regards, Richard

Windows XP541  
 
 
PA





PostPosted: Sat Apr 12 16:22:57 PDT 2008 Top

Windows XP >> unknown file... Why do you ask, Richard?

What anti-virus application or security suite is installed? What
anti-spyware applications (other than Defender)? What third-party firewall
(if any)?
--
~Robear Dyer (PA Bear)
MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
AumHa VSOP & Admin http://aumha.net
DTS-L http://dts-l.net/


RxK wrote:
> Any idea what this file is ?
> C:\hdfjawja.sys
> hrs flags are on.
> Gogl comes up blank.
> Virustotal reports nothing unusual.
>
> ..can't find my darned hex editor to see what's in it...
>
> TIA
>
> regards, Richard

 
 
databaseben





PostPosted: Sat Apr 12 16:24:59 PDT 2008 Top

Windows XP >> unknown file... http://tinyurl.com/4zvcq5



--

db·´¯`·...¸><)))º>

"RxK" <EMail@HideDomain.com> wrote in message
news:EMail@HideDomain.com...
> Any idea what this file is ?
> C:\hdfjawja.sys
> hrs flags are on.
> Gogl comes up blank.
> Virustotal reports nothing unusual.
>
> ..can't find my darned hex editor to see what's in it...
>
> TIA
>
> regards, Richard
>
>
>

 
 
RxK





PostPosted: Sat Apr 12 16:27:54 PDT 2008 Top

Windows XP >> unknown file... ...can anyone recommend a malware free hex-editor download, ...mine seems to
have vansiehd into thin air !

TIA

regards, Richard


"RxK" <EMail@HideDomain.com> wrote in message
news:EMail@HideDomain.com...
> Any idea what this file is ?
> C:\hdfjawja.sys
> hrs flags are on.
> Gogl comes up blank.
> Virustotal reports nothing unusual.
>
> ..can't find my darned hex editor to see what's in it...
>
> TIA
>
> regards, Richard
>
>
>


 
 
Pegasus





PostPosted: Sat Apr 12 23:18:51 PDT 2008 Top

Windows XP >> unknown file...
"RxK" <EMail@HideDomain.com> wrote in message
news:EMail@HideDomain.com...
> ...can anyone recommend a malware free hex-editor download, ...mine seems
> to have vansiehd into thin air !
>
> TIA
>

http://www.chmaas.handshake.de/delphi/freeware/xvi32/xvi32.htm


 
 
RxK





PostPosted: Sun Apr 13 08:39:16 PDT 2008 Top

Windows XP >> unknown file... BiiiiIIIIIIIIg thanks Pegasus, am much obliged :-)
....I recognised it {..by desktop icon } ...straight aways when I
right-clicked the XVI32.exe file "Send to Desktop | Create Shortcut,"
...that's the hex editor I'd used for ages, ...well older version I suppose,
....the I used to have - and couldn't find - how perceptive of you !

regards, Richard


"Pegasus (MVP)" <EMail@HideDomain.com> wrote in message
news:EMail@HideDomain.com...
>
> "RxK" <EMail@HideDomain.com> wrote in message
> news:EMail@HideDomain.com...
>> ...can anyone recommend a malware free hex-editor download, ...mine seems
>> to have vansiehd into thin air !
>>
>> TIA
>>
>
> http://www.chmaas.handshake.de/delphi/freeware/xvi32/xvi32.htm
>


 
 
MAP





PostPosted: Mon Apr 14 10:42:37 PDT 2008 Top

Windows XP >> unknown file... RxK wrote:
> Any idea what this file is ?
> C:\hdfjawja.sys
> hrs flags are on.
> Gogl comes up blank.
> Virustotal reports nothing unusual.
>
> ..can't find my darned hex editor to see what's in it...
>
> TIA
>
> regards, Richard

I submitted a file to virus total and came up blank as well, a week later I
resubmitted it and got several hits, something new needs time to be
discovered, try it again.

--
Mike Pawlak


 
 
RxK





PostPosted: Tue Apr 15 07:43:52 PDT 2008 Top

Windows XP >> unknown file... ...after more time on this hdfjawja.sys file,
http://www.all-nettools.com/forum/archive/index.php/t-242.html
...seems to have one with a similar filename - the contents of the file seem
to be several strings like:-
!ATYN1FZMH4DPG3QSBU81LSO6AD0CRMF3ZTJE4VHK*

I'm wondering if it's something to do with PerfectDisk.

...regards, Richard



"RxK" <EMail@HideDomain.com> wrote in message
news:EMail@HideDomain.com...
> Any idea what this file is ?
> C:\hdfjawja.sys
> hrs flags are on.
> Gogl comes up blank.
> Virustotal reports nothing unusual.
>
> ..can't find my darned hex editor to see what's in it...
>
> TIA
>
> regards, Richard
>
>
>


 
 
RxK





PostPosted: Tue Apr 15 08:37:06 PDT 2008 Top

Windows XP >> unknown file... ...after a bit more research, I'll be keeping a closer eye on BCwipe, when I
use it, I think it's this program that drops a *sys file into my boot-drive
root-directory !

regards, Richard


"RxK" <EMail@HideDomain.com> wrote in message
news:EMail@HideDomain.com...
> ...after more time on this hdfjawja.sys file,
> http://www.all-nettools.com/forum/archive/index.php/t-242.html
> ...seems to have one with a similar filename - the contents of the file
> seem to be several strings like:-
> !ATYN1FZMH4DPG3QSBU81LSO6AD0CRMF3ZTJE4VHK*
>
> I'm wondering if it's something to do with PerfectDisk.
>
> ...regards, Richard
>
>
>
> "RxK" <EMail@HideDomain.com> wrote in message
> news:EMail@HideDomain.com...
>> Any idea what this file is ?
>> C:\hdfjawja.sys
>> hrs flags are on.
>> Gogl comes up blank.
>> Virustotal reports nothing unusual.
>>
>> ..can't find my darned hex editor to see what's in it...
>>
>> TIA
>>
>> regards, Richard
>>
>>
>>
>
>


 
 
Volodymyr





PostPosted: Wed Apr 16 08:26:52 PDT 2008 Top

Windows XP >> unknown file... I'd start from decompiler rather then from hex editor. IDA Pro is an
excellent utility. If you have to chance to get it, you can at least use
Depends Walker to see the import table of driver to analyze in general what
it does.

--
V.
This posting is provided "AS IS" with no warranties, and confers no
rights.
"RxK" <EMail@HideDomain.com> wrote in message
news:EMail@HideDomain.com...
> BiiiiIIIIIIIIg thanks Pegasus, am much obliged :-)
> ....I recognised it {..by desktop icon } ...straight aways when I
> right-clicked the XVI32.exe file "Send to Desktop | Create Shortcut,"
> ...that's the hex editor I'd used for ages, ...well older version I
> suppose, ....the I used to have - and couldn't find - how perceptive of
> you !
>
> regards, Richard
>
>
> "Pegasus (MVP)" <EMail@HideDomain.com> wrote in message
> news:EMail@HideDomain.com...
>>
>> "RxK" <EMail@HideDomain.com> wrote in message
>> news:EMail@HideDomain.com...
>>> ...can anyone recommend a malware free hex-editor download, ...mine
>>> seems to have vansiehd into thin air !
>>>
>>> TIA
>>>
>>
>> http://www.chmaas.handshake.de/delphi/freeware/xvi32/xvi32.htm
>>
>
>