Answers to your tech questions
Computer forums for help with removing malicious software (malware) and improving computer security

Welcome ( Log In | Register )
Easy as 1,2,3!

 
Closed TopicStart new topic
> [Closed] Possible fake java file, JUCHECK.EXE and Jucheck.exe
JJJOOODDDYYY
post Nov 1 2009, 12:14 PM
Post #1


New Member
*

Group: New Member
Posts: 1
Joined: 1-November 09
Member No.: 88,623
Operating System: windows xp



I noticed a new process running. I have only seen it in process' once. I ran a search on my computer and found these. I see jusched.exe running all the time in the process window and have never seen the JUCHECK.EXE before, also the create date is 10/26/09 and not 10/19/08 like the rest of the Java files/

JUCHECK.EXE-366A48E6.pf located in C:/WINDOWS/Prefetch
open with unknown application. Has the icon box with the cogs in it. Created 10/26/09 (Bad?)

Jucheck.exe located in C://ProgramFiles/Java/jre1.6.0_107/bin
Has the orange Java icon next to it. Created 10/19/08 (Good?)

I am thinking the first one listed is a baddie and some kind of virus, malware, trojan etc...

It is not being flagged by spyware. I also have XP on my laptop and JUCHECK.EXE is not any where on there either.

Any info would be greatly appreciated. I just need to know if the one in all caps is valid Java file or if it is pretending to be a Java file. I have got mixed results doing an internet search. Thanks
Go to the top of the page
 
+Quote Post
Noviciate
post Nov 1 2009, 02:19 PM
Post #2


Classroom Teacher
Group Icon

Group: Classroom Teacher
Posts: 2,566
Joined: 30-July 06
Member No.: 59,198
Operating System: Windows XP



The give-away for the "Bad?" file is in the location - C:/WINDOWS/Prefetch. Microsoft created a method of "pre-loading" files so that they could be more quickly accessed when needed. This is part of what your OS is doing when you first boot up when it is unresponsive. The information about the files that it preloads are stored in the prefetch folder as .pf files.
I'd say that the file is legitimate, but there is nothing to stop you deleted this, or any other, file in this folder. Indeed, some people do this on a regular basis in the belief that it speeds up Windows. Others argue against this being effective, but you can't get all the people to agree all the time!
If you care to run a search for Windows prefetch, or similar, you can find out more information.

As to the "good?" file, if you right click it and select Properties, you should find out something about the original owner. I'd say that it was legit, as I have the same file in the same location.

I trust this "solves" the problem.
Go to the top of the page
 
+Quote Post
Noviciate
post Nov 8 2009, 03:08 PM
Post #3


Classroom Teacher
Group Icon

Group: Classroom Teacher
Posts: 2,566
Joined: 30-July 06
Member No.: 59,198
Operating System: Windows XP



Due to inactivity this topic will be closed.
If you need help please start a new thread.
Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


RSS Time is now: 20th November 2009 - 08:38 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy