http://antivirus.about.com/library/weekly/aa050702a.htm?terms=jdbgmgr.exe JDBGMGR.EXE New name. Same old hoax. Related Resources . Sulfnbk.exe hoax . Restoring Sulfnbk.exe . Likely source . Jdbgmgr.exe hoax . Hoax Encyclopedia . Virus Encyclopedia . Glossary of terms In May 2001, the SULFNBK.EXE hoax caused thousands of gullible users to delete a perfectly legitimate system file. Now the same hoax is circulating, this time targeting the equally benign JDBGMGR.EXE. As with the SULFNBK.EXE hoax, it is likely a result of confusion caused by the Magistr virus. While the hoax mail urges users to search for and delete the JDBGMGR.EXE file, in reality JDBGMGR.EXE should be on the system - it is a standard windows component included with Internet Explorer (at least as far back as version 3.02). For those hapless folks who've deleted the file, there is good news. Unless you are a Java developer, the file is not essential to normal operation and its absence should not create any adverse affects. If you do encounter problems with Java applications, you will need to either contact the vendor of the application for a new copy of Microsoft Virtual Machine or you can download Sun JavaT Virtual Machine instead. Unless you are a Windows XP user, Microsoft VM is no longer available directly from Microsoft (this is due to a licensing disagreement with Sun). XP users can obtain the Microsoft VM via XP's Service Pack 1 by visiting the Windows Update site. If you use XP and had already installed Service Pack 1 before deleting the file, the Windows Update site will no longer list SP1 for your system. You can obtain another copy of SP1 here. The email hoax urging users to delete this necessary file may be preceded with the dire sounding "National Virus Alert". It may also make reference to a Teddy Bear icon, which is the standard icon for that file. Following is one sample of the hoax: Hi, everybody: I just received a message today from one of my friends in my Address Book. Their Address Book had been infected by a virus and it was passed on to my computer. My Address Book, in turn, has been infected. The virus is called jdbgmgr.exe and it propagates automatically through Messenger and through the address book. The virus is not detected by McAfee or Norton and it stays dormant for 14 days before wipe out the whole system. It can be deleted before it erase your computer files. To delete it, you just have to do the following: 1) Go to Start, click on "Find" 2) At "files or folders" write the name jdbgmgr.exe 3) Be sure to search drive "C" 4) Click on "find now" 5) If you find the virus (the icon is a little bear with the name jdbgmgr.exe) DO NOT OPEN IT FOR ANY REASON 6) Right click on it and delete the file (it will go to the recycle bin) 7) Go to the recycle bin and delete the file definitivelly or empty the recycle bin. If you did fall victim to the hoax, you likely will not experience any ill effects as a result of the deleted file. However, you might not be as lucky when the next hoax rolls around, so be sure to check the facts before acting on unsolicited advice and warnings received via email. The Hoax Encyclopedia provides descriptions of common hoaxes. If you've received something not listed there and want to verify its authenticity, post a message in the help forums for assistance. ----- Original Message ----- From: wdbryant <wdbryant@lasvegas.net> To: <TX-CENSUS-LOOKUP-L@rootsweb.com> Sent: Wednesday, January 01, 2003 12:55 PM Subject: [TX-CEN] Please check for this virus > From: Paul Bryant <pdb1957@hotmail.com> > To: <msbren@hotmail.com>; <tag@swbell.net>; <bryantokc@hotmail.com>; <kandegurlaz@yahoo.com>; <a6m5@swbell.net>; <JeffJz@Pennwell.com>; <jkbryant60@hotmail.com>; <okjharris@prodigy.net>; <meggiemagoo3@hotmail.com>; <mgoin@ctechok.org>; <maddmikie@hotmail.com>; <llcoolnick@hotmail.com>; <OkieRose66@hotmail.com>; <salibadm@hotmail.com>; <SRF32@aol.com>; <ccgop@swbell.net>; <wdbryant@lasvegas.net> > Date: Tuesday, December 31, 2002 5:56 PM > > Hi Everyone: > > > A virus has been passed on to me by a contact. My address book has in turn > been affected. Since you are in my address book there is a good chance you > will find it in your computer too. I should explain that this is a > replication virus only and will not hurt your system unless you double click > on it. All it's doing now is replicating itself throughout address > books...I followed the direction below and eradicated the virus easily. > > > The virus (called jdbgmgr.exe) is not detected by Norton or McAfee > Anti-virus systems. The virus sits quietly for 14 days before damaging the > system. It is sent automatically by messenger and by the address book > whether or not you sent e-mails to your contacts. > > Here's how you check for the virus and get rid of it: > > > 1. Go to Start, Find or Search option. > > > 2. In the file/folders option, type the name: jdbgmgr.exe > > > 3. Be sure you search your C: drive and all the subfolders and any other > drives you may have. > > > 4. Click "find now" > > > 5. The virus has a teddy bear icon with the name jdbgmgr.e! xe. DO NOT OPEN > IT!!!! > > > 6. Go to edit (on the menu bar), choose "select all" to highlight the file > without opening it. > > > 7. Now go to the File (on the menu bar) and select delete. It will then go > to the Recycle Bin. > > > 8. Go to the Recycle Bin and delete it there as well. > > > IF YOU FIND THE VIRUS, YOU MUST CONTACT ALL THE PEOPLE IN YOUR ADDRESS BOOK, > SO THEY CAN ERADICATE IT IN THEIR OWN ADDRESS BOOKS. > > > To do this: > > a): Open a new e-mail message > > b): Click the icon of the address book next to the "TO" > > c): Highlight every name and add to "BCC" > > d): Copy this message.....enter subject.....paste to e-mail....and send. > > > > > > > > _________________________________________________________________ > MSN 8 with e-mail virus protection service: 2 months FREE* > http://join.msn.com/?page=features/virus > > > > ==== TX-CENSUS-LOOKUP Mailing List ==== > To Unsub from digest mail mode, send the command "unsubscribe" to > XX-CENSUS-LOOKUP-D-request@rootsweb.com (Remove the XX and replace it with your state abbreviation ) > > ============================== > To join Ancestry.com and access our 1.2 billion online genealogy records, go to: > http://www.ancestry.com/rd/redir.asp?targetid=571&sourceid=1237 > >