Page 1 of 4 123 ... LastLast
Results 1 to 10 of 33

Thread: Rogue executable in C:\windows\temp

  1. #1
    Join Date
    Oct 2007
    Posts
    17

    Rogue executable in C:\windows\temp

    Network admin has noticed that a system is constantly trying to connect to a domain with the following IP: 216.133.246.134. We have blocked all outbound traffic to this 'ad' site. Upon further investigation of the PC, I have found that there is an unknown, rogue process running with a corresponding .exe located in the C:\windows\temp folder. This executable and process name changes upon every reboot. We have tried various spyware programs and registry cleaning programs to no avail. I do have a HijackThis log file available and will post this when asked.

    Any help will be greatly appreciated.

  2. #2
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Go ahead and post the HJT log, but I would also suggest you follow the steps given here READ ME Before Posting A Request For Assistance!
    paying close attention to the instructions given in step #8 to disconnect completely from the internet when doing steps listed in that section. But do them all of course as directed before you get to step #8. But DO post that first HJT log you all ready have.

    Searching the IP it shows it is Vitalstream Holdings, Inc. in Irvine, CA. It appears to relate to Streaming Media and Media Console Software.

    Is this taking place on only ONE computer?

  3. #3
    Join Date
    Oct 2007
    Posts
    17
    Yes, it is only happening on one computer. I am in the process of following the steps in the 'Read Me' post. Should have all attachments posted tomorrow.
    thank you for your reply.

  4. #4
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    I'll be waiting.

  5. #5
    Join Date
    Oct 2007
    Posts
    17
    I have attached the 2 HJT logs and the kaspersky log. After running AVG, there was nothing found by the scan and did not see an option to save the log. Regarding the HJT logs, take note of the sections I have "***". This is the executable that continues to rename itself upon every reboot. There is also a subsequent process running of the same name. I'll be waiting for your reply and hopefully you'll have some idea.
    Attached Files Attached Files

  6. #6
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Go back and do a Full system scan with the Kaspersky online.

  7. #7
    Join Date
    Oct 2007
    Posts
    17
    I must be missing something. Was that not a full system scan log that I submitted? If I recall the choices, I did not see an option for a FULL SCAN. I performed the Critical scan I believe.

  8. #8
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Note your log you didn't scan the full computer, just Critical Areas;
    Scan Target - Critical Areas:
    C:\WINDOWS
    C:\DOCUME~1\JVinski\LOCALS~1\Temp\
    Total number of scanned objects: 16419
    Here is one which has scanned the entire computer;

    Scan Target - My Computer:
    C:\
    D:\
    E:\
    F:\

    Scan Statistics:
    Total number of scanned objects: 62856
    Note the differences. Your scan only scanned 16419 objects. Full computer scan scanned 62856 objects.

  9. #9
    Join Date
    Oct 2007
    Posts
    17
    okay, so then I should be choosing the 'select folders' option and select all of the C: drive. If I do 'My Computer' as you suggested, will this program also scan the contents of the 15 mapped drives this user has setup?

  10. #10
    Join Date
    Oct 2007
    Posts
    17
    I hope not to be wasting your time, but I ran a 'selected folder' scan on this system. It scanned 30,000+ files. Attaching the log. IF this still isn't good enough, I will document and unmap all drives and run another scan overnight.
    Attached Files Attached Files

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •