This is a read-only archive. No new posts or registrations. Privacy Page
Software

Probable malware issue

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

In the last few days, every time I boot up my firewall has detected a program in my c:Windows\Temp folder trying to access the Internet. These are .exe files with filenames that appear to be randomly generated 8-digit hexadecimal numbers (e.g. 35E9E393.exe), normally different names each time. Naturally I tell my firewall to block these attempts. I have done virus scans with AVG and Comodo (never running both at the same time, of course), neither of which found anything, and with Malwarebytes' Anti-Malware based on the recommendations found on this site, which found a rustock rootkit which it claimed it would delete the next time I rebooted, which I promptly did. This time I did not get a randomly-named file trying to call home, but I'm still not convinced I'm clean. What should be my next move? I'm happy to post an HJT log if desired, it's just that based on what I've read about this particular rootkit, that might not show anything even if I'm still infected. HJT did find some registry entries that an online HJT parser told me should probably be deleted, which I did. By the way, scanning those files with the randomly generated names doesn't turn up anything; all of the above tools detect nothing wrong with them. All are 52 kb. Currently I have three, and I've manually deleted at least that many previously.
Hmmm, I see we helped you back in February with a similar problem (except no one worked your log - :( sorry about that). I note back then I recommended you check out the Cleaning Out Malware sticky and I assume that is where you picked up MBAM you mentioned above. Note in that sticky is also included steps to clean your system of clutter with ATF, CCleaner, or Disk Cleanup. As Vectris said, this sounds like temp files.

If you set your defenses using that sticky as a guide to build your own suite, AND you (and every user of that computer) have been practicing safe computing since February, then I suspect you got it with MBAM.

However, the rootkit is surely a concern - even if reported removed by MBAM, which I have a lot of faith in. If you had a virus back in February, and rootkits now, then there is a breach in your computer's defenses. It is not being kept patched, updated, scanned or blocked as needed, or you or another user of that machine, have not been diligent at practicing safe computing. :(

I think you need to review that sticky and make sure your defenses are covered. Ensure all users of that PC understand where they can go, and more importantly, where they cannot go. The best defense cannot succeed if the weakest link, the user, lets the badguys in. Make sure all users are fully aware that downloading songs and movies from P2P sites that allow illegal filesharing of copyrighted materials is (1) illegal and (2) just about the best way to defeat all the computer's defenses and infect system with spyware and remote control access to use as a weapon against the rest of us.

Since your log was not analyzed in February, then I agree again with Vectris, a log would be a good idea, just to be safe. I recommend you post a log then leave that computer alone until one of WTT's Malware Removal experts can assist you. Note the sticky in that forum if not you have no response in 5 days.

If you need that computer for productivity work, then I would urge you to run one of those disk cleaners, update and scan with MBAM again, then post your log. Make no other changes to your system until someone there helps you. See WhattheTech HijackThis Log Procedures for complete instructions on running HijackThis, then post a log where instructed. Please refer to this post so they can catch up. When the HJT analysts give you a clean bill of health, please post back here with an update.

That said, I am not sure there was a problem with those seemingly randomly generated files. Similar files to the ones you note are often created in temporary folders to temporarily store configuration data and compressed/decompressed files during a program install. A good programmer would ensure the install routine cleans up after itself, but if that process is interrupted, perhaps by a firewall, or user terminating the install, they may be left behind. Downloaded files are often temporarily downloaded to temp folders while the system waits for the user to input the correct save location. If a download is terminated prematurely, it may leave such files. All the more reason to do regular disk cleanups.
I've posted fresh HJT and more recently MBAM logs in that forum, along with responses to a few of your remarks. Feel free, indeed encouraged, to have a look and make any further suggestions; long and short, I had already done some (but by no means all) of the things you suggest, still seem to be having problems, and believe I have reason not to share your sunny outlook on those randomly generated files. :(

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI