September 7th, 2006, 10:29 PM
|
#1 (permalink)
| | Member
Join Date: Oct 2001 Location: Long Island, New YorK
Posts: 352
|
The computer I am working on has one last bit of spyware in it. It generates 56Kb files in the windows temp directory that have 4 character names with a .tmp extension (like f7c4.tmp or 3baf.tmp). Zonealarm is catching them trying to contact 209.160.64.178. I have run Hijackthis,Adaware,spybot search and destroy and Norton antivirus 2006 repeatedly.
I just can't seem to identify what is generating these files. Any guesses?
Thanks in advance
Arjay13
__________________
While one person hesitates because he feels inferior, the other is busy making mistakes and becoming superior
|
| |
September 7th, 2006, 10:32 PM
|
#2 (permalink)
| | Mean Moderator
Join Date: Oct 2001 Location: N of Music City, USA
Posts: 7,791
|
Have you disabled System Restore?
__________________ This signature intentionally left blank. |
| |
September 7th, 2006, 11:04 PM
|
#3 (permalink)
| | Free Thinker
Join Date: Oct 2001 Location: Charleston, Illinois
Posts: 4,198
|
And empty every user's temp internet files and temp folder. Under C:\Documents and Settings and under each user, go to Local Settings and then temp and temp internet folders.
Also, if you know approximately the date you got the spyware, you can do a search for any file with that date or newer. Then sort by file type and look for unexplained executable files with .exe, .scr, .dat, or .dll extensions.
__________________
You can't fix stupidity.
|
| |
September 7th, 2006, 11:07 PM
|
#4 (permalink)
| | Mean Moderator
Join Date: Oct 2001 Location: N of Music City, USA
Posts: 7,791
|
One thing I do when I first setup a PC is go into the Environmental Variables and change the default 'TEMP' and 'TMP' locations to just C:\WINDOWS\TEMP so I only have to look in one spot for junk like this. |
| |
September 7th, 2006, 11:27 PM
|
#5 (permalink)
| | Member
Join Date: Oct 2001 Location: Long Island, New YorK
Posts: 352
|
Thanks for the ideas - I did dump the System Restore but it is active now. I killed most of the tmp files in safe mode. I'll check again to be sure I haven't missed any. I'll get back to you friday. Thanks again!  |
| |
September 7th, 2006, 11:29 PM
|
#6 (permalink)
| | Free Thinker
Join Date: Oct 2001 Location: Charleston, Illinois
Posts: 4,198
| Quote:
Originally Posted by EvilRick One thing I do when I first setup a PC is go into the Environmental Variables and change the default 'TEMP' and 'TMP' locations to just C:\WINDOWS\TEMP so I only have to look in one spot for junk like this. | Great idea. Need to write that one down.  |
| |
September 11th, 2006, 02:55 PM
|
#7 (permalink)
| | Member
Join Date: Oct 2001 Location: Long Island, New YorK
Posts: 352
|
Well guys, I still have the same problem. Zonealarm keeps catching new *.tmp files that are trying to contact the same IP address. I have run the IP address and am trying to contact the internet abuse folks at the ISP. I'm not sure what to do - can I configure Zone Alarm to block that IP address? |
| |
September 12th, 2006, 11:42 AM
|
#8 (permalink)
| | Ultimate Member
Join Date: Oct 2001 Location: Toronto Canada
Posts: 4,628
|
Set Zonealarm to "remember your answer" and select No to allowing the connection. It should stop bugging you about it.
Download and run the Sophos Antirootkit Scanner: http://www.sophos.com/products/free-...i-rootkit.html
And the Rootkit Revealer package: http://www.sysinternals.com/Utilitie...tRevealer.html
Just to make sure there isn't a rootkit installed that's preventing the spyware/av scanners from finding what's generating the stuff.
There are other rootkit scanners as well. Like AV and Antispyware scanners, Antirootkit scanners aren't all alike either.
__________________
AMD Phenom Q9500 Quad-Core 2.2ghz / Asus M3A78-EMH HDMI / 4GB PC667 RAM / 320GB SATA II
|
| |
September 15th, 2006, 11:51 AM
|
#9 (permalink)
| | Member
Join Date: Oct 2001 Location: Long Island, New YorK
Posts: 352
| Sucess!
Sean C
Your rootkitrevealer idea worked! It turns out that there was a directory c:\windows\softwaredistribution that the rootkit search programs revealed. I was able to go and delete the directory and voila, the problem is gone! Thank you so much!
Arjay13 
Last edited by Arjay13 : September 15th, 2006 at 11:54 AM.
|
| |
September 15th, 2006, 11:54 AM
|
#10 (permalink)
| | Ultimate Member
Join Date: Oct 2001 Location: Toronto Canada
Posts: 4,628
|
That's excellent.
I'd suggest running these programs every so often, like you run spyware scans every so often. |
| | |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | | |
Posting Rules
| You may post new threads You may post replies You may not post attachments You may not edit your posts HTML code is Off | | | | Most Active Discussions | | | | | Recent Discussions  | | | | | |