home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Join TechIMO for Free!
Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read
Reply Get bargains at  »  Dealighted.com
 
Thread Tools
Currently Active Users: 1902
Discussions: 188,470, Posts: 2,244,174, Members: 232,724
Old September 7th, 2006, 10:29 PM   Digg it!   #1 (permalink)
Member
 
Join Date: Oct 2001
Location: Long Island, New YorK
Posts: 352
spyware problem

The computer I am working on has one last bit of spyware in it. It generates 56Kb files in the windows temp directory that have 4 character names with a .tmp extension (like f7c4.tmp or 3baf.tmp). Zonealarm is catching them trying to contact 209.160.64.178. I have run Hijackthis,Adaware,spybot search and destroy and Norton antivirus 2006 repeatedly.

I just can't seem to identify what is generating these files. Any guesses?

Thanks in advance

Arjay13
__________________
While one person hesitates because he feels inferior, the other is busy making mistakes and becoming superior

Arjay13 is offline   Reply With Quote
Old September 7th, 2006, 10:32 PM     #2 (permalink)
Mean Moderator
 
EvilRick's Avatar
 
Join Date: Oct 2001
Location: N of Music City, USA
Posts: 7,791
Have you disabled System Restore?
__________________
This signature intentionally left blank.

EvilRick is offline   Reply With Quote
Old September 7th, 2006, 11:04 PM     #3 (permalink)
Free Thinker
 
M_Six's Avatar
 
Join Date: Oct 2001
Location: Charleston, Illinois
Posts: 4,198
And empty every user's temp internet files and temp folder. Under C:\Documents and Settings and under each user, go to Local Settings and then temp and temp internet folders.

Also, if you know approximately the date you got the spyware, you can do a search for any file with that date or newer. Then sort by file type and look for unexplained executable files with .exe, .scr, .dat, or .dll extensions.
__________________
You can't fix stupidity.

M_Six is offline   Reply With Quote
Old September 7th, 2006, 11:07 PM     #4 (permalink)
Mean Moderator
 
EvilRick's Avatar
 
Join Date: Oct 2001
Location: N of Music City, USA
Posts: 7,791
One thing I do when I first setup a PC is go into the Environmental Variables and change the default 'TEMP' and 'TMP' locations to just C:\WINDOWS\TEMP so I only have to look in one spot for junk like this.
EvilRick is offline   Reply With Quote
Old September 7th, 2006, 11:27 PM     #5 (permalink)
Member
 
Join Date: Oct 2001
Location: Long Island, New YorK
Posts: 352
Thanks for the ideas - I did dump the System Restore but it is active now. I killed most of the tmp files in safe mode. I'll check again to be sure I haven't missed any. I'll get back to you friday. Thanks again!
Arjay13 is offline   Reply With Quote
Old September 7th, 2006, 11:29 PM     #6 (permalink)
Free Thinker
 
M_Six's Avatar
 
Join Date: Oct 2001
Location: Charleston, Illinois
Posts: 4,198
Quote:
Originally Posted by EvilRick View Post
One thing I do when I first setup a PC is go into the Environmental Variables and change the default 'TEMP' and 'TMP' locations to just C:\WINDOWS\TEMP so I only have to look in one spot for junk like this.
Great idea. Need to write that one down.
M_Six is offline   Reply With Quote
Old September 11th, 2006, 02:55 PM     #7 (permalink)
Member
 
Join Date: Oct 2001
Location: Long Island, New YorK
Posts: 352
Same Problem

Well guys, I still have the same problem. Zonealarm keeps catching new *.tmp files that are trying to contact the same IP address. I have run the IP address and am trying to contact the internet abuse folks at the ISP. I'm not sure what to do - can I configure Zone Alarm to block that IP address?
Arjay13 is offline   Reply With Quote
Old September 12th, 2006, 11:42 AM     #8 (permalink)
Ultimate Member
 
SeanC's Avatar
 
Join Date: Oct 2001
Location: Toronto Canada
Posts: 4,628
Set Zonealarm to "remember your answer" and select No to allowing the connection. It should stop bugging you about it.

Download and run the Sophos Antirootkit Scanner:
http://www.sophos.com/products/free-...i-rootkit.html

And the Rootkit Revealer package:
http://www.sysinternals.com/Utilitie...tRevealer.html

Just to make sure there isn't a rootkit installed that's preventing the spyware/av scanners from finding what's generating the stuff.

There are other rootkit scanners as well. Like AV and Antispyware scanners, Antirootkit scanners aren't all alike either.
__________________
AMD Phenom Q9500 Quad-Core 2.2ghz / Asus M3A78-EMH HDMI / 4GB PC667 RAM / 320GB SATA II
SeanC is offline   Reply With Quote
Old September 15th, 2006, 11:51 AM     #9 (permalink)
Member
 
Join Date: Oct 2001
Location: Long Island, New YorK
Posts: 352
Smile
Sucess!

Sean C
Your rootkitrevealer idea worked! It turns out that there was a directory c:\windows\softwaredistribution that the rootkit search programs revealed. I was able to go and delete the directory and voila, the problem is gone! Thank you so much!
Arjay13

Last edited by Arjay13 : September 15th, 2006 at 11:54 AM.
Arjay13 is offline   Reply With Quote
Old September 15th, 2006, 11:54 AM     #10 (permalink)
Ultimate Member
 
SeanC's Avatar
 
Join Date: Oct 2001
Location: Toronto Canada
Posts: 4,628
That's excellent.

I'd suggest running these programs every so often, like you run spyware scans every so often.
SeanC is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may post new threads
You may post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
spyware problem thePh@r@oh Technical Support 4 November 24th, 2005 11:17 AM
spyware problem or something... chal7ds General Tech Discussion 8 July 8th, 2005 08:54 PM
Problem with Spyware! megarockman1 General Tech Discussion 14 December 1st, 2004 12:52 AM
Serious Spyware Problem!!!! survivalhero Technical Support 3 September 27th, 2004 11:01 PM
Spyware Problem dlh75 Applications and Operating Systems 10 June 18th, 2004 10:44 AM

Most Active Discussions
Is It Just Me? (2999)
"mastermind" of London at.. (65)
Intel Pentium 4 531 (7)
Please don't divorce us (40)
AMD Phenom II X4 940 Black Edition (11)
nVidia GTX 295 now available (21)
Replacing integrated video card (5)
Folderchat Weekday thread (458)
building a gaming computer, input p.. (14)
Recent Discussions
canon eos20d problem (1)
I cant sign into msn messenger,.. (8)
nVidia GTX 295 now available (21)
Folderchat Weekday thread (458)
Could I run this set-up (15)
Bought the Visiontek Radeon 387.. (1)
CPU Overheating ?? (18)
Computer will not boot(powers o.. (2)
*TechIMO's Top 30 PCs* (44)
Blackberry Storm, Gears of War .. (2)
Core 2 Quad Q9550 system (3)
COWBOOM Ripoff! Used Laptop w/$.. (4)


All times are GMT -4. The time now is 06:41 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28