Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Another Computer to Cleanup [Solved]


  • This topic is locked This topic is locked

#1
SomeCrazyStuff

SomeCrazyStuff

    Member

  • Member
  • PipPipPip
  • 401 posts
Yall are prolly getting to know me by name.. lol there isnt by anychance a book or such to teach the ways of GeekU? It would help me out alot as I am always back here to get help on cleaning a computer.

But anyways.. off to the point

I have yet another computer that seems it may have a bug on it
I have been using a program called process lasso that is very similar to the task manager to see what all is running and to help keep program from becoming too overpowering. I have noticed the last week or two that every time i open it there is a file in the temp directory that always has a random name. That immediately told me something was fishy. i have deleted the file a couple of times before but it is always replaced with a new one with a different name of seemingly random characters. which tells me that there is another file somewhere else generating this one in the temp folder. This is actually a new computer, have only had it running for a week. im pretty sure it was updated recently, but dont hold me to that. Its behind a hardware firewall. I have run mbam on it, and it has trend micro as well as spy sweeper. have stepped through the malware read first guide and will attach the HJT log to this post.

i checked the HJT log with a site called HiJackThis (dot) de.. i didnt do anything it suggested yet as i wanted a second opinion before i trusted its results, though I must say it has in the past been correct.

Looking at that I think these entries need to be fixed:

C:\WINDOWS\TEMP\XZ4136.EXE (this is running process)

R3 - Default URLSearchHook is missing (i just dont like this entry.. seems fishy to me)

O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware player\vsocklib.dll (this one was suggest to be left alone in HJT and fixed using a program called LSPFix from cexx.org.. I havent tried this yet as the name of the site suggested sounds like a scam)

O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware player\vsocklib.dll (this one was suggest to be left alone in HJT and fixed using a program called LSPFix from cexx.org.. I havent tried this yet as the name of the site suggested sounds like a scam)

you will probably see that this computer has Spybot S&D on it as well. It is installed but hasn't been used yet as all I have ever really found useful in spybot is the immunization feature. I have used other program for antispyware.

also there is a couple of entries for a program called Desktop Coral. That is legit. I installed it just 2 nights ago(long after i first noticed that temp file).

One last note. This computer IS on a corporate domain, But this is MY personal computer. I only have it on the domain so i can get internet and such. This company has the internet locked down so that unless the computer is on the domain you cant get out. I know it is against the TOS to ask for help with a corporate computer and I wouldn't even try to ask anyone to go against that. So just to reclarify, this is MY computer, not the companies, that I am needing help with. I spoke with ScHwErV and was told that with pseudo-corporate computers like my situation it would be up to the helper that responded to this post. Therefore, as I understand it, it is not specifically against the TOS to ask for help under these circumstances.

Thanks for any help received!
  • 0

Advertisements


#2
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Hi,

Looking at that I think these entries need to be fixed:

C:\WINDOWS\TEMP\XZ4136.EXE (this is running process)

Why do you want to fix that one? If you delete it, another random one will just generate again. They are related with your Trendmicro Officescan and if you look at the file, you'll see it has a dogs icon.
So leave it alone.

R3 - Default URLSearchHook is missing (i just dont like this entry.. seems fishy to me)

Not fishy. The default URLSearchHook is missing here. If you fix it in HijackThis, then it will restore it again.

O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware player\vsocklib.dll (this one was suggest to be left alone in HJT and fixed using a program called LSPFix from cexx.org.. I havent tried this yet as the name of the site suggested sounds like a scam)

O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware player\vsocklib.dll (this one was suggest to be left alone in HJT and fixed using a program called LSPFix from cexx.org.. I havent tried this yet as the name of the site suggested sounds like a scam)

Why do you want to fix these? I assume you know what programs you have installed? Well, in this case, it's a part of your Vmware Player and is needed for the networkconnection. You won't be able to fix it in HijackThis anyway.
Leave it alone.
  • 0

#3
SomeCrazyStuff

SomeCrazyStuff

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 401 posts
Oooh.. ok wow, now i feel like an idiot. That randomly named file is related to trend micro? if you dont mind, can you explain how you came to that? i tried doing a google on some of the file names and of course that didnt help any. I dont see anyway the random file is linked to trend micro. Unless you are judging by the fact that it has a little dog icon..

i should have looked up the vsocklib.dll. that would have instantly told me that they were legit. thats my bad.

But the R3 entry is safe to fix?
  • 0

#4
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP

That randomly named file is related to trend micro? if you dont mind, can you explain how you came to that?

Well, I've already done thousands of logs, and everytime when I see Trendmicro Officescan in a log, I always see an extra process present there, random file running from temp.
I've already asked samples and it is related with the trendmicro officescan and has the icon of a dog.
Also see here: http://esupport.tren....0-clients.aspx

But the R3 entry is safe to fix?

Yes, you may fix that.
  • 0

#5
SomeCrazyStuff

SomeCrazyStuff

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 401 posts
Thats where experience trumps technology xD.

Ok well thank you very much for your help!

One last question before i go. Is there anyway i could be allowed to view the G2G helpers forum thing so i could kinda have a good source of reliable news related to the evolution of malware? I was just talking to loophole about that. I didnt realize that HJT was becoming obsolete, especially since everyone still seems to use it and ask for it as first resort.

Another instance for why I would like to be able to just read this helper forum is back a couple months ago i found an article claiming DSS as compromised. I asked admin about it and he replied back that yes it had been and that everyone already knew about it. He also said that yall have either a forum where yall discuss current trends or somewhere else that yall go to to do the like.
  • 0

#6
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Hi,

You need to contact one of administrators first and ask for access to join training here. You cannot get access to the hidden forums without training. :)
  • 0

#7
SomeCrazyStuff

SomeCrazyStuff

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 401 posts
ha ok. I had once been part of the GeekU program, But had to drop out because of time restraints with work and school. Just had to much to do to be able to keep up with GeekU and rest of life. But that does make sence. I can understand why G2G wouldnt want just anyone reading the hidden forums.

mimekiemoes, Thanks for your help!
  • 0

#8
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
You're most welcome :)
  • 0

#9
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP