Suspected virus in C:\Windows\Temp area

Suspected virus in C:\Windows\Temp area

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Suspected virus in C:\Windows\Temp area Paul King 01-09-2008
Posted by Paul King on January 9, 2008, 5:52 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Dear all,

I have a Windows 2003 server OS, and Im sure I have a virus which is not
detected by my AV Solution - Trend OfficeScan product.

It first appears as a process in TaskMgr for example LA5819.exe - this file
is also apparent in the C:\Windows\temp directory. Thus I can only remove
the file when I kill the process.

However, within the next 5-10mins a new file with a completely different
name appears....

Has anyone heard about this?

Cheers
Paul.



Posted by David H. Lipman on January 9, 2008, 5:56 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Dear all,
|
| I have a Windows 2003 server OS, and Im sure I have a virus which is not
| detected by my AV Solution - Trend OfficeScan product.
|
| It first appears as a process in TaskMgr for example LA5819.exe - this file
| is also apparent in the C:\Windows\temp directory. Thus I can only remove
| the file when I kill the process.
|
| However, within the next 5-10mins a new file with a completely different
| name appears....
|
| Has anyone heard about this?
|
| Cheers
| Paul.
|

So what makes you think this is malicious ?
Nothing in your post indicates malicious activity and thus a problem.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by Paul King on January 9, 2008, 6:08 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi David,

Sorry to be so vague - but my machine is running really slow and I know its
something malicious which has recently been installed or resident within the
OS.

I also cannot start the MSSearch service as it cannot find the file
specified - yet the file is in the correct place.

Regards
Paul.

>
> | Dear all,
> |
> | I have a Windows 2003 server OS, and Im sure I have a virus which is not
> | detected by my AV Solution - Trend OfficeScan product.
> |
> | It first appears as a process in TaskMgr for example LA5819.exe - this
> file
> | is also apparent in the C:\Windows\temp directory. Thus I can only
> remove
> | the file when I kill the process.
> |
> | However, within the next 5-10mins a new file with a completely different
> | name appears....
> |
> | Has anyone heard about this?
> |
> | Cheers
> | Paul.
> |
>
> So what makes you think this is malicious ?
> Nothing in your post indicates malicious activity and thus a problem.
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>



Posted by David H. Lipman on January 9, 2008, 6:15 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Hi David,
|
| Sorry to be so vague - but my machine is running really slow and I know its
| something malicious which has recently been installed or resident within the
| OS.
|
| I also cannot start the MSSearch service as it cannot find the file
| specified - yet the file is in the correct place.
|
| Regards
| Paul.
|


That's a sign of OS corruption, not malware.

However I saw your OTHER post (reply ?) and it indicated multiple Trojans (Renos
and Vundo)
and the Virut virus.

This is NOT good !

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by Volodymyr Shcherbyna on January 10, 2008, 8:41 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Try to execute Windows File Protection. óhange your antivirus.

--
Volodymyr
NG tips:
http://msmvps.com/blogs/v_scherbina/pages/microsoft-newsgroups-tips.aspx

> Hi David,
>
> Sorry to be so vague - but my machine is running really slow and I know
> its something malicious which has recently been installed or resident
> within the OS.
>
> I also cannot start the MSSearch service as it cannot find the file
> specified - yet the file is in the correct place.
>
> Regards
> Paul.
>
>>
>> | Dear all,
>> |
>> | I have a Windows 2003 server OS, and Im sure I have a virus which is
>> not
>> | detected by my AV Solution - Trend OfficeScan product.
>> |
>> | It first appears as a process in TaskMgr for example LA5819.exe - this
>> file
>> | is also apparent in the C:\Windows\temp directory. Thus I can only
>> remove
>> | the file when I kill the process.
>> |
>> | However, within the next 5-10mins a new file with a completely
>> different
>> | name appears....
>> |
>> | Has anyone heard about this?
>> |
>> | Cheers
>> | Paul.
>> |
>>
>> So what makes you think this is malicious ?
>> Nothing in your post indicates malicious activity and thus a problem.
>>
>>
>> --
>> Dave
>> http://www.claymania.com/removal-trojan-adware.html
>> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>>
>>
>
>



Similar ThreadsPosted
Suspected virus causing windows temp to fill up January 30, 2008, 4:07 pm
Two arrested suspected of Zotob August 26, 2005, 6:21 pm
Suspected malware. Only affecting MLB.COM site. December 27, 2007, 10:04 am
HELP: Virus is preventing me from installing anti virus software!! January 11, 2007, 2:17 am
I have a virus that uses "anti virus software" downloads as a cover up March 24, 2007, 1:40 pm
I have a worm or virus that does not allow me to go to ANY anti-virus website January 28, 2006, 10:29 pm
Caught a Virus: Virus:Trj/Shutdown.Z -- need advice June 13, 2007, 12:59 am
Vundo fix not finding vundo virus - windows tool deletes virus May 14, 2008, 2:06 pm
Does anybody know what virus i've got? July 5, 2005, 8:23 am
New Virus? July 6, 2005, 11:22 am

The site map in XML format XML site map

Contact Us | Privacy Policy