• I am botted

    Author
    Topic
    #472922

    I have a multiboot system running XP, Vista, Win 7 and Ubuntu Linux. My computer has a network connection to my wife’s XP machine. In ALL of the Windows environments (including my wife’s XP) there is traffic on my internet connection sending and receiving up to 80 MB per day (if I leave my firewall open). When I set my Comodo firewall to block all traffic (when I am not using the web) I get a popup saying that a file called NEW….tmp.exe wants to connect to the web. the … in the file name changes each time to a different group of numbers and/or letters. eg New67d8.tmp.exe if I dismiss that popup, in a few minutes another NEW….tmp.exe asks for a connection.

    I have tried several antimalware programs, including Kaspersky, MS Security essentials, Superantispyware and about half a dozen more. NONE of them reports malware in any of the Windows systems.

    I am now getting desperate. Short of cleaning my entire setup and starting again with all the systems, what else can I try. (I have HUNDREDS of applications on my system)

    Please help !!

    Errol Greer

    Viewing 4 reply threads
    Author
    Replies
    • #1254333

      You can use a tool such as WhatInStartup – Disable/delete programs at Windows startup or Autoruns to see what is being started when you boot your system.

      You can also use a tool such as Rootkit Revealer to check for rootkits. BUT, be very careful when you use a rootkit tool. Correctly identifying and removing a rootkit is tricky. You should read the entire article on the download page.

      Joe

      --Joe

    • #1254337

      I have looked at the startup programs, but nothing unusual there. These bot things hide from everything, including the task manager. That’s why I need help. I have run several antirootkit apps and again, nothing is found.

    • #1254338

      Have you checked the services that are started automatically?

      Joe

      --Joe

    • #1254360

      May be a rootkit, very hasty. Try the Rootkit Revealer.

      cheers, Paul

    • #1254403

      Hi Errol :

      Appears you have a very advanced form of malware, to the degree you
      should ask an experienced, trained, Certified, Volunteer “Malware
      Removal Specialist” found on many Advanced Malware Removal
      Forums, such as the One at http://www.geekstogo.com/forum/forums.html .
      Follow the Info in their “Malware and Spyware Cleaning Guide” to the
      best of your ability . Practically speaking, I recommend you post a
      “Log” using the “OTL” program and let them take it from there. They
      use little known, but highly effective programs to detect, then remove
      malware . I suspect a rootkit is involved, and they recommend posting
      a “Log” using the GMER program .

    Viewing 4 reply threads
    Reply To: I am botted

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: