<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: What's producing these exe files in my temp folder?</title>
	<link>http://ask.metafilter.com/13614/Whats-producing-these-exe-files-in-my-temp-folder/</link>
	<description>Comments on Ask MetaFilter post What's producing these exe files in my temp folder?</description>
	<pubDate>Tue, 04 Jan 2005 06:51:49 -0800</pubDate>
	<lastBuildDate>Tue, 04 Jan 2005 06:51:49 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: What&apos;s producing these exe files in my temp folder?</title>
		<link>http://ask.metafilter.com/13614/Whats-producing-these-exe-files-in-my-temp-folder</link>	
		<description>On WinXP, every minute, I get a new file in my temp directory, and it appears to be a downloaded webpage. I&apos;m sure I have a virus or summat, but I can&apos;t see where. MI. &lt;br /&gt;&lt;br /&gt; I&apos;ve run adaware and AntiVir, but nothing is found. There are no scheduled tasks and I am no novice user.&lt;br&gt;
&lt;br&gt;
The files are being created in &lt;br&gt;
C:\Documents and Settings\User\Local Settings\Temp&lt;br&gt;
&lt;br&gt;
There is a new one each minute. Filenames are randomly created, such as ddgdjjgi.exe and jqdobkpk.exe. The files are Hex when I view them in Textpad, but the program also shows the ASCII version (?) of the Hex code, which is virtually identical to the source from http://www.flexiblesolutions.ws, or at least the first 2 to 6 kb of it.&lt;br&gt;
&lt;br&gt;
It&apos;s really wierd. I&apos;ve been through all the running processes, and all seem to be valid.</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2005:site.13614</guid>
		<pubDate>Tue, 04 Jan 2005 06:29:12 -0800</pubDate>
		<dc:creator>ajbattrick</dc:creator>
		
			<category>XP</category>
		
			<category>windows</category>
		
			<category>temp</category>
		
			<category>directory</category>
		
			<category>virus</category>
		
			<category>file</category>
		
	</item> <item>
		<title>By: gen</title>
		<link>http://ask.metafilter.com/13614/Whats-producing-these-exe-files-in-my-temp-folder#235355</link>	
		<description>Could they be attachments from your email app?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2005:site.13614-235355</guid>
		<pubDate>Tue, 04 Jan 2005 06:51:49 -0800</pubDate>
		<dc:creator>gen</dc:creator>
	</item><item>
		<title>By: SNACKeR</title>
		<link>http://ask.metafilter.com/13614/Whats-producing-these-exe-files-in-my-temp-folder#235356</link>	
		<description>Try &lt;a href=&quot;http://www.sysinternals.com/ntw2k/source/filemon.shtml&quot;&gt;filemon&lt;/a&gt; to see if you can figure out what process is creating the file.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2005:site.13614-235356</guid>
		<pubDate>Tue, 04 Jan 2005 06:53:07 -0800</pubDate>
		<dc:creator>SNACKeR</dc:creator>
	</item><item>
		<title>By: ajbattrick</title>
		<link>http://ask.metafilter.com/13614/Whats-producing-these-exe-files-in-my-temp-folder#235366</link>	
		<description>Filemon I have used before in the long distant past, and forgotten about, cheers SNACKeR. Anyway, that points me to&lt;br&gt;
C:\WINDOWS\system32\rnbw\hgkpgbmc.exe&lt;br&gt;
which leads me to the &lt;a href=&quot;http://www.sophos.com/virusinfo/analyses/trojbankerx.html&quot;&gt;Troj/Banker-X&lt;/a&gt; trojan / virus.&lt;br&gt;
&lt;br&gt;
But now I am stumped again, as the only bit that matches with that trojan is &quot;rnbw.&quot; None of the other symptoms appear</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2005:site.13614-235366</guid>
		<pubDate>Tue, 04 Jan 2005 07:15:31 -0800</pubDate>
		<dc:creator>ajbattrick</dc:creator>
	</item><item>
		<title>By: Alex Handcoding</title>
		<link>http://ask.metafilter.com/13614/Whats-producing-these-exe-files-in-my-temp-folder#235394</link>	
		<description>Ad Aware is good, but try also &lt;a href=&quot;http://security.kolla.de/&quot;&gt;Spybot Search &amp;amp; Destroy&lt;/a&gt;. It&apos;s another excellent spyware-removal app and, together with Ad Aware, they make a great team.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2005:site.13614-235394</guid>
		<pubDate>Tue, 04 Jan 2005 08:16:38 -0800</pubDate>
		<dc:creator>Alex Handcoding</dc:creator>
	</item><item>
		<title>By: u.n. owen</title>
		<link>http://ask.metafilter.com/13614/Whats-producing-these-exe-files-in-my-temp-folder#235397</link>	
		<description>My favorite is HijackThis.  But you need to have a bit of knowhow to know what to delete and not.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2005:site.13614-235397</guid>
		<pubDate>Tue, 04 Jan 2005 08:20:04 -0800</pubDate>
		<dc:creator>u.n. owen</dc:creator>
	</item><item>
		<title>By: zsazsa</title>
		<link>http://ask.metafilter.com/13614/Whats-producing-these-exe-files-in-my-temp-folder#235409</link>	
		<description>If it&apos;s a trojan and not spyware (the line between the two is becoming more and more blurred...) and AntiVir won&apos;t get rid of it, try &lt;a href=&quot;http://vil.nai.com/vil/stinger/&quot;&gt;Stinger&lt;/a&gt;, a quick removal tool for the most &quot;popular&quot; viruses.  Failing that, I&apos;ve had good luck with &lt;a href=&quot;http://free.grisoft.com/freeweb.php/doc/2/&quot;&gt;AVG Free&lt;/a&gt;.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2005:site.13614-235409</guid>
		<pubDate>Tue, 04 Jan 2005 08:35:41 -0800</pubDate>
		<dc:creator>zsazsa</dc:creator>
	</item><item>
		<title>By: juv3nal</title>
		<link>http://ask.metafilter.com/13614/Whats-producing-these-exe-files-in-my-temp-folder#235757</link>	
		<description>echoing what people have already said, update your definitions and hit it with the trinity of adaware, spybot and hijackthis. then avgfree. &lt;br&gt;
if issue persists, reboot in safe mode, repeat. &lt;br&gt;
this gets rid of most stuff.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2005:site.13614-235757</guid>
		<pubDate>Tue, 04 Jan 2005 19:30:19 -0800</pubDate>
		<dc:creator>juv3nal</dc:creator>
	</item><item>
		<title>By: ajbattrick</title>
		<link>http://ask.metafilter.com/13614/Whats-producing-these-exe-files-in-my-temp-folder#235876</link>	
		<description>Spybot tells me that it is &quot;n-Case&quot;&lt;br&gt;
&lt;br&gt;
Thanks all</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2005:site.13614-235876</guid>
		<pubDate>Wed, 05 Jan 2005 01:14:04 -0800</pubDate>
		<dc:creator>ajbattrick</dc:creator>
	</item>
	</channel>
</rss>
