Solved

unidentified malware creating appdata/temp folders

Posted on 2014-10-31
3
395 Views
Last Modified: 2014-11-07
At one or more a minute, new folders are created in Logged in User/appdata/temp. The folders names are 3 or 4 characters in length such as, 1eec or 3bc5, or 2d3f. Each folder contains a sub-folder "Appdata" among other things. As the number of folders increases in to the 1000s, the PC's performance degrades.

I cannot find any reference to any malware, etc. that describes this behavior. The folders can be easily and quickly deleted in Safe Mode. I ultimaley resolved this issue by going back to a restore point a couple of days prior to the infection.

Neither Symantec EndPoint 12.1.5, or Malwarebytes, or YAC found anything awry on this PC. However, Malwarebytes was reporting some "Malicious OUTBOUND activity".

Anybody have a clue what this was?

tom
0
Comment
Question by:tuckertf
  • 2
3 Comments
 
LVL 90

Accepted Solution

by:
John Hurst earned 500 total points
Comment Utility
Download, install and run Process Explorer from Microsoft (Sysinternals).  Look down the folder tree on the left for Explorer and see if there is a strange alphanumeric process running there. If so, Kill the process and do NOT restart the computer. Run Malwarebytes again, delete malware. Now restart and see if the temp file creation stops.
0
 

Author Comment

by:tuckertf
Comment Utility
Thanks for input. At original site I was able to clear the malware.
0
 
LVL 90

Expert Comment

by:John Hurst
Comment Utility
@tuckertf  - Thanks for the update and I was happy to help.
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

This article summarizes using a simple matrix to map the different type of phishing attempts and its targeted victims. It also run through many scam scheme scenario with "real" phished emails. There are safeguards highlighted to stay vigilance and h…
If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now