Link to home
Start Free TrialLog in
Avatar of Dan
DanFlag for United States of America

asked on

File Name Renaming

Is this an indication that I have a virus or something?  Has my server been hacked, I'm running windows server 2012 R2.

User generated image
SOLUTION
Avatar of Cliff Galiher
Cliff Galiher
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Dan

ASKER

but I never tried to create a folder called Program, it just comes up by itself.
somewhere, somehow, malware, installed program, task schedule the probable cause is missing quotation marks around c:\program files\blah which then creates the folder c:\program and then errors out.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Dan

ASKER

the same message appeared now on a 2nd server, this is strange. I'll run for malware, but I doubt it's that.
Per your original image, does this happen at startup, e.g. after you logon?
Avatar of Dan

ASKER

When I log into the server.
Check for suspects. your Startup folder, and Task Scheduler, and registry keys:

C:\Users\username\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
Avatar of Dan

ASKER

C:\Users\username\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
(Nothing here, empty)  But it could be in other profiles, as there's a lot of other account profiles on this server

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
(Nothing here, empty)  But it could be in other profiles, as there's a lot of other account profiles on this server

 I've attached what's in msconfig.
User generated image
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
(The only thing here is my symantec backup exec exe file)

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
(nothing here)

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
(everything.exe is here, which is I know what it is, but then I don't know what this is,
it's MtxHotPlugService.exe v)  It's in the system32 directory, so I'm assuming it's part of the OS.

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
(Nothing here)

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
(That folder does not exist)

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
(That folder does not exist)
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Dan

ASKER

Its my sql server so I can't restart it during production hours.
did you check -as i asked - if the program folder exists??
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Dan

ASKER

Thanks guys, I should have remembered about autoruns, I used to use it frequently.

I found that my AV program, Webroot was trying to create a folder called program in the rot of C.

I escalated the issue with webroot.