Avatar of Dan
Dan
Flag for United States of America asked on

File Name Renaming

Is this an indication that I have a virus or something?  Has my server been hacked, I'm running windows server 2012 R2.

file name renaming
PCWindows 7Windows Server 2012

Avatar of undefined
Last Comment
Dan

8/22/2022 - Mon
SOLUTION
Cliff Galiher

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Dan

ASKER
but I never tried to create a folder called Program, it just comes up by itself.
David Johnson, CD

somewhere, somehow, malware, installed program, task schedule the probable cause is missing quotation marks around c:\program files\blah which then creates the folder c:\program and then errors out.
SOLUTION
nobus

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Dan

ASKER
the same message appeared now on a 2nd server, this is strange. I'll run for malware, but I doubt it's that.
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
NVIT

Per your original image, does this happen at startup, e.g. after you logon?
Dan

ASKER
When I log into the server.
NVIT

Check for suspects. your Startup folder, and Task Scheduler, and registry keys:

C:\Users\username\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Dan

ASKER
C:\Users\username\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
(Nothing here, empty)  But it could be in other profiles, as there's a lot of other account profiles on this server

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
(Nothing here, empty)  But it could be in other profiles, as there's a lot of other account profiles on this server

 I've attached what's in msconfig.
startup
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
(The only thing here is my symantec backup exec exe file)

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
(nothing here)

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
(everything.exe is here, which is I know what it is, but then I don't know what this is,
it's MtxHotPlugService.exe v)  It's in the system32 directory, so I'm assuming it's part of the OS.

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
(Nothing here)

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
(That folder does not exist)

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
(That folder does not exist)
SOLUTION
NVIT

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Dan

ASKER
Its my sql server so I can't restart it during production hours.
nobus

did you check -as i asked - if the program folder exists??
Your help has saved me hundreds of hours of internet surfing.
fblack61
ASKER CERTIFIED SOLUTION
David Johnson, CD

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Dan

ASKER
Thanks guys, I should have remembered about autoruns, I used to use it frequently.

I found that my AV program, Webroot was trying to create a folder called program in the rot of C.

I escalated the issue with webroot.