<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: strange processes showing up in the task list    some random numbers.TMP</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/strange-processes-showing-up-in-the-task-list-some-random-numberstmp/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/strange-processes-showing-up-in-the-task-list-some-random-numberstmp/</link>
	<description></description>
	<pubDate>Mon, 09 Nov 2009 21:00:43 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: maxpro4u</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/strange-processes-showing-up-in-the-task-list-some-random-numberstmp/#comment-46079</link>
		<dc:creator>maxpro4u</dc:creator>
		<pubDate>Sat, 17 Jun 2006 13:23:17 +0000</pubDate>
		<guid isPermaLink="false">#comment-46079</guid>
		<description>I have written some pages that might be of some help
Virus Removal Instructions
http://home.neo.rr.com/manna4u/
Keeping Windows Clean
http://home.neo.rr.com/manna4u/keepingclean.html
And here is a list of tools and help links
http://home.neo.rr.com/manna4u/tools.html
post back with results
max</description>
		<content:encoded><![CDATA[<p>I have written some pages that might be of some help<br />
Virus Removal Instructions<br />
&nbsp;&lt;a href="http://home.neo.rr.com/manna4u/" title="http://home.neo.rr.com/manna4u/" target="_blank"&gt;http://home.neo.rr.com/manna4u/&lt;/a&gt;<br />
Keeping Windows Clean<br />
&nbsp;&lt;a href="http://home.neo.rr.com/manna4u/keepingclean.html" title="http://home.neo.rr.com/manna4u/keepingclean.html" target="_blank"&gt;http://home.neo.rr.com/manna4u/keepingcl&#8230;&lt;/a&gt;<br />
And here is a list of tools and help links<br />
&nbsp;&lt;a href="http://home.neo.rr.com/manna4u/tools.html" title="http://home.neo.rr.com/manna4u/tools.html" target="_blank"&gt;http://home.neo.rr.com/manna4u/tools.htm&#8230;&lt;/a&gt;<br />
post back with results<br />
max</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bobkberg</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/strange-processes-showing-up-in-the-task-list-some-random-numberstmp/#comment-46080</link>
		<dc:creator>bobkberg</dc:creator>
		<pubDate>Fri, 16 Jun 2006 14:46:41 +0000</pubDate>
		<guid isPermaLink="false">#comment-46080</guid>
		<description>In general, anything executable with a .TMP extension is suspicious.  Furthermore, if it/they are running out of the "Temp" directory or any of the "Temporary Internet Files" directories/folders, they're suspect.

All of the previous posters are correct, so no need to restate what they've already said.  One simple thing to try though is to delete all temporary Internet files, and clear out the temp directory.  Then see what happens after a reboot.

Bob

p.s. I also donate money to Patrick Kolla (safer-networking), author of Spybot Search &#38; Destroy and other fun products.  If you value his work, reward him.</description>
		<content:encoded><![CDATA[<p>In general, anything executable with a .TMP extension is suspicious.  Furthermore, if it/they are running out of the &#8220;Temp&#8221; directory or any of the &#8220;Temporary Internet Files&#8221; directories/folders, they&#8217;re suspect.</p>
<p>All of the previous posters are correct, so no need to restate what they&#8217;ve already said.  One simple thing to try though is to delete all temporary Internet files, and clear out the temp directory.  Then see what happens after a reboot.</p>
<p>Bob</p>
<p>p.s. I also donate money to Patrick Kolla (safer-networking), author of Spybot Search &amp; Destroy and other fun products.  If you value his work, reward him.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ELPUEBLO</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/strange-processes-showing-up-in-the-task-list-some-random-numberstmp/#comment-46081</link>
		<dc:creator>ELPUEBLO</dc:creator>
		<pubDate>Fri, 16 Jun 2006 12:45:16 +0000</pubDate>
		<guid isPermaLink="false">#comment-46081</guid>
		<description>PER CA (Makers of PestPatrol and etrust products)

it may be 1 of 2 trojan/viruses

1) Win32.Betalire Family
    aka AdClicker-BA.dll (McAfee), Win32/Betalire, Win32.Betalire, Win32.Betalire.B, Win32/Betalire.B!DLL!Trojan, Win32/Betalire.C, Win32.Betalire.C, Win32/Betalire.D, Win32.Betalire.D, Win32/Betalire.D!Trojan, Win32/Betalire.E, Win32.Betalire.E, Win32/Betalire.E!Trojan, Win32.Betalire.F, Win32.Betalire.G, Win32.Betalire.H, Win32.Betalire.I, Win32.Betalire.J, Win32.Betalire.K, Win32.Betalire.L, Win32.Betalire.M, Win32.Betalire.N, Win32.Betalire.O, Adware-EliteBar (McAfee) 

"http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=43340"
or

2)Win32.Spabot.A
    aka Downloader-LZ (McAfee), Trojan.Spabot (Symantec), Win32/SpaBot.A.Trojan, Trojan.Win32.Spabot.c (Kaspersky) 

"http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39923"

I too am interested to know what AV you have running.

are you running the adaware in safe mode?  Get a copy of clamwin @ "clamwin.com" (using another computer if possible), burn it to cd (Instructions on Clamwin site) and run a scan from the CD</description>
		<content:encoded><![CDATA[<p>PER CA (Makers of PestPatrol and etrust products)</p>
<p>it may be 1 of 2 trojan/viruses</p>
<p>1) Win32.Betalire Family<br />
    aka AdClicker-BA.dll (McAfee), Win32/Betalire, Win32.Betalire, Win32.Betalire.B, Win32/Betalire.B!DLL!Trojan, Win32/Betalire.C, Win32.Betalire.C, Win32/Betalire.D, Win32.Betalire.D, Win32/Betalire.D!Trojan, Win32/Betalire.E, Win32.Betalire.E, Win32/Betalire.E!Trojan, Win32.Betalire.F, Win32.Betalire.G, Win32.Betalire.H, Win32.Betalire.I, Win32.Betalire.J, Win32.Betalire.K, Win32.Betalire.L, Win32.Betalire.M, Win32.Betalire.N, Win32.Betalire.O, Adware-EliteBar (McAfee) </p>
<p>&#8220;http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=43340&#8243;<br />
or</p>
<p>2)Win32.Spabot.A<br />
    aka Downloader-LZ (McAfee), Trojan.Spabot (Symantec), Win32/SpaBot.A.Trojan, Trojan.Win32.Spabot.c (Kaspersky) </p>
<p>&#8220;http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=39923&#8243;</p>
<p>I too am interested to know what AV you have running.</p>
<p>are you running the adaware in safe mode?  Get a copy of clamwin @ &#8220;clamwin.com&#8221; (using another computer if possible), burn it to cd (Instructions on Clamwin site) and run a scan from the CD</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dusty1</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/strange-processes-showing-up-in-the-task-list-some-random-numberstmp/#comment-46082</link>
		<dc:creator>dusty1</dc:creator>
		<pubDate>Fri, 16 Jun 2006 10:04:57 +0000</pubDate>
		<guid isPermaLink="false">#comment-46082</guid>
		<description>If you're not running a workstation (I'm assuming this is a workstation) firewall, install one!  Download ZoneAlarm, at least, and set it up so that only the programs you designate can get to the network.  

While that might not remove your bot, if you have one, at least it will stop it from transmitting it's info out to the 'net.

I've seen some music sharing programs or other streaming media programs use so much thruput that they can also shut down an Internet connection.

Just my 2 cents.

</description>
		<content:encoded><![CDATA[<p>If you&#8217;re not running a workstation (I&#8217;m assuming this is a workstation) firewall, install one!  Download ZoneAlarm, at least, and set it up so that only the programs you designate can get to the network.  </p>
<p>While that might not remove your bot, if you have one, at least it will stop it from transmitting it&#8217;s info out to the &#8216;net.</p>
<p>I&#8217;ve seen some music sharing programs or other streaming media programs use so much thruput that they can also shut down an Internet connection.</p>
<p>Just my 2 cents.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bladish</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/strange-processes-showing-up-in-the-task-list-some-random-numberstmp/#comment-46083</link>
		<dc:creator>bladish</dc:creator>
		<pubDate>Fri, 16 Jun 2006 09:24:33 +0000</pubDate>
		<guid isPermaLink="false">#comment-46083</guid>
		<description>To help you better identify the process and get more information you might conisder getting a program called Process Explorer from Sysinternals - www.sysinternals.com.

They have another handy tool that I like to use called TCPView that will show you processes and what connections they are making via udp and tcp protocols.

</description>
		<content:encoded><![CDATA[<p>To help you better identify the process and get more information you might conisder getting a program called Process Explorer from Sysinternals -&nbsp;&lt;a href="http://www.sysinternals.com" title="http://www.sysinternals. " target="_blank"&gt;www.sysinternals.com&lt;/a&gt;.</p>
<p>They have another handy tool that I like to use called TCPView that will show you processes and what connections they are making via udp and tcp protocols.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dwiebesick</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/strange-processes-showing-up-in-the-task-list-some-random-numberstmp/#comment-46084</link>
		<dc:creator>dwiebesick</dc:creator>
		<pubDate>Fri, 16 Jun 2006 09:22:37 +0000</pubDate>
		<guid isPermaLink="false">#comment-46084</guid>
		<description>If you have the technical experience, here are some suggestions to try:
Down load autoruns from www.systernals.com Run the program and uncheck any item from the list that looks suspecious. This is like a toggle switch, you can uncheck to turn it off and put the check back to reenable the item.

Boot in safe mode with networking and go to http://www.bitdefender.com/scan8/ie.html and run their online scan.

Reboot into safe mode with networking and go to http://housecall.trendmicro.com/ and run their online scan. 

http://www.merijn.org/ is a site that contains more information that may assist you.

report back and let us know your results.

Best of luck
dmw</description>
		<content:encoded><![CDATA[<p>If you have the technical experience, here are some suggestions to try:<br />
Down load autoruns from&nbsp;&lt;a href="http://www.systernals.com" title="http://www.systernals. " target="_blank"&gt;www.systernals.com&lt;/a&gt; Run the program and uncheck any item from the list that looks suspecious. This is like a toggle switch, you can uncheck to turn it off and put the check back to reenable the item.</p>
<p>Boot in safe mode with networking and go to&nbsp;&lt;a href="http://www.bitdefender.com/scan8/ie.html" title="http://www.bitdefender.com/scan8/ie.html" target="_blank"&gt;http://www.bitdefender.com/scan8/ie.html&lt;/a&gt; and run their online scan.</p>
<p>Reboot into safe mode with networking and go to&nbsp;&lt;a href="http://housecall.trendmicro.com/" title="http://housecall.trendmicro.com/" target="_blank"&gt;http://housecall.trendmicro.com/&lt;/a&gt; and run their online scan. </p>
<p>&nbsp;&lt;a href="http://www.merijn.org/" title="http://www.merijn.org/" target="_blank"&gt;http://www.merijn.org/&lt;/a&gt; is a site that contains more information that may assist you.</p>
<p>report back and let us know your results.</p>
<p>Best of luck<br />
dmw</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: netware13</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/strange-processes-showing-up-in-the-task-list-some-random-numberstmp/#comment-46085</link>
		<dc:creator>netware13</dc:creator>
		<pubDate>Fri, 16 Jun 2006 09:18:34 +0000</pubDate>
		<guid isPermaLink="false">#comment-46085</guid>
		<description> Not knowing your platform or OS, and your statement that you think it is a trojan, I am going to assume you are talking about a workstation OS.
 Here is a link to a discussion that sounds a lot like what you are talking about:

http://forums.spybot.info/archive/index.php/t-3208.html

 I saw some information on somethings that are similar, but they are in regards to an IBM server running a version of symantec AV, and also windows 2003 IIS6 using ,NET V2.

 Hope this helps, and good luck.</description>
		<content:encoded><![CDATA[<p> Not knowing your platform or OS, and your statement that you think it is a trojan, I am going to assume you are talking about a workstation OS.<br />
 Here is a link to a discussion that sounds a lot like what you are talking about:</p>
<p>&nbsp;&lt;a href="http://forums.spybot.info/archive/index.php/t-3208.html" title="http://forums.spybot.info/archive/index.php/t-3208.html" target="_blank"&gt;http://forums.spybot.info/archive/index&#8230;.&lt;/a&gt;</p>
<p> I saw some information on somethings that are similar, but they are in regards to an IBM server running a version of symantec AV, and also windows 2003 IIS6 using ,NET V2.</p>
<p> Hope this helps, and good luck.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
<!-- dynamic -->