Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Suspicious Program Running in Temp


  • Please log in to reply
4 replies to this topic

#1 A Selene

A Selene

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:05 PM

Posted 07 February 2018 - 11:13 PM

Server 2003, in C:\WINDOWS\Temp is running gfxdrv.exe and it's a heavy CPU consumer.

It's unsigned and is using about 75% of the CPU.

 

Antivirus scan finds nothing wrong with it but I wonder...



BC AdBot (Login to Remove)

 


m

#2 SniperK4100

SniperK4100

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:07:05 PM

Posted 08 February 2018 - 02:26 AM

having the same problem. Started Tuesday.

 

I have delete the file from TEMP folder.

 

Don't like that I don't know the cause of the problem



#3 A Selene

A Selene
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:05 PM

Posted 08 February 2018 - 02:39 AM

having the same problem. Started Tuesday.

 

I have delete the file from TEMP folder.

 

Don't like that I don't know the cause of the problem

 

I've done the same thing. Will submit for analysis in the morning. thanks.



#4 A Selene

A Selene
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:05 PM

Posted 08 February 2018 - 11:23 AM

 

having the same problem. Started Tuesday.

 

I have delete the file from TEMP folder.

 

Don't like that I don't know the cause of the problem

 

I've done the same thing. Will submit for analysis in the morning. thanks.

 

 

VirusTotal results:

https://www.virustotal.com/#/file/638ea5d6bf8d6703b6a8e39622d88ad3dd75f5557fa81223b1ca861605caaeb6/detection

As I read it, 39 of 67 scan engines flag it as a malicious file.



#5 A Selene

A Selene
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:05 PM

Posted 08 February 2018 - 07:43 PM

Trend Micro WFBS now pronounces this a Trojan and quarantines it.

Good show...






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users