GTX Posted April 29, 2016 Posted April 29, 2016 Hi there, Keep getting a RunDLL egkAF3C.tmp file popup every hour or so on one of our machines. Screenshot: http://puu.sh/ozV88/f46e218904.jpg Had a quick google.. Nothing Checked the file location. Nothing in there. Any ideas guys?
mrwoberts Posted April 29, 2016 Posted April 29, 2016 (edited) To me, that kind of behaviour looks incredibly suspicious - malware like. Either that or something legit is attempting to be installed. What kind of changes have you made recently? GPO, local machine... What is the history of this user, have they noticed anything out of the ordinary, before this message? Edited April 29, 2016 by mrwoberts 1
GTX Posted April 29, 2016 Author Posted April 29, 2016 Funny you should say that MrWoberts, She had a popup saying she had a virus out of no were. So i did a scan and found 1 thing. Im "guessing" its installed a virus. ESET has removed it but there is a task scheduler trying to run it every hour or so? Ill take a look. Thanks Woberts!
mrwoberts Posted April 29, 2016 Posted April 29, 2016 Ah, thought so. Who uses this machine and what kind of access does it have to your network? Shared drives... You might just want to keep this machine under close monitoring, or better still, remove it from the network and see how serious it is. If you have even an little bit of doubt that the machine is clean, I would re-image the thing. Interesting that ESET didn't do a slightly better job at stopping the infection at source. 1
ZeroHour Posted April 29, 2016 Posted April 29, 2016 I would run a Malwarebytes scan as well to see if it picks up more, normally it does tbh. 1
Duke5A Posted May 2, 2016 Posted May 2, 2016 (edited) Quick and dirty method is to use 'msconfig' and take a peak under the Services and Startup tabs. Be sure to hit the check box on the Services tab that hides all MS services. Edit: If it's coming back while the machine is on then it might be a scheduled task. Take a look in there. Edited May 2, 2016 by Duke5A 1
Arthur Posted May 2, 2016 Posted May 2, 2016 If you enable the VirusTotal integration in Autoruns and/or Process Explorer you should be able to find out what malware is attempting to run. 1
ITGURU Posted May 2, 2016 Posted May 2, 2016 I've had about 3 reports from users in the past with these kind of error messages appearing when they first login. It's usually because malware hasn't been able to successfully run, causing a partial install. The way I sort it is by scanning the machine with malwarebytes which usually finds nothing at all, but then I search the registry for the file name which usually returns it in the run location of the users profile, so I just delete the key and it stops the error appearing. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now