Jump to content

Search the Community

Showing results for tags 'temp'.

  • Search By Tags

    Type tags separated by commas.
  • Search By Author

Content Type


  • Announcements
    • Malwarebytes News
    • Beta Testing Program
  • Malware Removal Help
    • Windows Malware Removal Help & Support
    • Mac Malware Removal Help & Support
    • Mobile Malware Removal Help & Support
    • Malware Removal Self-Help Guides
  • Malwarebytes for Home Support
    • Malwarebytes for Windows Support Forum
    • Malwarebytes for Mac Support Forum
    • Malwarebytes for Android Support Forum
    • Malwarebytes for iOS Support
    • Malwarebytes Privacy
    • Malwarebytes Browser Guard
    • False Positives
    • Comments and Suggestions
  • Malwarebytes for Business Support
    • Malwarebytes Endpoint Protection
    • Malwarebytes Incident Response (includes Breach Remediation)
    • Malwarebytes Endpoint Security
    • Malwarebytes Business Products Comments and Suggestions
  • Malwarebytes Tools and Other Products
    • Malwarebytes AdwCleaner
    • Malwarebytes Junkware Removal Tool Support
    • Malwarebytes Anti-Rootkit BETA Support
    • Malwarebytes Techbench USB (Legacy)
    • Malwarebytes Secure Backup discontinued
    • Other Tools
    • Malwarebytes Tools Comments and Suggestions
  • General Computer Help and Security Updates
    • BSOD, Crashes, Kernel Debugging
    • General Windows PC Help
  • Research Center
    • Newest Rogue-Ransomware Threats
    • Newest Malware Threats
    • Newest Mobile Threats
    • Newest IP or URL Threats
    • Newest Mac Threats
    • Report Scam Phone Numbers
  • General
    • General Chat
    • Forums Announcements & Feedback

Find results in...

Find results that contain...

Date Created

  • Start


Last Updated

  • Start


Filter by number of...


  • Start





Website URL






Found 13 results

  1. Hey guys, I noticed a strange folder in my temp folder called BCLTMP containing subfolders with the names of my browsers. Inside of these folders are files that contain my saved favourites, visited urls and searches. After deletion of the BCLTMP folder it appears again after a while, sometimes after a day, a week or a month. After scanning my PC with all the tools I have (which didn't find much and didn't stop the folder appearing) I decided it might be normal.. Then I bought a new laptop which showed the same behavior within the same week I bought it. Nothing was installed on the laptop, no usb used, it had only been connected to my router. I have connected other laptops to my network in the past which showed the same behavior. Could this BCLTMP folder which seems to track my browser history be spyware/malware? No one else seems to have the folder. I am using Windows 10 pro on both devices. I tried scanning with malwarebytes, roguekiller, adwcleaner, eset sysrescue, exterminate it, spydllremover (which reports hidden rootkit, with processID, hidden), superantispyware. tdsskiller won't boot (redownloaded, same result) and comodo CCE crashes the computer and then refuses to boot. Note that the laptop with the BCLTMP folder is a clean windows 10 install with no installed software. My router reports synflood attacks from within and outside of my network, and it's firmware has been reinstalled by the isp just to be sure. Not much else to see there. How can I figure out what is happening to my devices, and what this folder is for?
  2. Runtime Error (at 47:120): Could not call proc =================================== Microsoft Windows 10 Pro x64 Version 1607 (OS Build 14393.1480) My %Temp% and %Tmp% are normally set to a RAM drive, in format 'Z:' (no quotes). Attempting to update, offline, from MBAM free to MBAM free using mb3-setup-consumer- I repeatedly found that immediately after selecting the language, installation failed with the message: "Runtime Error (at 47:120): Could not call proc" I saw the same behaviour when I tried the mb3-setup-consumer- beta installer. Today (Thu 03 Aug 2017) I tried the 3.1 update again but first changed both %Temp% and %Tmp% back to: '%USERPROFILE%\AppData\Local\Temp' (No quotes). I then immediately, without reloading Windows, ran the MBAM 3.1 installer/updater again. It ran right through and appears to have sucessfully updated to MBAM 3.1. I inspected the settings, which appear to be, as far as is applicable, migrated. During the update, MBAM appears to have been completely removed from 'Program Files (x86)' and MBAM has been installed in 'Program Files' That seemed excellent until I noticed that 'Task Manager' > 'Processes' showed Malwarebytes is running as a 32 bit application, so shouldn't it be in 'Program Files (x86)'? I set my %Temp% and %Tmp% both back to my normal values, directing them to the RAM drive. I then went on line and requested whatever updates were available. (nb Controls for that are not well presented and neither could I clearly see what updates were actually done at that stage) I now see: " Version Information Malwarebytes version: Component package version: 1.0.160 Update package version: 1.0.2503 " So I am able to report that temporarily switching to the default Temp and Tmp directories fixed the update failure ===================================================================================== and it is proven that otherwise the install/update failed because it couldn't cope with those directories being on the RAM drive. =============================================================================================== I cannot commit to any further testing or diagnostics on this but hope that my information helps. Now I need to actually try running MBAM 3.1 and hope it will behave tolerably well.
  3. Hi, I used hitman pro and several malware files were detected in the Appdata\Local\Temp\ folder. I deleted them only to reboot and it picked up more of the same only different names example: "1234.tmp.exe" after deleting and reboot, 5678.tmp.exe would be found. I don't know where this came from or how to get rid of it. Malwarebytes does not pick it up at all so far. Is this something I should worry about. The info on HitmanPro says it is from Nircmd and NirSoft which I have no idea how it got on my pc unless installing a security feature on an external drive causes a false positive. I would appreciate any help.
  4. So I have this 'Temp' files in my windows folder and I dont know if this is a malware or something inside the 'Temp' folder I have many subfolders and applications with names here are some of the names: Folders:1.6CB1F574-F625-49C1-830B-8C54F5DE8BA7 2.7D8D418C-8391-40B8-9B00-29A179B9D84B 3.AF6666CB-F4D6-49ED-B8E7-BD13942C7C82 applications:1.{1DFE796C-0E04-4A77-86F6-5ECE11DE1951} 2.{1F04A3EA-17A2-4A65-BD35-1BAAF1E1848C} 3.{2AF06F42-95AE-4916-AFB3-6945EB6CF1A2} can somebody tell me if these are malwares or something I cant risk getting this laptop infected also I think there are more than 100 of these files and theres those tmp files:TS_8668, TS_87E0 those two are just one part of many, also, theres this "LOCAL" and "LOCAL1" executable windows command files and I dont want to run them coz theyre probably a virus or something my online realtime protector is Windows defender Most of the folders have "dismhost" Applications and dimhost.dll
  5. Hi, So a couple weeks ago, I installed a suspicious .exe file from an untrusted source. And then I find my computer was infected with malwares. Now in order to use my computer, I uninstall IE and use opera and Edge as explorer. And there are always many strange .tmp and .exe files in /temp/ folder. After scanning with MSE and Malwarebytes, they would be deleted. But days later, they will reappear. Can you please help me solve this situation? Thanks! Addition.txt FRST.txt
  6. good afternoon, recently my laptop symantec program started sending messages with an oct4ba2.tmp.exe file being reported as having been downloaded and of suspicious origin, each time im given the option of removing the program but it persists each time on computer startup. I downloaded malwarebytes and have attempted to use that program but havent seen any proogress from simply scanning and quaraanting the problem, any help would be greatly appreciated.
  7. Hello, I've been noticing a suspicious programs in Task Manager. First letter of all of them is 'g' and then four always different letters with extension .tmp.exe. Sometimes that program has very high disk usage but rarely. It's location is always in Windows\Temp folder and next to it is file with the same name but with only .tmp extension. Few hours after I stop and delete the file, new one is created and ran. Sometimes I find registry entry in RunOnce with location of g****.tmp.exe. I've downloaded Farbar Recovery Scan Tool and ran it. I attached the FRST.txt and Addition.txt. Thank you for help. Addition.txt FRST.txt
  8. So I don't know for how long I have this but I only noticed it today when I was looking through my taskmanager and I saw it's weird name. At first I tried to just delete the exe's but they reappeared afterwards and I don't know what makes them reappear. I tried installing Malwarebytes but this: After that I tried running it through an Admin console and got So then I browsed a bit through the forums and found this ADWCleaner. Tried to run it and got an red screen telling me the app is blocked, but got it running later through an admin console, AdwCleaner[S0].txt Oh and I'm german so if I wrote anything wrong please correct me. Addition.txt FRST.txt
  9. Hey guys, So there is this virus/malware whatever you want to call it which bothers me every time I start my computer. Once windows 10 boots up and I open Google Chrome this random ****.tmp.exe file is generated in the temp folder. I have attached the file in the zip folder if you guys want to have a look at it (Please don't open the .exe file as it may affect your PC too). As soon as the files are created in the temp folder it also starts in processes. Multiple times I have done a clean uninstallation of Google Chrome and installed it back again but after opening and closing chrome 2-3 times again it gets affected (Without even logging in Google chrome and syncing the data). Google chrome starts flickering 4-5 times and when you search for a result it displays the less memory error. Also, it has affected Mozilla firefox too but not Edge and Internet E. When the tmp.exe is working in the process all the search results are showed in cse i.e. google custom search which is annoying as hell. Once I kill the process and delete the tmp.exe file everything is back to normal but the flickering of Google Chrome is still there whenever I open Google Chrome. Any solution for this problem? Have used CC Cleaner, tried full scan in Kaspersky, etc and still no help. In fact, since my Gmail account was logged in google chrome on my PC and Laptop earlier, this tmp.exe has also affected my laptop too. Please Help! Thanks. Temp.zip
  10. Hi, some time ago I tried the beta 5, but I've then removed, because it gave me this problem, now I tried to make a clean installetion of the beta 6, and unfortunately it still gives me the same problem, that is, when I switch to another account, it's creates the temporary profile, which is then deleted on reboot. Before uninstall MBARW , I saved the log files. logs.zip Malwarebytes Anti-Ransomware.zip
  11. Hi, I have a terrible virus... svchost in my temp folder... any time I tried to kill it, or run any malwarebytes or hijackthis program to try to kill it... it gives me the BSOD. I have a hp pavilion dv7, running windows 7 64 bit. I have found several cases like mine on here.. but they all say do not run those programs unless told to do so by one of ya'll, so here I am. Thank you for your help!!!!
  12. yeah i think this is a false positive, can io ask to make sure here's the logs Malwarebytes Anti-Malware www.malwarebytes.org Database version: v2013.08.27.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16660 User :: SARAHNEW-PC [administrator] 27/08/2013 19:04:59 MBAM-log-2013-08-27 (19-33-46).txt Scan type: Full scan (C:\|E:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 399281 Time elapsed: 26 minute(s), 12 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 4 C:\Users\User\AppData\Local\Temp\mt_ffx (PUP.Optional.BundleInstaller.A) -> No action taken. [a7aa6029fa725cdafc56193f4db527d9] C:\Users\User\AppData\Local\Temp\mt_ffx\Check Point Software Technologies LTD (PUP.Optional.BundleInstaller.A) -> No action taken. [a7aa6029fa725cdafc56193f4db527d9] C:\Users\User\AppData\Local\Temp\mt_ffx\Check Point Software Technologies LTD\zonealarm (PUP.Optional.BundleInstaller.A) -> No action taken. [a7aa6029fa725cdafc56193f4db527d9] C:\Users\User\AppData\Local\Temp\mt_ffx\Check Point Software Technologies LTD\zonealarm\ (PUP.Optional.BundleInstaller.A) -> No action taken. [a7aa6029fa725cdafc56193f4db527d9] Files Detected: 0 (No malicious items detected) (end) ------------------------------------------------- since there folders i can't scan using virus total, however it's zone alarm. i've attached the folders, however each detection is just the next folder down. mt_ffx.zip
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.