Date: 1/01/2015 14:17:04
From: Aquila
ID: 654251
Subject: Unknown Program Access

Wondering if anyone can offer insight to this annoying program access.

My Zonealarm keeps asking (usually once a day) if I will allow this app to access the internet.
I click ‘deny’ because I have no idea which program it belongs too.

I think it is benign but can’t be 100% sure.
I’ve tried to find it by looking in the folder address but can’t find any clue as to what it is.
Don’t worry about the missing part after ‘users’, that’s just my name.

Reply Quote

Date: 1/01/2015 14:27:57
From: fsm
ID: 654254
Subject: re: Unknown Program Access

That looks typical of a virus. Update and run your antivirus program. Update and run Malwarebytes.

https://www.malwarebytes.org/

Reply Quote

Date: 1/01/2015 14:32:56
From: Aquila
ID: 654255
Subject: re: Unknown Program Access

fsm said:


That looks typical of a virus. Update and run your antivirus program. Update and run Malwarebytes.

https://www.malwarebytes.org/

I’ve already run updated malwarebytes and superantispyware, plus my Avast antivirus updates automatically.

Nothing shows up on any of these scans.

Reply Quote

Date: 1/01/2015 14:36:35
From: fsm
ID: 654256
Subject: re: Unknown Program Access

Some worms and viruses morph to avoid detection. Boot into safe mode and try running full scans again.

Reply Quote

Date: 1/01/2015 14:45:29
From: Aquila
ID: 654260
Subject: re: Unknown Program Access

Oh ok, cheers fsm, I’ll try that later, just doing some work at the moment.

I’ve just updated mbam and running it in the background while I work, will try the safe mode later.

My gut feeling is that it’s benign but I just want to know which program it belongs too.

thanks

Reply Quote

Date: 1/01/2015 14:47:57
From: fsm
ID: 654261
Subject: re: Unknown Program Access

A normal program will install and register itself. A virus or other nasty will often run out of a temp folder with an ever changing namepath.

Reply Quote

Date: 1/01/2015 14:53:36
From: Aquila
ID: 654268
Subject: re: Unknown Program Access

Yes, what you’re saying does make sense.

Reply Quote

Date: 1/01/2015 14:54:46
From: fsm
ID: 654269
Subject: re: Unknown Program Access

If you right-click on that Setup.exe and select Properties then you may find a description or a name of the author (if it is legitimate).

Reply Quote

Date: 1/01/2015 14:59:37
From: fsm
ID: 654272
Subject: re: Unknown Program Access

If Zone Alarm will tell you who it is trying to connect to then you could Google that IP and find out if it is a known rogue site.

Reply Quote

Date: 1/01/2015 15:01:58
From: Teleost
ID: 654273
Subject: re: Unknown Program Access

If none of those are doing the job, try Adwcleaner

Reply Quote

Date: 1/01/2015 15:08:32
From: Aquila
ID: 654274
Subject: re: Unknown Program Access

fsm said:


If you right-click on that Setup.exe and select Properties then you may find a description or a name of the author (if it is legitimate).

That’s the thing, I can’t find this setup exe, that image I posted is just the Zonealarm popup letting me know it didn’t execute because I denied it.

You know, I’m wondering if it has something to do with the new Epson printer I installed 2 months ago.

mbam says I’m clean.
I’ve never had issues with viruses …ever…thankfully, I am quite diligent in being careful in this regard.

Reply Quote

Date: 1/01/2015 15:09:08
From: Aquila
ID: 654275
Subject: re: Unknown Program Access

Teleost said:


If none of those are doing the job, try Adwcleaner

I might give this a try, just for the hell of it.

cheers

Reply Quote

Date: 1/01/2015 15:26:14
From: Aquila
ID: 654281
Subject: re: Unknown Program Access

Aquila said:


You know, I’m wondering if it has something to do with the new Epson printer I installed 2 months ago.


I’ll test this theory by uninstalling the printer for a few days.

It’s interesting, just chatting about things with other people can inspire new ideas, thoughts or avenues to pursue

cheers :-D

Reply Quote

Date: 1/01/2015 17:21:12
From: wookiemeister
ID: 654336
Subject: re: Unknown Program Access

I’m always inspired here

Reply Quote

Date: 1/01/2015 19:20:54
From: btm
ID: 654382
Subject: re: Unknown Program Access

At the risk of stating the obvious, try checking the “setup.exe” path before you click “OK” next time the error pops up.

A few years ago I had a vaguely similar issue with my work computer, and finished up using shexview to find that a bot had installed itself and was using shell extensions to execute itself. I posted details on the old TeckTalk, but it seems to be gone.

Reply Quote

Date: 1/01/2015 19:52:04
From: Aquila
ID: 654393
Subject: re: Unknown Program Access

btm said:


At the risk of stating the obvious, try checking the “setup.exe” path before you click “OK” next time the error pops up.

A few years ago I had a vaguely similar issue with my work computer, and finished up using shexview to find that a bot had installed itself and was using shell extensions to execute itself. I posted details on the old TeckTalk, but it seems to be gone.


hmmm, your logic suggests that this pftDxxx.tmp file will locate itself, momentarily in this temp folder, which might allow me to ascertain what program it belongs too?

Reply Quote

Date: 1/01/2015 20:02:59
From: Carmen_Sandiego
ID: 654394
Subject: re: Unknown Program Access

Aquila said:


You know, I’m wondering if it has something to do with the new Epson printer I installed 2 months ago.

My money is on this.

Reply Quote

Date: 2/01/2015 00:40:35
From: btm
ID: 654573
Subject: re: Unknown Program Access

Aquila said:


btm said:

At the risk of stating the obvious, try checking the “setup.exe” path before you click “OK” next time the error pops up.

A few years ago I had a vaguely similar issue with my work computer, and finished up using shexview to find that a bot had installed itself and was using shell extensions to execute itself. I posted details on the old TeckTalk, but it seems to be gone.


hmmm, your logic suggests that this pftDxxx.tmp file will locate itself, momentarily in this temp folder, which might allow me to ascertain what program it belongs too?

Pretty much. If you can find it you can examine it, and find out what it’s doing.

Reply Quote