We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

re-hijack this

Options
24

Comments

  • GunJack
    GunJack Posts: 11,828 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    RussJK wrote: »
    Also upload this to www.virustotal.com, even though it's usually a legit Realtek file:
    C:\Users\joe\AppData\Local\Temp\RtkBtMnt.exe

    bit of invest shows that if it's in a temp file, likelyhood is it's dodgy. Could have been legit if in a normal windows location (part of realtek HD sound). Check out

    http://www.pcmech.com/forum/networking-online-security/211839-rtkbtmnt-exe.html
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • joe134
    joe134 Posts: 3,336 Forumite
    edited 9 August 2011 at 4:32PM
    GunJack wrote: »
    two things jump out at me on the HJT log - Rapport and spybot's teatimer.

    Rapport is junk and well-known for bad interactions with other software, such as....yes, you guessed it, teatimer ;)

    Go into spybot and turn off teatimer (advanced mode, resident, untick teatimer) and uninstall rapport, then try again :)
    Hi Gunjack, thanks for info.I,ve done teatimer, BUT, I know the Rapport pros/cons. and have had it ages with no ill effects.+ do lots of internet banking, and prefer to keep it. I know you may /will disagree and tell me, why ask if I don,t take your advice.I can turn it off when downloading etc.If it continues, then I will take it off. Also, I,m lost about Upload. Is it the log, to upload? and are you disagreeing? .never heard of the site, or what it does.:beer:
  • RussJK
    RussJK Posts: 2,359 Forumite
    edited 9 August 2011 at 4:48PM
    Go to www.virustotal.com, press Browse, then in the dialog copy/paste this line:
    C:\Users\joe\AppData\Local\Temp\RtkBtMnt.exe
    and press enter.

    It should start to upload the file. When it gives a report, give us the URL/link if you can.

    Virustotal is a site that has multiple antivirus scanners from various vendors, and allows suspicious files to be checked. Of course you can't rely completely on the results, as there are many reasons for false positives and false negatives.

    The file I'm suggesting you upload is suspicious as it's running from a temp folder, even though it might be a legit file left running after an automatic update. There'd be no good recent for Realtek to want it permanently running from a temp folder, but there's no obvious autostart for it either. If it persists after a reboot, I'd be more even more suspicious.
  • joe134
    joe134 Posts: 3,336 Forumite
    RussJK wrote: »
    Go to www.virustotal.com, press Browse, then in the dialog copy/paste this line:
    C:\Users\joe\AppData\Local\Temp\RtkBtMnt.exe
    and press enter.

    It should start to upload the file. When it gives a report, give us the URL/link if you can.

    Virustotal is a site that has multiple antivirus scanners from various vendors, and allows suspicious files to be checked. Of course you can't rely completely on the results, as there are many reasons for false positives and false negatives.

    The file I'm suggesting you upload is suspicious as it's running from a temp folder, even though it might be a legit file left running after an automatic update. There'd be no good recent for Realtek to want it permanently running from a temp folder, but there's no obvious autostart for it either. If it persists after a reboot, I'd be more even more suspicious.
    I,ve just read the link Gunjack gave bout it.I,ll try and do as you say,hope i,m successful.
  • joe134
    joe134 Posts: 3,336 Forumite
    joe134 wrote: »
    I,ve just read the link Gunjack gave bout it.I,ll try and do as you say,hope i,m successful.
    Sorry Russ, I am a bit lost here,I cannot find BROWSE in the upload a file section, just list of files that doesn,t inclde that one.It,s probably me not doing it right.Where s the BROWSER? on the page
  • santer_2
    santer_2 Posts: 4,406 Forumite
    1,000 Posts Combo Breaker
    When I clicked this link it was below FAQ

    http://www.virustotal.com/

    You can e-mail them

    http://www.virustotal.com/advanced.html#email
  • GunJack
    GunJack Posts: 11,828 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    there's also a lot of carpy services running in there too, like all the acer sw, AOL connectivity, etc. I suggest once you've got it stable visit closed's thread on speeding up a pc, as the less carp running will also help with the overall stability :)
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • RussJK
    RussJK Posts: 2,359 Forumite
    virustotal1.png
  • joe134
    joe134 Posts: 3,336 Forumite
    RussJK wrote: »
    virustotal1.png
    I don,t get that when I visit. I get,choose file to the left, and no browse at all to the right.I,ve E-mailed them, but thats supposed to be an /or the Attached file, which I cannot find, so just typed it, and sent.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.8K Banking & Borrowing
  • 253K Reduce Debt & Boost Income
  • 453.5K Spending & Discounts
  • 243.8K Work, Benefits & Business
  • 598.6K Mortgages, Homes & Bills
  • 176.8K Life & Family
  • 257K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.