Or you have a virus/trojan/spy on your machine, but the name looks familiar.
| Forum Announcement |
Welcome to the new CNET Forums! Please don't panic. You are not in the Twilight Zone, you are experiencing the new CNET forums platform! Please click here to read the details. Thanks!!
Many times after booting up my computer and going on line I notice a heavy download of data flow thru my Internet Connection to my computer. I am not running any programs that require downloads after Start Up, not even my Norton AntiVirus. I have all Norton Programs disabled on Start Up. The Hidden File in my Temp Folder is ( BIT1.tmp ). I have to cut my Internet Connection before deleting this File. I think this file comes from the Windows Core Files to download for the Windows XP Operating System. I can halt the download after I delete this hidden file from my Temp folder, but the same file usually keeps popping up in my Temp Folder most of the time on the next boot up. Does anyone know exactly what this File is? The Search Option on Windows XP can not find this file. That is why I am inclined to believe this is one of Windows XP Files downloading data for the operating system or worse yet downloading data for self serving reasons for Microsoft. Any Help will be much appreciated.
I have disabled all of Windows XP Updates Totally. This is a new Copy of Windows XP 2002 Home Edition that I have installed. I usually save all my data on my computer and Clean my Hard Drive and reinstall Windows XP about every 2 months. Before I surf the internet I always reinstall my Norton AntiVirus and Run Updates to be current on Virus Protection as well as Trojans, Spyware, etc. This file, I am 99.9% sure is coming from the Windows Core Files. I just want to find out what Windows is trying to download. All the Windows Updates have been disabled and configured to run only when I allow them to, but I am sure that Windows has backup systems to do what they want. They do not want the users to be 100% in control. What are your thoughts about that?? Anxiously waiting for your reply..
I've got exactly the same problem(see discussion started by me (BIT*TMP files).
Bob is helping me, but tell me one thing, especially to Bob: Have you any P2P(emule 1.1d) software installed?
I didn't resolve the problem yet. Very tricky this one.
There is a line in register:
which can't be eliminated.
I've tried all kind of security software(spybot, adawrae, hijackthis, rootkit, xsoftspy). No way to get rid of these bit*tmp files.
I disabled automatic updates at services.msc and the microsoft windows XP automatic update options. Yes, SP2 installed.
I've no security running automatically, I activate Panda antivirus manually and have my pc "immunized" by spybot.
After running hijackthis the following LOG was displayed:
Logfile of HijackThis v1.99.1
Scan saved at 10:15:29, on 03/07/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
C:\Archivos de programa\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\Archivos de programa\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
C:\Archivos de programa\Panda Software\Panda Antivirus Platinum\AVENGINE.EXE
C:\Archivos de programa\Panda Software\Panda Antivirus Platinum\apvxdwin.exe
C:\Archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe
C:\Archivos de programa\Messenger\msmsgs.exe
C:\Archivos de programa\Panda Software\Panda Antivirus Platinum\pavProxy.exe
C:\Archivos de programa\BySoft StayAlive Pro\StayAlive.exe
C:\Archivos de programa\Mozilla Firefox\firefox.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.es
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.es/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.es
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.es/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = V
I've never hidden the fact that my boy installed P2P software.
Never lied avbout this fact, never, never, never.
I don't like to lie about things that can be important, but not trying to help somebody, just because you don't like P2P software, completely legal as far as I know in Europe. I told all of you again and again that before I became an internet paria, that is before my boy installed this emule I had this same problem, long long long before I even heard of P2P software. No relation at all with this software, otherwise I would be looking for a solution in a P2P forum, wouldn't I. I'm getting tired of this nonsense. Maybe there's some other reason not trying to help me. One more clue before I jump from the Eiffel Tower, guilty of using P2P(Yes, my son is using P2P software): could the problem be a parental control named pc tattletale?
Again, I stand guilty(but I never hid the fact)
... the Bit*.Tmp files can be produced by Auto-Windows Update, and maybe the Bit-Torrent P2P program. Are you using Bit-Torrent ? If P2P is not on your machine, it may be a different matter. If you have disabled Automatic Windows Update, what is showing at ''services.msc'' upon reboot ? If you go to Windows Update, do you get the message that Automatic Windows update is off and advised to put it on ?
Hope this discussion's going back to normal.
On the services.msc the automatic updates is turned off.
Maybe there's a clue for you. In another forum a guy had the same problem and discovered that a connection to the IP 22.214.171.124 was made. Is this the beginning of a sultion? I really hope so.
P.s. never used other P2P software than emule 1.1d.
In an emule foprum nobody ever heard of this bit.tmp files.
Again, thank you very much for your trouble.
Bob gave me the clue. I finally "deciphered" his, for me at least, cryptic messages and it was in services.msc where I deactivated the Background Intelligent Transfer Service. Worked perfectly.
Thank you, Bob.
P.s. Bob, I'll try to convince my boy to leave P2P software alone, but I can't promise, because he's 14 years old and very stubborn.
Tired of your tricky Wi-Fi password?
Stop trying to memorize a complicated sequence of numbers and letters. Learn how to change the default password.