Cahce on boot up (dio, mar, sts) -Logs Attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by Moe.help, Oct 21, 2008.

  1. Moe.help

    Moe.help Private E-2

  2. Moe.help

    Moe.help Private E-2

    MGlog.zip attached.
     

    Attached Files:

  3. Moe.help

    Moe.help Private E-2

    The three logs ARE attached this time - to early!

    Thanks again!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are all clean and do not show any signs of the files you are mentioning. I assume you meant you were seeing this in your C:\Documents and Settings\Owner\Local Settings\Temp\ folder?
     
  5. Moe.help

    Moe.help Private E-2

    Maybe I did something wrong?

    I just rebooted twice.

    Using McAfee>Advanced menu>Tools>McAfee Quick Clean – I see the following

    All in path c:\documents and settings\adp-bum\local settings\temp\ “file name”.tmp
    I will see these files or some form of them no matter which user I boot up as.


    1st reboot.

    MARB.TMP (1285Bytes)
    STSF.TMP (103 Bytes)

    I ran the McAfee “quick clean” and rebooted.

    This time I (“Quick Clean”) saw the following.

    2nd Reboot

    DIO19.tmp
    DIOC.tmp
    DIOD.tmp (ALL 47,122 BYTES)

    MARA.tmp (1285 bytes)

    STS1A
    STSF (BOTH 117Bytes)

    Also noticed a Real Media cookie although I traveled to no web sites nor did I open IE.
    Also from time to time I see a file named VBE (Visual Basic Editor?) as I did the second reboot.

    Could this be normal stuff that I am seeing?

    The computer does seem slower than it should be and there is a great of disk chatter this AM.

    Thanks again.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you post logs for the user account named owner which did not show these files. The owner account is an admin account and the adp-bum account is a restricted user account. These file may not even be problems although many people often just remove them since they are in a temp folder and are not required. If you could put 1 of each type file name into a ZIP file and attach it, I will take a look at them to see if we can determine what they are from.

    If you want us to check out the adp-bum account, you will have to run SAS, MBAM, and MGtools while logged into this account. And attach these new logs.


    Both normal and cookies are not problems.

    It could just be due to McAfee; however run the below and attach the requested log:

    Running GMER to detect rootkits
     
  7. Moe.help

    Moe.help Private E-2

    I can't thank you enough for all of the help.

    Attached is the gmer log.

    I will reboot and gather the other logs (as owner) in a few minutes.

    I will check to see if the files are present "prior" to running them

    Thanks again!
     

    Attached Files:

  8. Moe.help

    Moe.help Private E-2

    Attached is the zip folder with examples of each of the temp files.

    DIO - MAR - STS

    Thanks again - I really hope I am not being a pain!
     

    Attached Files:

  9. Moe.help

    Moe.help Private E-2

    Reran GMer (correctly this time - I hope).

    See attached.

    Thanks again.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The GMER logs are clean.

    These files are not problems and may all be related to your HP Printer. The STS14.tmp file shows the below:
    And the DIOC.tmp file just has lots of info related to different character sets and key codes for different languages. And the MARB.tmp file is also benign. It is probably just something used by the HP software in doing updates or similar.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. After doing the above, you should work thru the below link:
     
  11. Moe.help

    Moe.help Private E-2

    Thank you very much for all of the help and piece of mind (those temp files were driving me nuts).

    I will procede with the suggestions.

    Thanks again!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds