fnm5D.tmp & SB-CLSID-cache.dat

Discussion in 'Malware Help (A Specialist Will Reply)' started by quatrosales, Aug 10, 2006.

  1. quatrosales

    quatrosales Private E-2

    These files keep showing up in my temp directory. fnm5D.tmp & SB-CLSID-cache.dat
    Actually the "fnm" files multiply in the temp directory. The form is "fnmXX.temp"

    bitdefender reported NO Infections.

    I followed all the steps. CCcleaner, Spybot, SpyCatcher.

    I am at wits end.

    Ron
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    I need the logs from ShowNew & CounterSpy as requested in the READ ME. However this does not sound like malware. It just sounds like temp files being created by somethings that you are running on your PC.
     
  3. quatrosales

    quatrosales Private E-2

    I'm sorry I thought I had attached this file to my original post.

    Ron

    PS thanks for your INCREDIBLE work helping people!!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. You still forgot to attach the log from CounterSpy.

    Why didn't you install and run Spybot as requested in the READ ME? Please do this now! Make sure you run a full scan and also use the Immunize feature. DO NOT use Teatimer.


    Are the below programs paid or free versions?
    SpyCatcher Express 2006
    Spyware Doctor 4.0

    Uninstall the below old version of Sun Java
    Java 2 Runtime Environment, SE v1.4.1_02

    Did you copy MSconfig from another PC to this Windows 2000 PC which does not have MSconfig as part of the OS?

    "C:\WINNT\system32\"
    msconfig.exe Jun 5 2006 145408 "msconfig.exe"

    Also you appear to be using MSconfig to control startups which we specifically request that you not do in the READ ME. You must select normal startup.

    You logs are really not showing any signs of malware problems!
     
    Last edited: Aug 12, 2006
  5. quatrosales

    quatrosales Private E-2

    As to spybot, I've been using spybot for at least a year! It is always the first scan I use. I did not see in the READ ME that you wanted the log from Spybot.

    I did import msconfig, this was at the request of some tech support guy for some program somewhere along the way. I have programs that want to run at startup. I search the registry and still can't keep them form running, msconfig is the only way I can stop them. I would love to be able to do that without it.

    I know it looks like I don't have any malware, but, my hard drive is working when I'm not doing anything and the fnmxx.tmp and clsid files keep showing up. Some program is creating these files.

    I will uninstall the old Java, I've never done that as I wasn't sure what the result would be. As to the I'm sure I save the log file, but don't know its name so I'm rerunning it and will attach it next.

    Ron
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For some reason it is not showing in your Uninstall programs list at the end of the ShowNew log. Look for yourself. Does it appear in Add/Remove Programs?

    We don't ask for one in the READ ME and I did not ask for one either. I did however ask for a CounterSpy log!

    This is not how Microsoft intended MSconfig to be used. It is only meant to be used as a temporary debugging tool. Things that you do not want to run at startup should either be uninstalled or if you still need them but do not want them to run at startup, you should disable the program itself from loading at startup. Also better tools exist then using MSconfig. For example: Startup CPL

    Processes are always running on your PC and some of them may be accesing the harddisk. There are also disk indexing services that run and cause lots of disk activity.

    What CLISD files and where are they located? Be specific.
     
    Last edited: Aug 13, 2006
  7. quatrosales

    quatrosales Private E-2

    Spybot does not show up in add/remove. While it functions well, all labels on buttons have disappeared as of late. I've been meaning to uninstall and reinstal it. The programs you asked about, spy catcher and spy dr. are the free versions.

    A cut and paste version of the counterspy report is attached.

    I will work on replacing msconfig. I did not realize it was a problem. Thanks!!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should uninstall it, REBOOT, and then reinstall.

    Then they are not worth having installed.

    There is no sense in running the scans unless you allow them to fix the problems they find. You told CounterSpy to ignore everything.
     
  9. quatrosales

    quatrosales Private E-2


    I had already run CounterSpy and fixed the problems it found. The ignored programs have been on my machine for a very long time before this problem started and have never produced this result.

    BTW while the fnmXX.tmp files tend to increase in number over time, I can delete all but one or two which seem to be in use. I can delete them, however, when booted up in safe mode.

    Spybot reinstalled reports no problems.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    WeatherBug is a program that has received much debate on weather it is malware. It is definitely adware supported. Did you notice that it adds literally many hundreds of keys to your registry? While it is up to you weather you want to remove it or not, most scanners detect it as a problem and remove it. The second item eDonkey2000 contains bundled malware and should not be used. Many malware removal forums will refuse to even work on a PC until all P2P programs have been uninstalled. Since P2P programs can be a source or malware, they can download new malware on to a PC faster than we can clean it so it can be a complete waste of time trying to remove malware while programs like this are present.

    They just sound to me like they belong to an application you are running. While it is running, the temporary files cannot be deleted. Do you still have SpyCatcher installed?
     
  11. quatrosales

    quatrosales Private E-2

    OK. I'll remove Weatherbug and edonkey, if for no other reason than I'm pretty well out of options. So we'll see. Yes I have SpyCatcher and will rerun it. It seems to me, but what do I know, that there should be a way of finding out what program creates a file in the temp directory. Obviously, a program is running that does not appear in ANY listing of what starts at startup. How can this be tracked?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I really did not want you to rerun it. I wanted to see if you had uninstalled it because I said to uninstall it. I never use it. It could even be a source of the temp files.


    There are many tools that can be used to do all kinds of things. They just are not necessarily things for novices to use. If you want to hunt this down further you could do several things:

    1. look at the contents of the files to see if there is anything in them that reveals what they are from.
    2. look at file Properties for Version info (if any exists)
    3. Use a program like this: Filemon v7.03
    4. Also this can prove useful: Regmon v7.03
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds