Question for Shadow_Puter_Dude

Discussion in 'Malware Help (A Specialist Will Reply)' started by CloneT, Jun 6, 2009.

  1. CloneT

    CloneT Private E-2

    Hello Shadow;

    In the following thread:

    http://forums.majorgeeks.com/showthread.php?t=185225&highlight=DIO3.tmp&page=2


    You seem to be concerned about the following files being telltale signs of an infection:
    "
    C:\Documents and Settings\Jim\Local Settings\Temp\UAC822c.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\DIO10.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\DIO3.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\DIO41.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\DIO5.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\DIO6.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\DIO7.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\DIO8.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\DIO9.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\DIOA.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\DIOB.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\DIOD.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\MAR1.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\MAR2.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\MAR3.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\MAR4.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\MAR5.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\MAR6.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\MAR7.tmp
    C:\Documents and Settings\%Userneme%\Local Settings\Temp\MAR8.tmp
    C:\Program Files\bad.dll
    C:\Program Files\AskBarDis\bar\bin\askBar.dll
    C:\Program Files\AskBarDis\bar\bin\AskService.exe
    "

    I have regenerating instances of some of the DIO#.tmp and MAR#.tmp files. The others are not there.

    I have run a SLEW of tools, killed a bunch of bugs, and now the tools do not find any more signs of infection. However, these pesky file keep regenerating upon reboot, and I can't find any definite reference to either legit, or malware info on them.

    Could you help out?

    BTW, I checked into the size of services.exe and it looks ok.

    I'm including my MGlogs just in case anyone else wants to take a shot at this.
    HJT and Combofix logs look clean as far as I could tell.
     

    Attached Files:

  2. CloneT

    CloneT Private E-2

    Question for Chaslang

    Hello Chaslang;

    Firstly, I've learned a lot from your posts and troubleshooting. Thanks for all the work you've done!

    Now, to my question:

    You might remember thread http://forums.majorgeeks.com/showthread.php?t=146006&highlight=dio8.tmp, in which you asked someone to attach a suppossedly legit file to figure what it was.

    I've been chasing the pesky file all around the internet to find about it. There are relatively close matches, but nothing definite on DIO##.tmp or MAR#.tmp files.Although eaqsy to delete, lots of both regenerate into my temp dir at boottime.

    Did you ever figure out what they were used for?

    My PC is now otherwise clean (thanks to your posts and Shadow_Puter's).

    Thanks in advance.

    Clone
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The DIOxx.tmp and MARxx.tmp files are not problems. They are used for language translation in something you run (maybe even part of Windows).

    The below are potential problems and should be deleted:
    C:\Documents and Settings\Jim\Local Settings\Temp\UAC822c.tmp
    C:\Program Files\bad.dll

    The below are really not a major malware problems but frequently get installed without user's knowledge. If you did not knowingly install it, then uninstall it. It even installs with some free tools like Comodo Internet Security and ZoneAlarm unless you tell it not to.

    C:\Program Files\AskBarDis\bar\bin\askBar.dll
    C:\Program Files\AskBarDis\bar\bin\AskService.exe


    If you need malware help, you need to run 100% of the cleaning procedure. Just attaching a log from MGtools is not enough.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Question for Chaslang

    I merged this post with your other thread. Please remain in one thread in the future for a common subject.
     
  5. CloneT

    CloneT Private E-2

    Re: Question for Chaslang

    Thanks for taking the time to check and address BOTH threads, Chaslang. I did the whole malware removal shebang and beyond. I'm sort of computer proficient, and capable of interpreting my logs. My only gripe was with the said files, as I did not recogize them, but couldn't directly trace them as malware.

    Funny thing; Where in my logs did you find references to:

    C:\Program Files\bad.dll
    C:\Program Files\AskBarDis\bar\bin\askBar.dll
    C:\Program Files\AskBarDis\bar\bin\AskService.exe ?

    I did not see any of those reported, and just double checked to be sure.

    EDIT: I think you got my logs mixed up with someone elses' (Or maybe it was an offhand suggestion?).
    I just noticed you pulled a "jim" profile there. No Jims here :D

    Thanks again.


    Clone
     
    Last edited: Jun 8, 2009
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Question for Chaslang

    I was not looking at your logs. I was referring to the question you posted about them.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds