Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Funny .tmp file but Virus / Trojan not found 1

Status
Not open for further replies.

jamesvmoore

Technical User
Nov 12, 2002
3
0
0
US
This is a tough one! I have picked up something nasty and so far no anti-virus / anti-trojan I have tried detects it. I think that this hides in either the flash memory of the BIOS, or the flash memory of the Network Card - I don't think that an ATA controller could hide malicious code in its firmware.

Basic Info: AMD 750 Processor, AOPEN AK72 MotherBoard with latest BIOS, Promise ATA 100 PCI Controller, 3COM 3c905B-TX PCI NIC, SB16 PCI, Maxtor 45 GB HDD and new 256 SDRAM and later a known good but used 512 MB SDRAM, connected highspeed via cable/fiber optic running Windows 98SE with latest updates, ZoneAlarm and Norton AV.

Symptoms:
I first noticed that a .tmp file composed of mostly high (above 128) ASCII and control characters appears in my c:\windows\temp directory, it is referenced in the wininit.ini file its name starts with ~EF####.tmp (where # is any integer) - it is locked against deletion.

After a reboot or shutdown then a new file named ~DC####.tmp (where # is any integer) composed of mostly high (above 128) ASCII and control characters appears in my c:\windows\temp directory this file is mostly composed of a character that looks like a 'y' with 2 dots (umlot y?) over it and regular text that says R O O T E N T R Y. This file is also locked against deletion.

When restarted 2 instances of RUNDLL appear in the Task Manager - as seen via CTRL-ALT-DEL, they can be clicked on but END TASK will only cause them to restart. This does not occur if started in safe mode.

Things I have tried:
I have done a fdisk / mbr, fdisk, format and re-install of Win98se, the install will complete after scandisk supposedly fixes the drive mis-reporting its size. The same symptoms reappear shortly after installing all of the correct motherboard and device drivers.

I used the hard disk manufacturer's tools to low-level format the entire drive (write completely to zeros). Re-installing Win98se, the symptoms are back. After another lowlevel format using Symantec GDISK to write the whole drive to zeros I have tried to install Windows 2000 Professional from CD, if I attempt to format NTFS that will fail, if I use a pre-existing FAT32 partition the install only makes it to the first real Windows 2000 screen that detects hardware, this will go 70% and then the entire screen will turn black with backwards white commas.

After letting the CMOS BIOS go cold, no power - no battery, then flashing the BIOS to 1.00 and back again to 1.11 I re-attempted installing using a completely new hard disk in the same PC with the same results, Windows 2000 asks for the Promise ATA Card driver if I connect the drive to that and can't format the disk or fails at the detect hardware if the hard disk is already formatted. Using the built in IDE controller gets the same results sans the need to F6 to specify the ATA card. Windows 98 SE can install but displays the scandisk fix. Both Windows install CDs work fine on other computers.

I have tried this on the original hard disk, a clean hard disk only used for data storage, and a new hard disk direct from the manufacturer. After this happens to a hard disk, it is not cleanable via floppy disk virus scan - nothing is ever detected and it will always mis-report its size to Win98 but will allow install if 'fixed', will not allow Win2000 to format NTFS or finish installing.

I put a second clean PC on my network, behind a hardware firewall, also running Norton AV and ZoneAlarm and it developed the exact same symptoms within a week, I have been very good about not swapping diskettes or burned CD's back and forth between these PC's, so I can rule our .

Once infected I am pretty sure that this somehow hides from the file system on the hard disk or changes the drive geometry.

Whatever this is, it can survive a zero-fill format of the hard disk, and even re-appears after the installation of a new hard disk on the same machine. I am almost certain that it was delivered through my Internet connection because it appeared on a clean PC plugged into the firewall. Curiously, on the new hard disk install, I had not even plugged the network cable into the PC and still developed the mysterious .tmp files.

Sorry for the lenght of this posting and I would appreciate any advice or assistance that can be offered.
 
Have you considered that this suspected file is actually being generated by the OS as a temp file? I'm pretty sure at least one AV vendor would have known about it if it were an actual worm/trojan/virus.

Might also be a bad HD. AVChap
... take my advice, I don't use it anyway!
 
Thank you for such a quick response. Yes, it is possible that these .tmp files are generated by either the OS or by a program / driver. These files may be simply coincidental to my other issues. The largest issue being that I am unable install Windows 2000 at all or Windows 98SE cleanly - BTW LINUX will install but shows the drive as much smaller than its actual formatted size. Tools like Norton DISKEDIT or Maxtor's utilities show the drive's size / geometry incorrectly and differently depending on which one is used. The other issue I have is that Maxtor's tools can't test the whole LBA and won't format the entire LBA ... I am on my second new Maxtor Drive, I have tried an older Quantum drive also.

Thanks for any help.
 
Hi,
I know this is an old issue, but have you ever resolved it?
I am experiencing a problem where my 20G Maxtor HD 92040U6 is sized at 7.8G by W2K. W98SE has no problem with it on the same machine.
I have been talking to Microsoft about this and the case is still in process. So far we believe there is a geometry interpretation fault somewhere but we are not sure where and what to do about it.
Ovi
 
Yeah, good to know how its going. Sounds like a dodgey disk - maybe? If not, drop to DOS (ahh, old fashioned DOS - can't beat it!) and try a unconditional format (/u). Boot up and reload.

If the problems are still there, and you can't see any specific vendor/manufacturer in these .tmp files then post it on the Win98 Forum. See if anyone else has these problems.

Good Luck

Steve Hewitt
 
Its been a long time, my final resolution was to call Maxtor tech support and get an RMA, they mailed me a new hard drive ... everything installed and works fine on it - even a 100% NTFS Win2K partition.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top