1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Cookies, History and TIFs moved ......

Discussion in 'Internet Explorer & Microsoft Edge' started by Christer, 2003/09/24.

Thread Status:
Not open for further replies.
  1. 2003/09/24
    Christer

    Christer Geek Member Staff Thread Starter

    Joined:
    2002/12/17
    Messages:
    6,585
    Likes Received:
    74
    Hello all!

    Suddenly there was some disc activity when the computer was idling. I thought nothing of it but when I continued using it I noticed this:

    I had to log in to all sites where I usually stay logged in. This has happened before on one site at a time but not all sites at the same time.

    The history had been cleared. On certain boards a thread that has been read changes colour but now all had the unread colour.

    I opened Windows Explorer to check the folders in my account and found out that things had happened:

    C:\Documents and Settings\My Name\Local Settings\Temp all of a sudden had Cookies, History and TIF subfolders.

    The "original" folders were still there but with a contents that doesn´t seem normal.

    In Internet Explorer > Tools > Internet Options > TIF-settings the location of the TIF folder and its maximum size had been altered and I think it is possible/probable that the Cookies and History also have been redirected.



    Has anyone else had the same experience?



    The only "new" site I visited was *www*.*stupidvideos*.*com* and it is possible that there is a connection. (remove the *s if You want to go there ...... :D ......)

    I have scanned for malware using DO YOU HAVE PARASITES? but it found nothing.

    I have yet to install spybot and ad-aware and run them.

    Thanks for Your time,
    Christer
     
  2. 2003/09/24
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
    Christer--Certainly could be a virus or spyware. Look forward to your hearing the results of your scans with Antivirus and a Spyware Detector. Presume you know where to find.
     

  3. to hide this advert.

  4. 2003/09/24
    Christer

    Christer Geek Member Staff Thread Starter

    Joined:
    2002/12/17
    Messages:
    6,585
    Likes Received:
    74
    So far I´ve done this:

    Restart #1

    In Internet Explorer > Tools > Internet Options > TIF-settings were back to normal.

    The TIF folder had been cleared but was back to normal.

    I once again had to log in to all sites which means that all cookies had been cleared.

    History was back to normal with contents as prior to the event.

    C:\Documents and Settings\My Name\Local Settings\Temp could be cleared of its contents except one file in use (no connection to this issue).

    Restart #2

    Everything back to normal except this:

    A history folder with a subfolder being created in C:\Documents and Settings\Christer Engdahl\Lokala inställningar\Temp\Tidigare\History.IE5\MSHist012003092520030926

    There is a reference to this path in the registry but it´s the "short" version, e.g. Docume~1 instead of Documents and Settings:

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012003092520030926

    and

    HKEY_USERS\S-1-5-21-1757981266-1078145449-1343024091-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012003092520030926

    There are six similar subfolders in "Extensible Cache" but they all have the %USERPROFILE% type of path.

    That history folder is similar to the one in C:\WINDOWS\system32\config\systemprofile\Lokala inställningar\Tidigare\History.IE5\MSHist012003060420030605.

    There is a reference to this path in the registry:

    HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012003060420030605

    and

    HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012003060420030605

    This is the only subfolder in "Extensible Cache" and it has the %USERPROFILE% type of path.

    I believe that something edited the registry which makes that folder appear and if deleted to be recreated in C:\Documents and Settings\Christer Engdahl\Lokala inställningar\Temp.

    Now it´s 3 o´clock in the morning and I´ve got to get some sleep.

    Christer
     
  5. 2003/09/25
    brett

    brett Inactive Alumni

    Joined:
    2002/01/11
    Messages:
    2,058
    Likes Received:
    0
    Meaning?
     
  6. 2003/09/25
    Christer

    Christer Geek Member Staff Thread Starter

    Joined:
    2002/12/17
    Messages:
    6,585
    Likes Received:
    74
    The Cookies, History and TIF folders that are supposed to be there had not been removed. They had been copied (?) to the temp folder and the contents tossed around between the repective folders.

    E.g. the TIF folder that is supposed to be there, its properties said 2 folders and 50 files but it actually contained hundreds or thousands of files.

    Christer
     
  7. 2003/09/25
    Christer

    Christer Geek Member Staff Thread Starter

    Joined:
    2002/12/17
    Messages:
    6,585
    Likes Received:
    74
    I have taken these actions:

    Norton Anti Virus scan = clean

    Trend Micro HouseCall = clean

    SpyBot (easy mode) found 7 red problems, 1 Alexa related *.htm, 4 DSO Exploit registry changes and 2 Windows Media Player registry changes.
    All problems fixed and rescan = clean.

    Ad-aware found 2 problems, 1 Alexa regkey and one tracking cookie (bravenet).
    All problems fixed and rescan = clean.



    It seems to me like *www*.*stupidvideos*.*com* isn´t the culprit.

    The only application on my system, that I know of, which use the "short" version of folder and file names is Norton Ghost.
    In TaskManager an instance "GHOSTS~2.EXE" is running.

    From "Answers that work - Task list programs ":

    I will find out what this is about.

    Christer
     
  8. 2003/09/25
    brett

    brett Inactive Alumni

    Joined:
    2002/01/11
    Messages:
    2,058
    Likes Received:
    0
    Peculiar. AFAIK, there is no malware which causes that type of behaviour. I take it that you haven’t been experimenting with any cache purging utilities? Or custom XML files for IE?
     
  9. 2003/09/25
    Christer

    Christer Geek Member Staff Thread Starter

    Joined:
    2002/12/17
    Messages:
    6,585
    Likes Received:
    74
    Nope, the only purging utility I have is Norton File Protection which is set to protect deleted files that didn´t go to the recycle Bin.
    After 7 days they are automatically purged but if I wish I can do it manually. I did that a month ago when I created my latest Ghost Image.

    I don´t even know what it is ...... :( ......



    Two days ago we had a power failure which lasted for 5 hours. It was a "clean" power cut and the computer started without problem when the power came back.
    I don´t think there´s a connection since this issue appeared 36 hours later.

    Christer
     
  10. 2003/09/25
    brett

    brett Inactive Alumni

    Joined:
    2002/01/11
    Messages:
    2,058
    Likes Received:
    0
    I think I’d be inclined to chalk it down as a peculiar hiccough and, unless the behaviour is repeated, forget about it.

    BTW - Custom XML.
     
  11. 2003/09/25
    Christer

    Christer Geek Member Staff Thread Starter

    Joined:
    2002/12/17
    Messages:
    6,585
    Likes Received:
    74
    brett,
    thanks for the link "Custom XML "!

    I have come to the same conclusion and will report back if it happens again.

    I have removed the two regkeys with the abnormal path and the offending folder is no longer recreated in the temp folder.

    However, can I be sure that no other registry key(s) have been added/altered?

    I will wait a week or so to see if it reoccurs but then I will restore my system with my latest Ghost Image.

    I have sent a question to Symantec Support regarding the GhostStartService.exe and it normally takes a day to get a reply.

    Christer
     
  12. 2003/09/25
    brett

    brett Inactive Alumni

    Joined:
    2002/01/11
    Messages:
    2,058
    Likes Received:
    0
    Just as an aside - this is quite a handy little gadget (which is free and uses zero resources).
     
  13. 2003/09/25
    Christer

    Christer Geek Member Staff Thread Starter

    Joined:
    2002/12/17
    Messages:
    6,585
    Likes Received:
    74
    Thanks brett!

    I believe that I would be up to my chin in trouble using that application ...... :confused: ...... I would have to learn much more to know what to allow and what not to.

    Some other useful applications too, on that site.

    Christer
     
    Last edited: 2003/09/25
  14. 2003/09/25
    brett

    brett Inactive Alumni

    Joined:
    2002/01/11
    Messages:
    2,058
    Likes Received:
    0
    The program couldn’t be easier to use. It simply alerts you if a program attempts to write to certain areas of the registry - namely, those which malware typically uses in order to autostart - and allows you to deny the action of you wish. If you’re installing some new software then you’d expect to see it write to those areas; however, if you’re viewing (a supposed) JPEG file then you wouldn’t expect to see that action!
     
  15. 2003/09/25
    Christer

    Christer Geek Member Staff Thread Starter

    Joined:
    2002/12/17
    Messages:
    6,585
    Likes Received:
    74
    Thanks for the informative confidence booster ...... :D ......
    I think that I´ll try it ...... :cool: ......

    Christer
     
    Last edited: 2003/09/25
  16. 2003/09/25
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Hi


    a Google search for " Lokala inställningar" brings up lots.
    did the page you visited contain flash or a macromedia movie
    Perhaps not alowing it to complete goofed up the cache.
    =====
    I only have win ME
    the other day I noticed tif/content.ie5/had four random folders as usual== but along side temopary internet files was another four random folders, I corrected this by moving the folder then moving it back to the windows dirrectory.
    Later ,several days, for some odd reason I had eight random folders within the content.ie5 folder.


    The only reason Im commenting is to say windows IE cache is buggy and to ask brett about the reg monitor
    I cant see any info about compatability there
    any ideas ?

    Lonny
     
  17. 2003/09/26
    brett

    brett Inactive Alumni

    Joined:
    2002/01/11
    Messages:
    2,058
    Likes Received:
    0
    Lonny - RegProt will run fine under ME.
     
  18. 2003/09/26
    Christer

    Christer Geek Member Staff Thread Starter

    Joined:
    2002/12/17
    Messages:
    6,585
    Likes Received:
    74
    Lonny,

    You probably hit the nail on the head. I´m not sure about flash or macromedia but there were a lot of stupidvideos that were too stupid to watch. I interrupted quite a few of them.

    Your comment made me remember a thread about unfinished streaming media which went to a super hidden part of the TIF folder. I even took part in that discussion, see Temporary Internet Files

    Wow, is my memory short or what ...... :rolleyes: ...... but I didn´t realize that the cash could be completely messed up!

    Thanks,
    Christer
     
  19. 2003/09/26
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    " "Wow, is my memory short or what" "
    Thats the way feel quite often :)
    Take a look at this tool it may interest you,, best one ive found,
    It was suggest By freeatlast, recongnize the name, He helps alot at forums.spywareinfo
    System Security Suite : http://www.igorshpak.net/


    Charles di you originaly have win me ,, and upgrade to XP or is this another PC (i forget)
    Thanks for the conformation Brett

    Lonny
     
  20. 2003/09/26
    Christer

    Christer Geek Member Staff Thread Starter

    Joined:
    2002/12/17
    Messages:
    6,585
    Likes Received:
    74
    In an earlier post I told that I was going to find out what GhostStartService, a Service running in the background on Windows XP, is about.
    I asked Symantec Support and for any interested user of Norton Ghost 2003, this is their answer:

    Regards,
    Christer
     
    Last edited: 2003/09/26
  21. 2003/09/26
    Welshjim

    Welshjim Inactive

    Joined:
    2002/01/07
    Messages:
    5,643
    Likes Received:
    0
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.