weird temporary int...
 
Notifications
Clear all

weird temporary internet files

5 Posts
4 Users
0 Reactions
547 Views
(@sierraindia)
Eminent Member
Joined: 20 years ago
Posts: 24
Topic starter  

Hi,
I've located what appears to be cached webpages in \documents and settings\username\local settings\temp\01808300\. The cached webpages have a numerical file name and a .tmp extension. I'm trying to figure out what software created these files. I'm guessing a browser of some sort. AOL Connectivity Services is installed…would this have anything to do with it? The os is XP SP2.
Thanks


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

Have you scanned the system for malware/spyware?

Is there any index.dat file associated with these files?

How were you able to determine that these .tmp files were web pages?


   
ReplyQuote
(@mmachor)
Trusted Member
Joined: 17 years ago
Posts: 70
 

I've seen this naming convention used by IE in the creation of its cached files. Could have come from there. Not sure about the location though.


   
ReplyQuote
(@minesh)
Trusted Member
Joined: 18 years ago
Posts: 75
 

Check files accessed in moments before the relevant file's accessed/creation times. That should help narrow things down.

I'm pretty sure i've seen similar which have been malware.

Kind Regards,

Minesh


   
ReplyQuote
(@sierraindia)
Eminent Member
Joined: 20 years ago
Posts: 24
Topic starter  

Thanks for the suggestions. I haven't performed a malware scan yet but judging by what I've seen so far I'm sure there will be many hits.

The files are filled with HTML and EnCase reports them having Yahoo Webmail signatures. The weird things is that each .tmp file appears to contain numerous cached webpages crammed inside them. I located several webmail messages which would normally be separate ShowLetter[n].htm's in the .tmp files.

Files accessed moments before the .tmp files are index.dat files, so I'm guessing the .tmp files are related to IE? I think IE can be configured to store temp internet files elsewhere but that still doesn't explain the cramming of several cached pages into individual files…


   
ReplyQuote
Share: