SL7.tmp found by Zone Alarm

F

Fruit2O

Zone Alarm is finding SL7.tmp and sometimes othe SL*.tmp files and is
asking for my approval to run. I can't fins=d, on Google, if this is
legitimate or part of some malware. Does anyone know what this is?
Thanks........
 
D

David H. Lipman

From: "Fruit2O" <[email protected]>

| Zone Alarm is finding SL7.tmp and sometimes othe SL*.tmp files and is
| asking for my approval to run. I can't fins=d, on Google, if this is
| legitimate or part of some malware. Does anyone know what this is?
| Thanks........

If a TMP is doing something to access the Internet, chances are good it is malware.


Please submit a sample of "SL7.tmp" ( or similare file) to Virus Total --
http://www.virustotal.com/flash/index_en.html
The submission will then be tested against many different AV vendor's scanners.
That will give you an idea what it is and who recognizes it. In addition, unless told
otherwise, Virus Total will provide the sample to all participating vendors.

You can also submit a suspect, one at a time, via the following email URL...
mailto:[email protected]?subject=SCAN

When you get the report, please post back the exact results.
 
F

Fruit2O

From: "Fruit2O" <[email protected]>

| Zone Alarm is finding SL7.tmp and sometimes othe SL*.tmp files and is
| asking for my approval to run. I can't fins=d, on Google, if this is
| legitimate or part of some malware. Does anyone know what this is?
| Thanks........

If a TMP is doing something to access the Internet, chances are good it is malware.


Please submit a sample of "SL7.tmp" ( or similare file) to Virus Total --
http://www.virustotal.com/flash/index_en.html
The submission will then be tested against many different AV vendor's scanners.
That will give you an idea what it is and who recognizes it. In addition, unless told
otherwise, Virus Total will provide the sample to all participating vendors.

You can also submit a suspect, one at a time, via the following email URL...
mailto:[email protected]?subject=SCAN

When you get the report, please post back the exact results.

Thank you - let's see what they find!!!!!!!!!
 
F

Fruit2O

From: "Fruit2O" <[email protected]>

| Zone Alarm is finding SL7.tmp and sometimes othe SL*.tmp files and is
| asking for my approval to run. I can't fins=d, on Google, if this is
| legitimate or part of some malware. Does anyone know what this is?
| Thanks........

If a TMP is doing something to access the Internet, chances are good it is malware.


Please submit a sample of "SL7.tmp" ( or similare file) to Virus Total --
http://www.virustotal.com/flash/index_en.html
The submission will then be tested against many different AV vendor's scanners.
That will give you an idea what it is and who recognizes it. In addition, unless told
otherwise, Virus Total will provide the sample to all participating vendors.

You can also submit a suspect, one at a time, via the following email URL...
mailto:[email protected]?subject=SCAN

When you get the report, please post back the exact results.

Well, I provided SL7.tmp and several variations which I found (and get
once in a while). None of the AV engines found a problem. Do you have
any suggestions on where I go from here? Thanks.........
 
D

David H. Lipman

From: "Fruit2O" <[email protected]>


|
| Well, I provided SL7.tmp and several variations which I found (and get
| once in a while). None of the AV engines found a problem. Do you have
| any suggestions on where I go from here? Thanks.........

You'd have to question what ZoneAlarm is indicating or use Ethereal and see what is
emanating from the PC.

You could also try the Sysinternals utility "Process Explorer" and see what is generating
the *.TMP files.
 
F

Fruit2O

From: "Fruit2O" <[email protected]>


|
| Well, I provided SL7.tmp and several variations which I found (and get
| once in a while). None of the AV engines found a problem. Do you have
| any suggestions on where I go from here? Thanks.........

You'd have to question what ZoneAlarm is indicating or use Ethereal and see what is
emanating from the PC.

Not familiar with Ethereal.
You could also try the Sysinternals utility "Process Explorer" and see what is generating
the *.TMP files.

I have Process Explorer - will try this and let you know.
 
F

Fruit2O

From: "Fruit2O" <[email protected]>


|
| Well, I provided SL7.tmp and several variations which I found (and get
| once in a while). None of the AV engines found a problem. Do you have
| any suggestions on where I go from here? Thanks.........

You'd have to question what ZoneAlarm is indicating or use Ethereal and see what is
emanating from the PC.

I'll Google Ethereal.
You could also try the Sysinternals utility "Process Explorer" and see what is generating
the *.TMP files.

To use Process Explorer, wouldn't I have to allow the SL*.tmp file to
run? This would concern me if it is malware.
 
F

Fruit2O

From: "Fruit2O" <[email protected]>


|
| Well, I provided SL7.tmp and several variations which I found (and get
| once in a while). None of the AV engines found a problem. Do you have
| any suggestions on where I go from here? Thanks.........

You'd have to question what ZoneAlarm is indicating or use Ethereal and see what is
emanating from the PC.
Installed Ethereal but am not familiar with it. How do I use it?
 
F

Fruit2O

Why don't you open it in notepad and see if there's any visible text?

Thanks - I didn't think of that. NOTE: I used ZA to kill all the
variations of SL*.tmp (except one which ZA says is a system file and it
cannot kill it (SLF8.tmp)). I suspect, though, that some sort of
malware is generating these files and the next time I see a ZA warning,
I'll use Notepad. The one that ZA can't kill is SLF8.tmp. I can only
find it as a prefetch file. I dragged it into Notepad but got no
readable text.
 
D

David H. Lipman

From: "Fruit2O" <[email protected]>


| Installed Ethereal but am not familiar with it. How do I use it?
|
Too complex to explain. It ais a packet decoder and breaks down Ethernet and TCP/IP packets
into the intgral parts.

No offense...
If you have to ask, Ethereal is NOT for you.
 
F

Fruit2O

From: "Fruit2O" <[email protected]>


| Installed Ethereal but am not familiar with it. How do I use it?
|

Too complex to explain. It ais a packet decoder and breaks down Ethernet and TCP/IP packets
into the intgral parts.

No offense...
If you have to ask, Ethereal is NOT for you.

David, something is generating these SL*.tmp files and I'm pretty sure
they are malicious. How can I find this out for sure? ZA is stopping
them from running (if I deny them) so, Process Explorer won't show them
(unless I DON'T deny them). I'm afraid allowing one of them to run
would be a mistake. ZA says SLF8.tmp is a system file and cannot kill
it - but I can only find this file as a prefetch. I was able to kill
all the other SL*.tmp files with ZA. Haven't noticed any adverse
effects with my system yet. Any other suggestions? Thanks.......
 
D

David H. Lipman

From: "Fruit2O" <[email protected]>


|
| David, something is generating these SL*.tmp files and I'm pretty sure
| they are malicious. How can I find this out for sure? ZA is stopping
| them from running (if I deny them) so, Process Explorer won't show them
| (unless I DON'T deny them). I'm afraid allowing one of them to run
| would be a mistake. ZA says SLF8.tmp is a system file and cannot kill
| it - but I can only find this file as a prefetch. I was able to kill
| all the other SL*.tmp files with ZA. Haven't noticed any adverse
| effects with my system yet. Any other suggestions? Thanks.......

Process Explorer is what will identify wehat is creating the TMP files.
 
K

kurt wismer

Fruit2O said:
David, something is generating these SL*.tmp files and I'm pretty sure
they are malicious. How can I find this out for sure? ZA is stopping
them from running (if I deny them) so, Process Explorer won't show them
(unless I DON'T deny them). I'm afraid allowing one of them to run
would be a mistake. ZA says SLF8.tmp is a system file and cannot kill
it - but I can only find this file as a prefetch. I was able to kill
all the other SL*.tmp files with ZA. Haven't noticed any adverse
effects with my system yet. Any other suggestions? Thanks.......

zone alarm may be stopping them from running, but is it stopping them
from being created?

process monitor (by the same folks who made process explorer) should be
able to help you figure out what process is *creating* the files (if
appropriate filters are used - otherwise there's just too much to wade
through)...

by the way, does zone alarm not tell you which process is calling these
files? sunbelt personal firewall (formerly kerio personal firewall) has
an application launch whitelist feature which i assume is similar to
what you're seeing with zone alarm, but it tells me not only what
application is trying to launch but also what process is
calling/launching it...
 
F

Fruit2O

zone alarm may be stopping them from running, but is it stopping them
from being created?

process monitor (by the same folks who made process explorer) should be
able to help you figure out what process is *creating* the files (if
appropriate filters are used - otherwise there's just too much to wade
through)...

by the way, does zone alarm not tell you which process is calling these
files? sunbelt personal firewall (formerly kerio personal firewall) has
an application launch whitelist feature which i assume is similar to
what you're seeing with zone alarm, but it tells me not only what
application is trying to launch but also what process is
calling/launching it...

Next time an SL*.tmp shows up (via ZA), what should I do to determine
what is launching it? I don't think ZA tells me what is launching it
(but I'll look again). I have process explorer. Should I launch IT
and will it show me the SL*.tmp even if I don't allow it to run with
ZA? What is different about Process Monitor? Where can I get it (I've
forgotten where I got Process Explorer)? Thanks............
 
F

Fruit2O

zone alarm may be stopping them from running, but is it stopping them
from being created?

process monitor (by the same folks who made process explorer) should be
able to help you figure out what process is *creating* the files (if
appropriate filters are used - otherwise there's just too much to wade
through)...

by the way, does zone alarm not tell you which process is calling these
files? sunbelt personal firewall (formerly kerio personal firewall) has
an application launch whitelist feature which i assume is similar to
what you're seeing with zone alarm, but it tells me not only what
application is trying to launch but also what process is
calling/launching it...



OK, I now have Process Monitor AND Process Explorer installed. What
would be appropriate filters for Process Monitor?
 
F

Fruit2O

zone alarm may be stopping them from running, but is it stopping them
from being created?

process monitor (by the same folks who made process explorer) should be
able to help you figure out what process is *creating* the files (if
appropriate filters are used - otherwise there's just too much to wade
through)...

by the way, does zone alarm not tell you which process is calling these
files? sunbelt personal firewall (formerly kerio personal firewall) has
an application launch whitelist feature which i assume is similar to
what you're seeing with zone alarm, but it tells me not only what
application is trying to launch but also what process is
calling/launching it...

OK, in the hope of finding the process that is trying to launch
SL*.tmp, I am going to leave Process Monitor and Process Explorer
running all the time. Please help me use these tools to find the
culprit - tell me what to do. Thank you.........
 
K

kurt wismer

Fruit2O said:
Next time an SL*.tmp shows up (via ZA), what should I do to determine
what is launching it? I don't think ZA tells me what is launching it
(but I'll look again). I have process explorer. Should I launch IT
and will it show me the SL*.tmp even if I don't allow it to run with
ZA? What is different about Process Monitor? Where can I get it (I've
forgotten where I got Process Explorer)? Thanks............

process monitor can be gotten from here
http://www.microsoft.com/technet/sysinternals/utilities/processmonitor.mspx

what it does is monitor file system and registry access in real-time
(basically telling you what processes are doing rather than about the
processes themselves as process explorer does)

what you'd actually have to do with process monitor is run it *before*
any attempt to launch an SL*.tmp file occurs so that you can find out
which process is trying to create the file... for the filter, i'd try
clearing out all the existing filters and then adding these two: 'path
ends with tmp include' and 'path excludes sl exclude'... that should
show everything to do with sl*.tmp files (and perhaps some other temp
files as well)...

in retrospect, filemon (again, same folks) might have been a better
suggestion since it seems to support wildcards - which would have made
for a more straight forward filter... kinda surprised process monitor
doesn't have conventional wildcard support since it's supposed to be a
melding of filemon and regmon, but oh well...
 
F

Fruit2O

process monitor can be gotten from here
http://www.microsoft.com/technet/sysinternals/utilities/processmonitor.mspx

what it does is monitor file system and registry access in real-time
(basically telling you what processes are doing rather than about the
processes themselves as process explorer does)

what you'd actually have to do with process monitor is run it *before*
any attempt to launch an SL*.tmp file occurs so that you can find out
which process is trying to create the file... for the filter, i'd try
clearing out all the existing filters and then adding these two: 'path
ends with tmp include' and 'path excludes sl exclude'... that should
show everything to do with sl*.tmp files (and perhaps some other temp
files as well)...

in retrospect, filemon (again, same folks) might have been a better
suggestion since it seems to support wildcards - which would have made
for a more straight forward filter... kinda surprised process monitor
doesn't have conventional wildcard support since it's supposed to be a
melding of filemon and regmon, but oh well...

Thanks again - I'll try these filters.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top