Discussion in 'other anti-malware software' started by tbay2athome, Jul 17, 2008.

    I upgraded to the latest version of Firefox 3.0.1 today on a couple of machines. Since then every time I start Firefox, a few minutes later WinPatrol alerts me on a new hidden file which is always in C:\Documents and Settings\myname\Local Settings\Temp\etilqs (followed by random numbers and letters and changes with every restart of Firefox).
    I'm pretty sure it isn't malware but does anybody know what function this file performs?
    Running Symantec corporateV10 and GeSWall paid.
    I got a reply from Bill Pytlovany, developer of WinPatrol and he told me that by default the option to monitor hidden files is turned off because a lot of legitimate programs create hidden files. He also said the main reason for having this feature is to help clean up malware which does include partner programs which are hidden.
    I get the same thing. I saved one of the files and it was 0 KB in size. No indication what it is, but it started happening after the 3.01 update to Firefox.
    Yes but why are they created?
    That is a question for someone who is one heck of a lot more knowledgeable than am I.

    Just speculating......(a) it could be that the use of sqlite *requires* that a temp file be specified, even if it's not utilized, (b) a temp file is used to write changes to the table before they're (ultimately) written to the sqlite files that reside in the profiles directory.

    Regardless, the important point (considering where this inquiry was posted) is that the file is there by design and is not malware.
    I am glad that i wasnt only one :) I have trying to hunt this temp file down. Well now i can stop ;)
    Do you have Spiceworks installed ?

    etilqs sqlite logs

    "random numbers and letters" bolding mine

    From Bugzilla@Mozilla – Bug 385470

    Thousands of "etilqs_******" files created in the TEMP folder
    Nope, on none of four different PCs.
    Mozilla Article
    You never know everything no matter how knowledgeable you are, even Guru XYZ can´t know all spheres of knowledge in detail.

    Mainly created by firefox.

    It is easy to kill etilqs. Start Process Explorer > search handle > kill etilqs.

    By chance I caught a etilqs from memory but it is filled with kinda slackspace, visible invisibility.
