puter question (DOS)

mellowyellow

Vice Admiral
Joined
Jun 8, 2002
Messages
5,327
for awhile now, I have been getting a new msdos<br />icon on my puter as a shortcut called "~" only.<br />over 5K? appears to be coming from inside, but<br />other than looking at properties I have been too<br />paranoid to actually open the file for fear of<br />virus...<br />any fellow propeller heads recognize this file?
 

mellowyellow

Vice Admiral
Joined
Jun 8, 2002
Messages
5,327
Re: puter question (DOS)

have deleted several times EF, then immediately<br />emptied recycle bin, but it keeps comin' back?<br />like a bad nickel ;)
 

gsbodine

Petty Officer 1st Class
Joined
May 4, 2004
Messages
346
Re: puter question (DOS)

have you updated your virus software and run it? did you install any new software right before it happened that could cause it? i think windows temp files start with a tilde. could just be something using the wrong directory for temp files or something. is it just on your desktop or what? what os version are you using?
 

mellowyellow

Vice Admiral
Joined
Jun 8, 2002
Messages
5,327
Re: puter question (DOS)

this 5K file has been deleted several times.<br />appears on desktop upon re-start sometimes,<br />but has been detected in many other start up<br />postions over last several mo.<br />am tempted after dur dilligence to actually open<br />it and examine.... but not till I know what she<br />is.
 

gsbodine

Petty Officer 1st Class
Joined
May 4, 2004
Messages
346
Re: puter question (DOS)

if you update and scan for viruses first, it likely won't do anything. you do have an antivirus program don't you?
 

Ralphy

Petty Officer 1st Class
Joined
May 7, 2004
Messages
280
Re: puter question (DOS)

I got the same thing Mellow. I have clicked on it and it does nothing. I delete it and sometimes it stays away for weeks, then out of the blue, it shows back up. I am sure it from some adware, as when i run my Ad-aware, it finds it and deletes it, but there is a hidden file somewhere because in time, it returns again
 

Dunaruna

Admiral
Joined
May 2, 2003
Messages
6,027
Re: puter question (DOS)

My, its likely not a virus. Probably one of those programs that load secretly while your are logged on. When you delete, you are only deleting the icon, not the hidden program. Its in your start up registry so it will recreate the icon every time you startup the computer.<br /><br />1. SpyBot S&D should find it and completely remove it.<br /><br /> SpyBot S&D v1.3 <br /><br />2. You can check to see what is automatically loading when you bootup: Open windows/system/msconfig.exe<br /><br />View the startup menu, don't change anything unless you feel confident. When I first did this I found 25 programs that I never used or even heard of before. I then used nortons wipeclean to delete them (it also cleans the part of the registry that is off limits to non nerds like me) and now my computer boots much quicker. Please don't change anything without being absolutly sure, I don't want to be responsible for creating problems.<br /><br />Hope this helps.<br /><br />Aldo
 

Dunaruna

Admiral
Joined
May 2, 2003
Messages
6,027
Re: puter question (DOS)

Sorry, the link didn't work (I stuffed up) Its fixed now.<br /><br />Aldo
 

mellowyellow

Vice Admiral
Joined
Jun 8, 2002
Messages
5,327
Re: puter question (DOS)

adaware, spybot, EZ anti virus, EZ firewall all<br />run and current. none remove it at all or even<br />recognise it. nothing in start up menu...
 

Dunaruna

Admiral
Joined
May 2, 2003
Messages
6,027
Re: puter question (DOS)

MY, I can hear your frustration, I don't want to add to it - just trying to help.<br /><br />Version 1.3 will fing more nasties than version 1.2. (about 1000 more) Are you running 1.3?<br /><br />Aldo
 

SlowlySinking

Master Chief Petty Officer
Joined
Oct 31, 2002
Messages
897
Re: puter question (DOS)

try this, point your mouse at the icon, right click, click on PROPERTIES, this will tell you where the file is located, click the tabs on the top and see what you have, the info might help you, let us know what you find, good luck
 

ebbtide176

Commander
Joined
Jan 22, 2002
Messages
2,289
Re: puter question (DOS)

ok mellow, here is my 2c, which would amt to @ .000002 in AV skills, but it gets me thru hardtimes when the beaurocracy of getting our corp IT team involved isn't worth the hassle...<br /><br />i recently picked up the blackmalB and sasser worms, and cleaned up shop within 4 days, partime, as one of my 'test' pc's is not under the heavy blanket imposed by corp IT.<br /><br />i would explore that file, change its tag to .txt<br />if that gives 'in use' err then u got a good idea its something sinister ;) and even not, if its reinitializg itself, then same suspicion.<br />once i did that, i'd open it with notepad. if its junk, maybe it'll give a few legible paths, like www.werule.schitheds.com, etc<br />THEN use these legible words as wildcards to search the c: along with the actual filename. <br /><br />i guess my slow columbo work aint rocket science but you will eventually get there, and after a few times, remember the basic files used by regedit, startup, core oslevel kernal, etc<br /><br />i would change all .exe you find to .2exe,but that's just my way. oh yeah, if you get the 'in use', then its time to reboot to safe mode, then rename. i guess i basically searched all variables found, then their variables(filenames,paths) and pretty quickly shut it down.<br /><br />not to mention <end task> to see whats running in the bkgrnd, and then ZoneAlarm to reject all the crap (one at a time)until i could verify where it was coming from. which, in my case, several come from the timesync prog since we work online realtime support callcenters.<br /><br />then, once i figured out the areas of my opsys that were affected, and how, i had an idea of what to search for in online AV sites. <br /><br />i learned/figured out that:<br /> viruses are quick to mutate<br /> viruses cheifly combine the best features of other common viruses <br /> this is called a 'blended threat'<br /> they could be really nasty and del files, but most of the time just duplicate oslevel files, and setup bkgrnd proc - spam machines<br /><br />that is what i caught-- making spam mch on my pc. and it would replace my last used exec progs to be robots or whatever the hell you wanna callem. i would have perfectly legit progs like mediaplayer, ipconfig, clocksync - all going out on the internet connecting to ftp sites with automatic scripts, pulling crap back to me!<br /><br />the <end task> routine helped spot alot, the searches/ file properties helped spot alot, and finally the Zone Alarm/firewall kept it from running. THEN i had wildcards to search for on AV sites. i got most help from MS.com believe it or not. i got symptoms to match mine, and downloadable fixes. and i found that the core opsys .exe files were still intact, and the ones actually running were duplicates, but in diff directories- if you understand what i mean. its just the $path allowed it to use the 1st occurrance of the specified $variables... i wont expl in detail, but hope you understand, and/or research it rather than have me offer fodder to the other zillion 12yrold dumazzes that want to incr their ego by writing a virus... :D <br /><br />but i didn't dwnload, i did it manually. i don't want more .exe files that are unfamiliar and unkn to me 6mos from now... i then had the printouts with step by step filenames to look for in regedit. and regedit is what prevents it from reocurring, like you are seeing.<br /><br />once i got familiar with the fields within regedit, it helps tremendously in understanding how exec files can 'popup' on your desktop, or after running your IE browser to access iboats.com<br /><br />hope this might point you in the right direction, or at least help entertain ;)
 

mellowyellow

Vice Admiral
Joined
Jun 8, 2002
Messages
5,327
Re: puter question (DOS)

thanks all! the icon appeared as an explorer page.<br />properties just said it was a dos file and the size.<br />did a simple find files search under "~" and found<br />8 files in different areas from program file to<br />my briefcase. went ahead and deleted them, so I<br />think the file is gone for good. sure hope it<br />wasn't something I needed :rolleyes: <br /><br />PS. the key to finding them was to add the parenthesis<br />as without them a zillion files came up under ~
 
Top