Need Help! Weird Characters in Hard Drive Context Window! Do I Have a Virus?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Kr@zy1, Nov 30, 2008.

  1. Kr@zy1

    Kr@zy1 Private E-2

    Please Help. I'm having a problem with my computer. When I open 'My Computer' and right click on a hard drive, the context window that appears displays more that it should. In addition to the usual top three which include: 'open', 'search', and 'explore' there is a fourth mystery button that appears. It roughly resembles a '2Y.A' Do I have a virus? How do I remove it? How do I remove the symbols? I've scanned with Ad-Aware, McAfee Rootkit Detective, Spybot S&D, McAfee Stinger, Symantec, CCleaner, Super Anti-Spyware, Windows Defender, and Windows Malicious Software Removal Tool. All are up to date and all came up with nothing. I don't know what to do at this point. Any help would be extremely appreciated. Thank you very much for your time.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are already using precious web resources to work your problem at the below forum

    http://www.bleepingcomputer.com/forums/topic181674.html

    Please only post in one forum and work your problem thru to resolution there. If your problem cannot be resolved at that forum then it is okay have that thread closed and to try and seek help elsewhere.

    NOTE: But I do suggest that you look at the below registry key which may help you determine what this context menu item is:

    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shell
     
    Last edited: Dec 2, 2008
  3. Kr@zy1

    Kr@zy1 Private E-2

    I made the post on bleeping computer more than a week ago with no response. That's why I'm trying this support forum instead. Thank you for telling me where to look. No luck though, I couldn't find anything suspicious in that registry file. Is there anywhere else this bug could be hiding? I don't know what to do at this end short of reformatting my hard drive. I really don't want to do that. Any help would be extremely appreciated. Thank you very much.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This may not even be a malware problem. It still could just be a registry entry related to context menus somewhere that has been corrupted. However, just to make sure that we are not dealing with any malware, please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  5. Kr@zy1

    Kr@zy1 Private E-2

    Problem fixed. Thanks for the help.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome; however could you explain how you fixed it?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds