strange little buttons next to my desktop icons

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by xkeltfirex, Apr 6, 2007.

  1. xkeltfirex

    xkeltfirex Private E-2

    I recently dowloaded a trojan attached to another file.....Nortons caught it but said it couldnt delete it...I ran a scan and three files came up and were suposedly fixed by Nortons....however I now have these wierd little red circles with a white arrow next to most of my desktop Icons...what is this all about...is it related to the trojans I accidentally downloaded or just something to do with WinXP????????....like a startup indicator or something?
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and welcome to the forums


    Best option is to follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.

    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. xkeltfirex

    xkeltfirex Private E-2

    ok...done everything you suggested and still there.......all logs requested are attached here.
     

    Attached Files:

  4. xkeltfirex

    xkeltfirex Private E-2

    and here............................
     

    Attached Files:

  5. xkeltfirex

    xkeltfirex Private E-2

    also wanted to let you know that panda ran and didnt find anything and it wouldnt give me an option to view or save the log.....
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You attach a log from CounterSpy as requested! Right now your problems are not looking like malware.

    Is your copy of Spyware Doctor a paid or free trial version?

    You do need to do the following to get the proper Sun Java installed (this was requested in step 6 of the READ ME).

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 3
    Java 2 Runtime Environment, SE v1.4.2_03

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Also do you know what the two below files are that are wasting almost 3 GB of disk space:
    Code:
    "C:\"
    25a.tmp       Apr  7 2007  1409417728  "25A.tmp"
    3dd.tmp       Apr  7 2007  1409417728  "3DD.tmp"

    Now Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

    After clicking Fix, exit HJT.

    Now reboot and attach new logs from :
    • ShowNew (get the new version just released first)
    • HJT
    • also don't forget the CounterSpy log
     
  7. xkeltfirex

    xkeltfirex Private E-2

    1)Neither AVG nor Counter spy will allow me to update or view or save reports

    2)SpywareDoctor is free version.

    3)Installed Java SE Runtime environment 6 update 1

    4)I have no Idea what those two Files are.

    5)The first and third files were not present in this scan.

    6) See logs attached.
     

    Attached Files:

  8. xkeltfirex

    xkeltfirex Private E-2

    This is an addendum to the last post.....ok I tried some stuff on my own. I first did a Dell factory system restore (reboot system and hit Ctrl+f11. When the utility loads choose: reset to original factory configuration). This seemed to work as the little arrow things weren't there anymore. I then followed the instructions in step ten of the read this first thread (How to protect yourself from malware). I Downloaded & installed SpywareBlaster, PCTools AntiVirus, PCTools Firewall Plus, A-Squared(a2) and Mozilla Firefox 2.0. Seemed to work for a while but then the arrow things came back.

    Also.....Could you tell me how to take a snapshot of my desktop so you can see exactly what I'm talking about?...........would that help?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall CounterSpy now if still installed! Also uninstall the free version of Spyware Doctor you have installed? Also uninstall Viewpoint Media Player

    Do the above before continuing.

    You will now need to attach new logs from GetRunKey, ShowNew, and HJT. Make sure you download the new version of ShowNew that was just updated again before getting a new log.

    You can use FastStone Capture 5.3 - get it here http://www.faststone.org/

    If the image is too large to upload, you may need to scale it. You can do that with the below utility or you could just cut a smaller box out of your desktop with Fastone Capture

    FastStone Image Viewer
     
    Last edited: Apr 9, 2007
  10. xkeltfirex

    xkeltfirex Private E-2

    Ok...here we go.....did what you said....spyware doctor was eliminated when I did the reset! sorry. New Logs Attached....here
     

    Attached Files:

  11. xkeltfirex

    xkeltfirex Private E-2

    and Desktop Snapshot is ......here....... see the little square with the arrow icon in the lower left corner of most of the program icons.............those are what I'm having a problem with..................they look different than what I originally described because of the reset and I was using Style XP when I made the original post and I'm not now. I also just found a suspicious file in my C:\ file(see attached snapshots!) its the first file listed in the C:\ Directory. I could access the enu file before but now all of a sudden I cant..... said something about overriding user settings and stuff..... I knew I should have copied it the first time....:(
     

    Attached Files:

    Last edited: Apr 9, 2007
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Note that you did not redo step 2 of the READ ME which is evident from you GetRunKey log; however, I'm not sure you should bother. I fail to see any problems in what you are posting. The left most snapshot of your Desktop is normal. Arrows to the lower left side just indicate that the icon represents a shortcut to the program.

    Also I see no problems in the othe snapshots. Everything is normal!
     
  13. xkeltfirex

    xkeltfirex Private E-2

    Hmmmmmm.....well that will teach me to listen to so-called "experts"....lol.....thanks for all the help anyway.....when nortons found that Trojan and refused to Quarantine or delete it, I guess it scared me.....lol.........and like they say....better to be safe than sorry!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As long as everything is working properly, you are probably OK! If Norton popups up again, get more exact detail information and give it to us. A log would be good but some tools are terrible as far as providing detail logs or any logs at all.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds