why is there a . before some file names?

Discussion in 'Software' started by abri, Aug 5, 2006.

  1. abri

    abri MajorGeek

    Chas thought I might need to be here with my question. I recently found a file directly under C:\Program Files called .autorun and in one of the logs thrown out by runkeys, I found an entry .owner
    Why is there a . before these names? When I first saw it I thought it was malware.
    abri
     
  2. Clark_Kent

    Clark_Kent MajorGeek

    Personnaly i nerver saw those kind of extension files but autorun.exe is when you insert a cd it will start right away when your put in your cd drive.....

    Did you check with google ???
     
  3. abri

    abri MajorGeek

    I don't know how to get Google to do a search that will take the . into consideration, otherwise I would have looked it up that way
    abri
     
  4. Toni_1947

    Toni_1947 Command Sergeant Major

    HI!
    Clark is right...those are NOT 'normal' file extensions.
    I searched several extensive libraries and did not find them listed.
    Have you tried looking at thier 'properties'?
    Reading them in Notepad?
    Maybe you could try renaming them...( .autorun to autorun.txt-.owner to owner.txt) and see what happens. Are they 'readable'?
    They are definately NOT system files and would probably not cause any problems if they got deleted, but I would try to 'read' them first.

    Here are 3 of the libraries I searched:

    http://www.file-ext.com/o.html

    http://whatis.techtarget.com/file-extension-list-A/0,289933,sid9,00.html

    http://www.fileinfo.net/

    Here is a place you can upload a 'suspicious' file to have it analyzed:

    http://virusscan.jotti.org/
    :rolleyes:
     
  5. abri

    abri MajorGeek

    Thanks!
    I deleted the .autorun with no apparent problems, but later pulled it back out of the trash so I could run ccleaner without losing it.
    I'm more reluctant to delete the file
    {972ce4c6-7308-4474-a285-3208198ce6fd}
    which I found under c:\Programme\Extensions
    because it looks like a registry entry. Since they came into the computer within a minute of each other, I expect they are related.
    I will try the jotti.org
    When I tried copying this registry-looking entry, I couldn't get it to paste into Google. Is that normal for registry entries? I thought you could paste anything into Google. Also, I had thought file extensions were what came at the end of the file, like .exe or .doc Is it also a file extension if it comes at the beginning of the file?
    abri
     
  6. InYearsToCome

    InYearsToCome MajorGeek

    a '.' before a file name indicates a Hidden file, at least in Unix. I'm fairly certain that that followed through to DOS (stripped down version of unix) and from there, into Windows.

    feel free to scan the files, but my guess is that you have 'view hidden files' and 'view protected operating system files' enabled. :)
     
  7. abri

    abri MajorGeek

    I tried to rename .autoreg to .autoreg.txt and when I did, it said (translated from German) "put a name in". Then I took the . out and changed it to autoreg.txt which turned out to be a .txt file with nothing in it. When I tried to put it back to .autoreg, I couldn't. I got the same error message "put a name in". It didn't seem able to read there was anything in there. So now it's missing. oh dear!
    both of the mysterious files have zero bytes, so I wondered why they would exist at all, however, maybe after reboot, I will know if something is not working anymore.
    abri
     
    Last edited: Aug 5, 2006
  8. abri

    abri MajorGeek

    I did one last thing. I ran a search for anything that was changed or put on the computer at the exact same time. I found 15 entries, all with the same date and time to the minute, all with 0 bytes. They are all under C:\Programme and all of them put in in the one minute have zero bytes. One is a folder called res which contains four subfolders dtd, entity Tables, fonts, html. The others are directly under C:\Programme and are called defaults, extensions, chrome, components, greprefs, plugins, uninstall, autoconfig, pref, and {972ce4c6-7308-... etc)

    Anything here ring any bells? Too weird. What are zero bytes good for?
    Thanks.
    abri
     
  9. Toni_1947

    Toni_1947 Command Sergeant Major

    Hi again,
    Looks like Firefox...???
    :confused:
     
  10. abri

    abri MajorGeek

    I think you're right with firefox. I hope I didn't kill anything when I took the . out of autoreg. Guess time will tell. lol
    thanks :)
    abri
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    abri ....abri ....abri .......give the entire path for the questionable files (and I use alltheweb, rather than google ....like the results much bettter) ...and if in doubt, run an online scan:
    Panda online active scan
    http://www.activescan.com
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds