Warning symbol on document icons

Discussion in 'Malware Help (A Specialist Will Reply)' started by KimJ, Oct 17, 2008.

  1. KimJ

    KimJ Private E-2

    Yesterday morning when I booted up my computer, I noticed a warning symbol (a red circle with a white exclamation mark) on all the document icons on my desktop. The symbol also appears on the icons of all document files when I view them in Windows Explorer - txt files, jpg, pdf, xls, psd, doc, ai all have the symbol. (The symbol does not appear on the new files I created yesterday while working through the readme.) There is also a file on my desktop I don't recognize - dxva_sig.txt. It was created 2 days ago. I don't know if that is related.

    I have AVG 8.0.173 and Spy Sweeper 5.8.1 (which I have just realized is not the latest version).

    I have gone through the readme and am attaching the requested logs.

    I had one problem in trying to do the initial step 1 cleanup. I cannot remove "Weather Services" using Add/Remove Programs. When I click the Change/Remove button, the window goes "inactive" for a minute or so, but nothing happens. The program is still there.

    I have also noticed a lot of activity from Spy Sweeper's Internet Communication shield saying it has blocked access to various sites. As far as I know, this just started since last night after I ran all these scans.

    First 3 files attached here, 4th to follow.
     

    Attached Files:

  2. KimJ

    KimJ Private E-2

    MGlogs.zip attached.

    Thanks so much for any assistance you can provide.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    There are no malware problems showing in your logs. I'm going to give you a few things to do further down.

    The dxva_sig.txt file may be related to DirectX Video Acceleration. You can just attach this text file to your next message and I will look at it, but it is unlikely to be anything important since it is only a 3 byte file.

    You do have to consider uninstalling either AVG8 or Spy Sweeper though. Grisoft states they have conflicts with Spy Sweper. See this: http://www.avg.com/faq.num-1214#faq_1214 However rather than saying Spy Sweeper needs to be installed, you should decide for yourself which one you want to keep.


    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run this Running GMER to detect rootkits and attach the GMER log.

    Now go here and download SysClean:
    http://www.trendmicro.com/download/dcs.asp

    You will need to download two additional files, one for viruses and the other for spyware. Instructions for which ones to download are found here:
    http://www.trendmicro.com/ftp/products/tsc/readme.txt
    After running SysClean, attach the log from it.
     
  4. KimJ

    KimJ Private E-2

    I don't know anything about video acceleration, but am attaching the file. Good to know it is probably harmless.

    I was unaware of the incompatibility. Since I have been unhappy with what a memory hog the latest version of AVG has been while scanning, I went ahead and installed Avast and removed AVG. I also updated Spy Sweeper while I was at it. My subscription is up in December. I will research in the mean time to see if this is still the best alternative for me.

    I did receive a success message with the fixme.reg.

    I am attaching the GMER and SysClean logs.

    I noticed that SysClean removed The Weather Channel Desktop. I have found this to be a handy application, and am wondering what the issue with it is. Should I not reinstall it?

    I still have the warning symbols peppering my document icons. Here is a partial screenshot in case that helps.
    http://i200.photobucket.com/albums/aa60/KimJensenDesigns/iconscreenshot1.jpg

    Thanks for your time. :)
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It looks like nothing to worry about.


    Both show no real problems.

    It is considered adware by some programs. You can reinstall it if you wish.

    I see nothing in your logs that indicates why this is occurring. Are you sure this is not related to some software you installed?
     
  6. KimJ

    KimJ Private E-2

    I had thought of that, but can't imagine what it might be. As far as I remember, the only thing I installed recently was Photoshop Elements, but the last couple of weeks have been such a blur that I could be forgetting something. Is it ok for me to experiment with uninstalling some things to see if it makes a difference? Would it mess anything up with the state things are in from the cleaning steps? If that doesn't work, maybe I can do a System Restore?

    If it turns out to be Elements causing all of this I'm going to be kicking myself. :p
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can uninstall anything you want. There are no malware reasons that I can see for your problems. In fact, let me give you all of my final cleaning instructions but I will leave out a couple steps since you may be trying to use a System Restore point. I also suggest that you not do any of the steps where installing any new software is involved.


    It is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. After doing the above, you should work thru the below link:
     
  8. KimJ

    KimJ Private E-2

    It's been a busy day, so I haven't quite worked my way through all the cleanup yet (still reading theough all the "protect yourself" info), but I wanted to let you know that I was able to determine that all the warning symbols were actually coming from Mozy. I've been using Mozy since January, and it quit working for me about 3 months ago, being unable to properly maintain the connection (some sort of known fault they are working on). I assume the warning symbols were flagging the files, showing that they hadn't been backed up, but even when it was working, it never put these symbols on anything before, so why it suddenly decided to out of the blue, I have no idea. This morning I was uninstalling things, rebooting in between programs, and when I got to that one, boom, the warning symbols disappeared. Just thought I'd let you know in case anyone else turns up with this same problem.

    Thanks so much for all your time!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for letting us know. Sooner or later someone else will have the problem. ;)

    And you're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds