Computing.Net > Forums > Security and Virus > Suspicious file

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Suspicious file

Reply to Message Icon

Name: jlyon
Date: March 27, 2004 at 11:50:04 Pacific
OS: XP
CPU/Ram: 2.7ghz
Comment:

Hi,
I just set up a new computer for a relative. Everything was smooth. Next day when booting up they noticed a weird file on the desktop. It has the Windows flag icon and the ~ for the name. When I click properties it says, Type of file: File, Description: ~, and that's it. It's 178 kb in size. Any idea what it is? We ran Norton Antivirus on it and nothing, and McAfee Stinger came back with nothing as well...I opened it in notepad and here is a sample of what's in it:

ˍuX OyV     Є  D  Є @   Є @ !  Є @   Є +        F   3 2 8 5 4   3 2 8 5 5   3 2 8 5 6   3 2 8 5 7   3 2 8 1 2   3 2 8 1 3   3 2 8 1 4   3 2 8 0 2 2 <v
  3 2 7 6 9   3 2 7 7 0   3 2 7 7 1   3 2 7 7 2   3 2 7 7 3   3 2 7 7 4
  3 2 7 7 5   3 2 7 7 6   3 2 7 7 7
  3 2 7 7 8 ~+6   M s g r I D  T  R    l      S 
 V 
  u  &      !    $ $  @ 0 
  f  0@ 0 Gam N { E 3 8 B 6 0 C 8 - F 3 E 6 - 4 1 B F - A 1 6 5 - 7 E 8 B A B F 8 4 0 C 9 }   
N { E 3 8 B 6 0 C 8 - F 3 E 6 - 4 1 B F - A 1 6 5 - 7 E 8 B A B F 8 4 0 C 9 }    f              
  
              02 M a i n I d e n t i t y ' s C o n t a c t s     
4 4 =  @ 0 q: U: 0 0T:V: : : 0   !  Q G  @ 0 ~ q:   U:  0
S M T P  0" c a m 9 9 @ a o l . c o m T: 
S M T P V: & " c a m 9 9 @ a o l . c o m  : E d s  : B e v  0 B e v E d s        
4 4 5  @ 0 q: U: 0 0T:V: : : 0   !  Q G  @ 0 w q:   U:  0
S M T P  0 j @ j u n o . c o m T: 
S M T P V: $ j @ j u n o . c o m  :
L y  : J a m e s  0 J a m e s L y        
4 4 Y  @ 0 q: U: 0 0T:V: : : 0   !  Q G  @ 0 )> q:   U:  0
S M T P  0. c r e a t @ a d e l p h i a . n e t T: 
S M T P V: 2 . c r e a t e@ a d e l p h i a . n e t  : W a l k e r  :  0 W a l k e r        
4 4 I  @ 0 q: U: 0 0T:V: : : 0   !  Q G  @ 0 X q:   U:  0
S M T P  0* j s t u @ s o c a l . r r . c o m T: 
S M T P V: . * j s t u @ s o c a l . r r . c o m  : S t u a r t  : J e f  0 J e f S t u a r t        
4 4 I  @ 0 q: U: 0 0T:V: : : 0   !  Q G  @ 0 *n q:   U:  0
S M T P  0$ g g r o b i n s s @ m s n . c o m T: 
S M T P V: ( $ g g r o b@ m s n . c o m  : R o b i n  :
G r e g  0 G r e g R o b i n        
4 4 M  @ 0 q: U: 0 0T:V: : : 0   !  Q G  @ 0 悏 q:   U:  0
S M T P  0& K C B o e l @ a o l . c o m T: 
S M T P V: * & K C B o e l@ a o l . c o m  : B o e l  :
K . C .  0 K . C . B o e l s       
4 4 I  @ 0 q: U: 0 0T:V: : : 0   !  Q G  @ 0 % q:   U:  0


There is a lot more of this, with large blank gaps in between as well.
Any help on this...?



Sponsored Link
Ads by Google

Response Number 1
Name: edsod
Date: March 27, 2004 at 12:07:37 Pacific
Reply:

You can also have it scanned with the best scanner for trojans and viruses online:
http://www.kaspersky.com/remoteviruschk.html

or just delete it.


0

Response Number 2
Name: mesich
Date: March 27, 2004 at 12:20:16 Pacific
Reply:

Hi James, Edsod, hello everyone

It is caused from a cumulative patch for Outlook Express that was released in April 2003.

You notice in reading through the file, copied and pasted above, several people that are in their Outlook Express Address book are within the text.

Read more about it here.

Best Regards,
Mesich


0

Response Number 3
Name: jlyon
Date: March 27, 2004 at 12:53:16 Pacific
Reply:

Thanks Mesich!
That looks like the problem :-) I had tried searching the net for more info on this w/no luck....you had the magic keywords I suppose. Anywys, thanks for the help amigos!


0

Response Number 4
Name: mesich
Date: March 27, 2004 at 14:49:06 Pacific
Reply:

Hi James, Edsod, hello everyone

I had seen and heard of the problem many times in the past and knew what it was. I thought a link such as the one above might provide a bit more insight into the problem than my fading memory. :-)

You are so correct, a search on a couple of different engines is difficult for that problem. Google for example removes the ~ symbol within the search making the search worthless for what you are trying to find.

My issue was the correct spelling of the symbol, ~, referred to as a tilde. I think the whole brain is going and not just the memory. :-))

Glad to hear you now understand where it is coming from and the options you have.

Thanks for posting back with the results, you probably just helped out someone else in the near future.

Best Regards,
Mesich



0

Response Number 5
Name: Dog
Date: March 27, 2004 at 17:46:00 Pacific
Reply:

You may also find the tilde file in your root directory or elsewhere depending on where you have opened Outlook Express from i.e. the toolbar or Desktop or Internet Explorer.

It works for me

D4


0

Related Posts

See More



Response Number 6
Name: anbo
Date: March 29, 2004 at 02:54:15 Pacific
Reply:

Hi,

this is maybe a bit off-topic,
but I was looking answer for the same thing, but instead of trying to google "~" I copy-pasted "M a i n I d e n t i t y ' s C o n t a c t s" from the suspicious text file and used that as a search word and voil.

Anyway, thanks for the advice.


Anders Bhle


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Suspicious file

suspicious file www.computing.net/answers/security/suspicious-file/14334.html

Suspicious Files/ www.computing.net/answers/security/suspicious-files/10075.html

suspicious file outgoing OE6 mail?? www.computing.net/answers/security/suspicious-file-outgoing-oe6-mail/22003.html