PDA

View Full Version : What The Hell Is This?



balamm
05-17-2003, 06:32 PM
Duties are not performed for duty's sake, but because their neglect would make the man uncomfortable. A man performs but one duty - the duty of contenting his spirit, the duty of making himself agreeable to himself.
Mark Twain

Jibbler
05-17-2003, 06:40 PM
Originally posted by balamm@17 May 2003 - 14:32
This is what the top few lines look like after reformatting to RTF
More importantly, what is reformatting to RTF? Isn't this Rich Text File? What exactly are you trying to reformat?

balamm
05-17-2003, 06:46 PM
Duties are not performed for duty's sake, but because their neglect would make the man uncomfortable. A man performs but one duty - the duty of contenting his spirit, the duty of making himself agreeable to himself.
Mark Twain

thisiswhoweare
05-17-2003, 06:47 PM
I get this on my desktop sometimes after closing Outlook Express. Does your ~ file contain people's email addresses? further down?

I dont know why i get it, might be a bug :(

ToraBoraDweller
05-17-2003, 06:50 PM
Never seen such a file but entries near bottom seem to refer to your addressbook
or at least emailclient .
Could be just a dump but check out your addressbook for changed entries.

balamm
05-17-2003, 06:58 PM
Duties are not performed for duty's sake, but because their neglect would make the man uncomfortable. A man performs but one duty - the duty of contenting his spirit, the duty of making himself agreeable to himself.
Mark Twain

Twist3r
05-18-2003, 04:45 PM
i got one of thoughs files in my C drive just sitting there its wierd

MenderOne
05-18-2003, 08:23 PM
I also saw that it shows MSGR ID on the top part , it might be in MS messenger., also look for the file in dos.

ijc_2003
05-18-2003, 08:34 PM
k it seems to be when your outlook express aint configured, because i clicked on mine by accident and then canceled it and it put this file on desktop thats the 1st time i seen it.

Jibbler
05-18-2003, 09:05 PM
Originally posted by balamm@17 May 2003 - 14:46
RTF is the only thing it would open with to show anything but blocks so at least I can see a few of it's contents.
And you wonder why it looks all garbled. Its probably a data file used by some program. If it isn't a virus, then leave it alone. Stop searching for weird stuff on your computer, and start searching kazaa for weird stuff. :huh:

ugluk
05-18-2003, 09:17 PM
i may be wrong but dont the temp files for MS Word/MS Excel/MS whatever save their temp data in files that begin with ~? the program must have forgotten to delete the file after it was done.
that's what I think anyway! ;)

balamm
05-18-2003, 09:45 PM
Duties are not performed for duty's sake, but because their neglect would make the man uncomfortable. A man performs but one duty - the duty of contenting his spirit, the duty of making himself agreeable to himself.
Mark Twain

ShockAndAwe^i^
05-19-2003, 04:21 AM
Originally posted by ijc_2003@18 May 2003 - 21:34
k it seems to be when your outlook express aint configured, because i clicked on mine by accident and then canceled it and it put this file on desktop thats the 1st time i seen it.
Thats it.
I've seen this as well whenOutlook is'nt configured

balamm
06-05-2003, 07:24 AM
I just found a bunch more of these in my system, filled with peoples email addresses. All scans with AV and Anti-Trojan again come up clean.
The email addresses weren't just from my accounts and I don't keep address books or contact lists on the computer.
I did a full system search and found them in the symantec client AV folder and outside the OS files in one partition.
Nothings gotten out as far as mail but there were refferences to the SMTP( simple mail tranfer protocol) service which I have disabled.
I have to assume this is some part of a virus or trojan program which isn't being recognised yet by the AV makers or maybe something that hasn't been allowed to fully execute itself. Maybe bits that were left behind by an attempted virus entry.
I have had some cracks try to execute but they were caught by norton and wiped.

The thing that convinces me there's more to these files is that all email addresses were copied in different variations like first name last, last name first, slightly different spellings, etc.

ilw
06-05-2003, 09:24 AM
I know this isn&#39;t helpful, but balamm I was just wondering if u could modify your sig a little bit. On my work computer (runs crappy netscape 4 <_< ) for some reason your sig flashes quite insanely and its making me go cross eyed :blink: Does it have to be a gif? it doesn&#39;t seem to be animated or is that this browser being crap again? For some reason its only your pic that does.
Would be very much appreciated :P

balamm
06-05-2003, 10:14 AM
Ummm.... it&#39;s a static gif at the moment. The end of internet one?

Netscape 4? Aren&#39;t they up to 6 or something now?

ilw
06-05-2003, 10:22 AM
yeah tell me about it this browser sucks balls. But I&#39;m new at work so I&#39;m not too sure about handling upgrades and stuff. Its not important, I just thought i&#39;d ask cos it was annoying me a little bit.

balamm
06-05-2003, 10:46 AM
I&#39;d change it but the ISP isn&#39;t responding to front page at the moment. That may be part of why you&#39;re seeing flickers.

m8t
06-05-2003, 11:07 AM
:D
hi there &#33;
what the hell is this ?
one programme that lets you see a lot more than most is
Quick View Plus . there are many options to choose from.
regards
m8t :D

balamm
06-05-2003, 11:25 AM
Awesome&#33; thanks. I got that program off fosi and saved it to CD without ever checking it out cause I thought it was just an image viewer. I just tried it on a few .dat&#39;s and .exe&#39;s and it works great.
I&#39;ll be prepared next time I see one of the buggars, lol &#33;&#33;&#33;

ilw
06-05-2003, 11:38 AM
thanks for changing your sig
:)

I didn&#39;t really wanna ask u to change it completely (though I think the new ones funnier) I just thought u could maybe convert it from gif to jpeg or something? But thanks&#33;

balamm
06-05-2003, 12:20 PM
lol , I lost the whole works now. When I try to publish to my site I get a message from frontpage telling me the ISP server doesn&#39;t support frontpage&#33;&#33; Rather than piss around, i just deleted the whole account.

Cl1mh4224rd
06-05-2003, 07:34 PM
I&#39;ve gotten that same file before... Since you mentioned Symantec, I&#39;m wondering if it has something to do with Norton AntiVirus. NAV scans all your incoming and outgoing email, so I wonder if this is a temp file of sorts...

I seriously doubt it&#39;s a trojan or virus, as I&#39;ve had this going on for months and I don&#39;t think Symantec is that far behind the curve. ;)

balamm
06-05-2003, 09:18 PM
It&#39;s nothing to do with symantec scanning my email cause I have the corporate client installed and it doesn&#39;t touch outlook express untill you open a file (it only works with Outlook). It&#39;s not configured to do anything but deny access to infected files so there&#39;d be no reason for it to have all those addresses and variations of addresses in any temp or data file,unless that info is in an infected file which again points to virus or trojan activity. Still though, there would be some association or extension for the file if it was created by any program or system file I know of. My system has no info on it, it&#39;s origin, date of creation, properties, owner, etc. Very unusual given the system settings and security on the server. Nothing else can create or execute files without a whole mess of logs, rules, and properties being created in windows 2000 advanced server. I have scanned the entire system from Other NT systems and other AV programs and found nothing.