Hi, i have downloaded some images (what i thought were images) and when i tried to open them it says preview unavailable. So i tried to delete it and it doesn't give that option, heck i can't even move it. Any ideas??
That could also mean that there is no valid file association for the FILE TYPE that you downloaded (such as filename.DOC or filename.JPG).Hi, i have downloaded some images (what i thought were images) and when i tried to open them it says preview unavailable.
How to change file associations in Windows XP
http://support.microsoft.com/kb/307859
If you still have concerns about malware post the URL of the site where you downloaded the files (and their file extension/type) and produce a HiJackThis LOG as per the READ FIRST Procedures found here:
http://www.d-a-l.com/help/showthread.php?t=32403
I followed all procedures before posting and these files do say that they are a .jpeg image and it won't give me the options to change it.. i am not to good with computers so maybe i am missing something?
Investigate whether the file extention is .JPG (right-click on a given file) and how that file type is associated with a particular application that would open such a file (report that). The 'file association' link that I gave will show you how to do that and to change to another file association, if necessary (such as PAINT or other graphics viewer).these files do say that they are a .jpeg image
I have tried to open with every program in my list, the only one that says anything that might be useful was when i tried to open it with quicktime viewer, it said cannot find a suitable graphics importer?? I cannot make any other changes to the picture itself, the delete function does not even come up when i right click on it.
Are these indeed viewable document or pretending to be viewable content? Are you currently experiencing any issues with your PC?
You did not report back that the files in question are .JPG or other seemingly compatible viewable image documents. Please specifiy the website (and URL links) where each specific document was acquired. If you right-click on each document, what information can you determine by clicking on 'Properties'.
Sorry, yes they are .jpg When i put the cursor over the thumbnail it says.. Type JPEG IMAGE SIZE 89.6 kb, all images were acquired from LimeWire. When i right click on the thumnail it only gives me these options
Preview
Edit
preview
Rotate clockwise
Rotate Counterclockwise
Set as desktop background
Open with
Send to
It doesn't have the properties on it like any of the other real images nor does it have the copy paste or delete option.
Limewire downloads can often lead a lot of people into this kind of trouble - probably a Trojan(s).
Proceed with the instructions that I gave to produce a HijackThis (HJT) log - run the other two (2) scans, as well, if you haven't been using anti-malware scanning tools. If you haven't already done so please run the following scan before you post a HJT LOG:
We will be restarting into Safe Mode later on in the fix and you might not be able to access the Internet. Accordingly, it is probably a good idea to print out the following directions or copy them to a text file on your desktop using NOTEPAD. Read these instructions carefully and feel free to ask if you're unsure about anything.
Download and install AVG Anti-Spyware 7.5 (AVG AS - formally known as Ewido anti-spyware 4.0 - uninstall any previous version first).
- Click the Download BUTTON. On the next page click the Download now BUTTON.
- Save and then install (Run) from the save location.
- Open/Run AVG Anti-Spyware
- Wait a few moments and AVG Anti-Spyware should Auto update itself (note date of last update). If it doesn't update, click the update ICON at top of screen:
- Click on the Update now LINK at the top of the window
- Click on the Start update button
- Wait for the update to download and install
- This is very important to get the LATEST updates.
- Click on the Status ICON
- Under "Your computers Security"
Click change status on Resident shield to inactive (ONLY consider activation of that feature once you are clean)- Click on the Scanner ICON at the top of the window
- Click on the Settings tab then select Recommended Actions and choose Quarantine
- When updating has finished. Close AVG Anti-Spyware.
We will be using this tool in a later step.
Reboot your computer in Safe Mode.______________________________
- If the computer is running, shut down Windows, and then turn off the power.
- Wait 30 seconds, and then turn the computer on.
- Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
- Ensure that the Safe Mode option is selected.
- Press Enter. The computer then begins to start in Safe mode.
- Login on your usual account.
Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware , and run a full scan:
- Click on the default Status ICON and select the Scan now LINK.
OR
- Click on the Scanner ICON . Select the Scan TAB.
- Select Complete System Scan. AVG Anti-Spyware will now begin to scan your system.
- If AVG Anti-Spyware finds anything it will list them in the Preview WINDOW:
- Make sure that Set all elements to: shows Quarantine, if not click on the link and choose Quarantine from the popup menu.
- Select Apply all actions at the bottom of the window (and the items found will be quarantined – and recoverable, if any items are needed back).
- When the scan has completed, click on the Save Scan Report button and save the scan to your Desktop where it can be easily found.
- Copy and paste the AVG Anti-Spyware scan results into your next post.
- Close AVG Anti-Spyware.
Post your latest HijackThis log and let us know how your PC is now behaving.
Last edited by VopThis; 06-11-2006 at 03:38 AM.
Computer is still running fine, still can't get rid of thumbnails. here is the scan report
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 1:26:04 AM 11/6/2006
+ Scan result:
C:\System Volume Information\_restore{971CC777-75E4-4CBA-9CBC-151CFCBD3A49}\RP426\A0060404.DLL -> Adware.FunWeb : Cleaned with backup (quarantined).
HKU\S-1-5-21-329068152-1580818891-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext \Settings\{4E7BD74F-2B8D-469E-8DBC-A42EB79CB428} -> Adware.Generic : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{971CC777-75E4-4CBA-9CBC-151CFCBD3A49}\RP466\A0067410.DLL -> Adware.IWon : Cleaned with backup (quarantined).
HKU\S-1-5-21-329068152-1580818891-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext \Settings\{8B6DA27E-7F64-4694-8F8F-DC87AB8C6B22} -> Adware.LinkMaker : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{971CC777-75E4-4CBA-9CBC-151CFCBD3A49}\RP466\A0067434.EXE -> Adware.MyWebSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{971CC777-75E4-4CBA-9CBC-151CFCBD3A49}\RP466\A0067400.DLL -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup (quarantined).
:mozilla.54:C:\Documents and Settings\check\Application Data\Mozilla\Firefox\Profiles\nczergbp.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\check\Cookies\check@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:C:\Documents and Settings\Shane Foyston\Application Data\Mozilla\Firefox\Profiles\jauzqyvm.default\coo kies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.38:C:\Documents and Settings\check\Application Data\Mozilla\Firefox\Profiles\nczergbp.default\coo kies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Shane Foyston\Cookies\shane foyston@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\check\Cookies\check@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.77:C:\Documents and Settings\Shane Foyston\Application Data\Mozilla\Firefox\Profiles\jauzqyvm.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.79:C:\Documents and Settings\Shane Foyston\Application Data\Mozilla\Firefox\Profiles\jauzqyvm.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.80:C:\Documents and Settings\Shane Foyston\Application Data\Mozilla\Firefox\Profiles\jauzqyvm.default\coo kies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.37:C:\Documents and Settings\check\Application Data\Mozilla\Firefox\Profiles\nczergbp.default\coo kies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.51:C:\Documents and Settings\check\Application Data\Mozilla\Firefox\Profiles\nczergbp.default\coo kies.txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\check\Cookies\check@e-2dj6wflikmczoeq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\check\Cookies\check@e-2dj6wjk4gmdzecq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.89:C:\Documents and Settings\Shane Foyston\Application Data\Mozilla\Firefox\Profiles\jauzqyvm.default\coo kies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.23:C:\Documents and Settings\Shane Foyston\Application Data\Mozilla\Firefox\Profiles\jauzqyvm.default\coo kies.txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Shane Foyston\Cookies\shane foyston@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.18:C:\Documents and Settings\Shane Foyston\Application Data\Mozilla\Firefox\Profiles\jauzqyvm.default\coo kies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.19:C:\Documents and Settings\Shane Foyston\Application Data\Mozilla\Firefox\Profiles\jauzqyvm.default\coo kies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.20:C:\Documents and Settings\Shane Foyston\Application Data\Mozilla\Firefox\Profiles\jauzqyvm.default\coo kies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.21:C:\Documents and Settings\Shane Foyston\Application Data\Mozilla\Firefox\Profiles\jauzqyvm.default\coo kies.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Shane Foyston\Cookies\shane foyston@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
::Report end