Interesting (And annoying) files in my Temp directory

loco365

Well-Known Member
OP
Member
Joined
Sep 1, 2010
Messages
5,457
Trophies
0
XP
2,927
pUeQFT8.png
I have these two files in my Temp directory, and upon login, it tries to call regedit to edit something in my registry. After scanning them with AVG, Windows Malicious Software Tool, and MSE, none of them acknowledge that they may be malicious. A UAC prompt comes up every time, and if I click No on it, it goes away, then just comes back again. Deleting these files from the temp directory doesn't seem to make any difference. What I want to know, is, is it malicious? Has anyone had these files before to any ill effect?​
I would do a system restore, but I'm not sure when they placed themselves in the Temp directory, or what places them there, and I don't know when the file that places them here were added. Where should I go from here? I'm considering using the Avast boot tool after running Windows 7 in safe mode and running another AVG scan, but I want to see if anyone here has had any experience with these registry-editing files.​
 

gifi4

How am I a 'New Member'?
Member
Joined
Apr 21, 2010
Messages
2,350
Trophies
0
Age
27
Location
Melbourne
XP
713
Country
A google search leads straight to this.
The person with the issue fixed it by using a previous system restore point. They had no clue when it came about so they just took a guess.
Read over the thread and perhaps post another thread on that site with a referal to the original thread.

Other than that, I can't really help you out...
 

loco365

Well-Known Member
OP
Member
Joined
Sep 1, 2010
Messages
5,457
Trophies
0
XP
2,927

loco365

Well-Known Member
OP
Member
Joined
Sep 1, 2010
Messages
5,457
Trophies
0
XP
2,927
It's the file association, when you try to run a .reg file it launches regedit, which needs admin permission.

Dunno' what it'll do, most likely fail since it's not formatted right.
Well, running it doesn't seem to be doing anything. I just kinda wish it would go away. Hopefully AVG will fix it in the future.
 

jefffisher

Well-Known Member
Member
Joined
Dec 17, 2006
Messages
1,621
Trophies
1
XP
2,068
Country
United States
since they are re-appearing i'd suspect there is a program running that is rewriting them, bring up the task manage and view processes from all users to see if you can find anything unusual.
a rather simple solution that works a surprising amount of the time to get rid of problems like this is run ccleaner, the cleaner the registry cleaner and then go to tools and startup disable anything that shouldn't be there and restart.
 

lufere7

Well-Known Member
Member
Joined
Jul 29, 2010
Messages
471
Trophies
0
Age
28
Location
Sonora
XP
250
Country
Mexico
Not really helpful, but I find it fun that the file is named "ForYouAleMyLove" in spanish. Weird name for a virus (if it is one at all) Maybe some hacker dude declared his love to "Ale" like this? :P
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Psionic Roshambo @ Psionic Roshambo: https://m.youtube.com/watch?v=FzVN9kIUNxw