Solved

Strange names applied to downloaded files from links

Posted on 2010-11-14
9
588 Views
Last Modified: 2013-12-08
Hi Experts

I have just noticed some strange behaviour with my Windows XP SP3 IE7 system with regard to the names applied to downloaded files.

I had looked back at another EE question that prompted me to download a program again.
http://www.medical-dictionary.ro/download.html
A Right-Click > Copy Shortcut on the "Version 2.0" link pastes as this:
http://www.medical-dictionary.ro/download/xt2installer1.exe
but Right-Click > Save Target As downloads the file as: "xt2installer1CAX7JBQU.exe"

So, it has added on "CAX7JBQU" to the file name, and that at first glance matches the names of the files here:
C:\Documents and Settings\Bill\Local Settings\Bill\Temporary Internet Files\Content.IE5\

The thing is that none of the sub-folders there has that name:
55VSLUVQ, 65K93GTA, 7V9X2QCS, JQ18NKJP, ON08ZNU8, SK3CE7JA, SPOMD3SH, U07EKR1E

This is not isolated to that page, eg. maybe a PHP Script has modified the file name as it is fetched from source.  I first noticed this with the following link that I was pasting in another question this morning.  You will see the link to "ntfsext.exe" in the comment ID 34129989 in this question:
http://www.experts-exchange.com/Q_26600910.html

That saves as "ntfsextCA7ZZZZD.exe" even though the shortcut's target is to "ntfsext.exe", and I have no temporary internet files sub-folders named "CA7ZZZZD".

The file is actually downloaded to the temporary internet files folders as "ntfsextCA7ZZZZD.exe" before it copies to my specified download destination, so it doesn't appear to be something applied after the download.

Note, the same applies when I paste the link into a new Outlook Express message, show the "preview" tab, and click or right-click the link.

This behaviour seems so far to be isolated to links Internet Exlorer and Outlook Express.
It DOES NOT occur with links in Firefox, Google Chrome, Opera, or from a Windows shortcut to a target file.

Deleting the temporary internet files does not change the behaviour.

Has anybody else experienced this behaviour?
Perhaps it is a Windows Update at work?
Malicious behaviour?

As far as I can determine this computer is currently free from malware.

The only recent changes I made to this system are that I installed the free ZoneAlarm firewall and upgraded my AVG Free AntiVirus application.  It is hard to know when it occurred in relation to those applications, but I will try to test with ZoneAlarm disabled.  It's a bit harder to completely disable AVG though.

Thanks

Bill
0
Comment
Question by:BillDL
  • 3
  • 2
  • 2
  • +2
9 Comments
 
LVL 11

Expert Comment

by:farjadarshad
ID: 34130367
0
 
LVL 22

Expert Comment

by:orangutang
ID: 34130370
Wow, BillDL is asking a question? :)

Did you already check the add-ons? And what's wrong with IE8? :)
0
 
LVL 47

Accepted Solution

by:
dbrunton earned 167 total points
ID: 34130394
Comment

These look like 8 letter file names.  

See http://wordpress.bladeforensics.com/?p=204 because what you seem to be getting is a cache folder name applied to the file name.  The link shows that Outlook Express also uses this area.

I wonder if the cache area is screwed in some manner.  You could try deleting all of those cache folders and seeing if IE rebuilds them and starts working properly.
0
 
LVL 22

Assisted Solution

by:orangutang
orangutang earned 167 total points
ID: 34130414
Also, maybe try checking the "Index.dat files" checkbox in CCleaner.
0
Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 
LVL 66

Assisted Solution

by:johnb6767
johnb6767 earned 166 total points
ID: 34142629
Lol @ orangutang....

I would be curious what the following command returns as a file location....

Start,run,"shell:cache\content.ie5"

Also, I would uninstall avg for now. Can always reinstall or change av later...

 At minimum, disable the web shield and the avg linkscanner..... Seen hokey things with those installed....
0
 
LVL 38

Author Comment

by:BillDL
ID: 34143106
Thanks for your suggestions and comments so far guys.

Actually, there are a few things that have begun to go a bit wonky with this system and I've started backing up recent stuff in case I need to reinstall from fresh.

I believe that Lavasoft Ad-Aware has actually been the original cause of the problem, or has certainly contributed to it.  I decided to give Ad-Aware a try out again just about the time this issue with the downloaded file names started, or rather the issue started just after Ad-Aware froze my system during a scan and I uninstalled it in disgust as I had done last year when a previous version screwed up.

Uninstalling it did not remove the registry values for a low level driver/service ("LBD.SYS" - Ad-Aware mini-filter driver) and this is what has been hanging other services and drivers at boot time, including the AVG Drivers and Services.  I think it may also have been hampering various attempts at deleting certain things like "index.dat" files "on reboot".

I'll get back later with more details, because I now have an issue that my display is screwed up at 32-bit colour setting whereby it shows a ghosted duplication of desktop and start menu content. Desktop and start menu content in the bottom 8th of the screen gets ghosted up in the top 8th of the screen and vice-versa.  Reinstalling graphics drivers and deleting the Icon Cache *.db file hasn't helped either.

I can't help but think that the two issues are related, but I need to try a few more things.

Bill
0
 
LVL 38

Author Comment

by:BillDL
ID: 34145010
OK Guys, both issues now resolved.

Firstly the actual question, ie. the additional "cache-type" 8-character content being injected into the names of downloaded files.

Thanks for the info and links, farjadarshad, but I had mentioned already mentioned: "As far as I can determine this computer is currently free from malware". It's the first thing I do when I see odd behaviour, but I nevertheless did so again with negative results.

orangutang: Add-Ons were already verified to be the "standard" ones, but good suggestion.  IE8?  That comes next. I had to sort out the display issue first.

dbrunton, orangutan and johnb6767:
Certainly the additional characters matched the format of the Content.IE5 sub-folders, but each time I had the issue none of those folder names matched the extra characters in the file names I was downloading.  So yes, it looked like "index.dat" was holding leftovers and was corrupt, but which one?  

I went wild and deleted all of them, but that still didn't fix the issue on reboot UNTIL I:

1. Disabled Virtual Memory to delete "C:\pagefile.sys"
2. Removed the "LBD.SYS" - Ad-Aware mini-filter driver registry values using SysInternals "autoruns"
3. Deleted the index.dat files
4. Rebooted
5. Enabled Virtual Memory again
6. Rebooted.

Mysteriously that's also when my display issues resolved themselves and I could change to 32-bit colour mode without the screen artefacts. I had wasted a lot of time deleting the icon cache, testing on another monitor, uninstalling programs like RealVNC and Skype, (which allow screen sharing and could potentially have caused issues), plus deleting various registry MRU keys, etc.

Incidentally, Disabling AVG Free 2011's "Identity Protection" component has speeded up the boot process to ther "ready" state.  With it enabled it took ages to load the desktop and become ready in the system tray, and before it did so it was blocking other services from launching and showing there.  That didn't help to resolve the specific issues, but made the 20 or so reboots at least tolerable!

I really don't know which of the actions fixed the issue, or if they were linked, but I'm glad it's fixed and I'm thankful for the suggestions. My guess is still that the leftover Ad-Aware drivers/services were preventing a real cleanup by hanging the system boot process.

PS, don't touch Ad-Aware. Their software has twice screwed up my system in two successive years after running it only once on each occasion.

Thanks again.
Bill
0
 
LVL 38

Author Closing Comment

by:BillDL
ID: 34145056
Thank you guys. The suggestions kept me looking in the right direction.
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 34147201
i stopped using it years ago. used to be a real good product.....

glad u r fized though.....
0

Featured Post

How to improve team productivity

Quip adds documents, spreadsheets, and tasklists to your Slack experience
- Elevate ideas to Quip docs
- Share Quip docs in Slack
- Get notified of changes to your docs
- Available on iOS/Android/Desktop/Web
- Online/Offline

Join & Write a Comment

I recently found myself in a Corporate Situation where the client had requested blocking access to any and all websites except his own Domain? Easy? I am sure this would be your answer but their requirement was, this has to be done without using…
Do you come here a lot? Are you lazy like me and don't want to go through the "trouble" of having to click your Dock's Safari icon and then having to click your Experts Exchange Favorites bookmark to get here? Well then this article is for you.
Google currently has a new report that is in beta and coming soon to Webmaster Tool accounts. This Micro Tutorial will highlight new features for Google Webmaster Tools.
This Micro Tutorial will demonstrate how to add subdomains to your content reports. This can be very importing in having a site with multiple subdomains.

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now