Hi Friends
Found this icon on the desktop - Wgtvsdzmkk.tmp - I delete it and it appears again when I next start PC. Is this something to worry about? Any commentsappreciated. PC is on good old XP. Thanks all, Tez

Dani AI

Generated

Several replies already point toward a malware angle and to scan/remove tools (noted above from , and ). The next step is to identify how that desktop icon is being created before repeatedly deleting it. Do not run the file. First, confirm whether it is a real file or a shortcut: check Properties to see the full path and the Target (shortcuts) and turn on visible extensions so the name really ends with .tmp. Record file size, timestamps and the exact path (XP desktop is typically C:\Documents and Settings\<User>\Desktop).

If the file is recreated at boot, look for the creator rather than the file itself. Use an autorun/startup inspector and a handle/process viewer to search the system for that filename, jump to the start-up entry, and see which process holds the file at boot. Also search scheduled tasks, the per-user and All Users Startup folders, and the registry Run keys (HKCU/HKLM Run). On XP the Scheduled Tasks applet lists active tasks; many persistent creators hide there or in services. For quick multi-engine checking, submit the file hash or the file itself to VirusTotal (https://www.virustotal.com/). For locating startup items and open handles, the Sysinternals utilities are ideal: Autoruns (https://learn.microsoft.com/sysinternals/downloads/autoruns) and Process Explorer (https://learn.microsoft.com/sysinternals/downloads/process-explorer).

Removal: boot to Safe Mode or use an offline/rescue environment so the creator process cannot reload the file, then delete the file and remove the offending startup/task/registry entry. If a process holds the file, use Process Explorer to close the handle or stop the service first. Keep the machine offline while cleaning. Finally, note that Windows XP reached end-of-support in 2014; unpatched legacy systems are much more vulnerable, so migration to a supported OS is strongly recommended (https://learn.microsoft.com/en-us/lifecycle/products/windows-xp).

Recommended Answers

All 3 Replies

Likely a malware file. Download MBAM, update and run a Quick scan, ensure all it finds has a checkmark and choose to remove all. Reboot if MBAM requests it.
Please report back on your findings.

The file you mentioned above is definatly a malware file-epesially if it appears again upon delete.the file is a "temporary file" as well meaning it may not be their for long you should find the malware and kill it soon! If MBAM doen't find it, I used a tool calle "McAfee Stinger" google that and download it (That stinger tool has helped me kill that conficker worm and many others before.) But try MBAM first!

Good Luck!

javanoob101

If you have not yet removed it and it still comes back, turn off the restore before you use the tool to remove it, then remove. Then shut down restart and reset the restore.
Sometimes virus/malware hides in the restore cabinets and will come back unless the restore is turned off to remove it.
m

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.