Results 1 to 9 of 9

Thread: need info re: possible trojan

  1. #1
    johnyboy Guest

    need info re: possible trojan

    Windows on my system is set to show ALL files & folders.
    However, scandisk shows 41,824,256 bytes in 190 hidden files.
    I need some way to identify what kind of files these are & get
    rid of them, (without having to go thru the hassle of reformatting my HD).
    Is somebody hiding illicit files on my hard disk?
    Are these files created by some sort of "remote administrative trojan?

  2. #2
    Danzer Guest

    Re: need info re: possible trojan

    johnyboy wrote:
    > Windows on my system is set to show ALL files & folders.
    > However, scandisk shows 41,824,256 bytes in 190 hidden files.
    > I need some way to identify what kind of files these are & get
    > rid of them, (without having to go thru the hassle of reformatting my HD).
    > Is somebody hiding illicit files on my hard disk?
    > Are these files created by some sort of "remote administrative trojan?


    Showing all files and folders is not the same as changing the hidden
    attribute of a file or folder. Making a file not hidden is accomplished
    by entering the following.

    attrib -h filename

    Windows makes use of the hidden, system and read-only attributes to
    prevent you from possibly deleting a file or directory that is necessary
    for its operation, e.g. IO.SYS. Use a virus and/or adware scanner to
    check for any other possibilites.

    Danzer


  3. #3
    Guest

    Re: need info re: possible trojan


    It's normal for Windows to create a large number of hidden files.

    "johnyboy" <johnyboya3@netscape.net> wrote in message
    news:bfeb4c08.0312021122.5475635d@posting.google.c om...
    > Windows on my system is set to show ALL files & folders.
    > However, scandisk shows 41,824,256 bytes in 190 hidden files.
    > I need some way to identify what kind of files these are & get
    > rid of them, (without having to go thru the hassle of reformatting my HD).
    > Is somebody hiding illicit files on my hard disk?
    > Are these files created by some sort of "remote administrative trojan?




  4. #4
    Al Bundy Guest

    Re: need info re: possible trojan

    johnyboya3@netscape.net (johnyboy) wrote in
    news:bfeb4c08.0312021122.5475635d@posting.google.c om:

    > Windows on my system is set to show ALL files & folders.
    > However, scandisk shows 41,824,256 bytes in 190 hidden files.
    > I need some way to identify what kind of files these are & get
    > rid of them, (without having to go thru the hassle of reformatting my
    > HD). Is somebody hiding illicit files on my hard disk?
    > Are these files created by some sort of "remote administrative trojan?


    If you want a text files showing what they all are and what folders
    they're in, from a command prompt try:


    cd \
    C:\> dir */a:h/s > hidden.txt


    As mentioned, hidden files are not bad boys by default.

  5. #5
    Bill Sanderson Guest

    Re: need info re: possible trojan

    "johnyboy" <johnyboya3@netscape.net> wrote in message
    news:bfeb4c08.0312021122.5475635d@posting.google.c om...
    > Windows on my system is set to show ALL files & folders.
    > However, scandisk shows 41,824,256 bytes in 190 hidden files.
    > I need some way to identify what kind of files these are & get
    > rid of them, (without having to go thru the hassle of reformatting my HD).
    > Is somebody hiding illicit files on my hard disk?
    > Are these files created by some sort of "remote administrative trojan?


    I did Al Bundy's command-line procedure on my machine and came up with 52.5
    megs of hidden files--far more than I would have expected. At a quick run
    through, there's nothing strange about them--chief larger offenders are
    music and digital rights management (DRM) stuff and fonts. Besides these
    there are profiles and bits of the OS that are important, as well as many
    many little zero bit critters used for various purposes.




  6. #6
    Dave Guest

    Re: need info re: possible trojan

    johnyboy wrote:
    > Windows on my system is set to show ALL files & folders.
    > However, scandisk shows 41,824,256 bytes in 190 hidden files.
    > I need some way to identify what kind of files these are & get
    > rid of them, (without having to go thru the hassle of reformatting my HD).
    > Is somebody hiding illicit files on my hard disk?
    > Are these files created by some sort of "remote administrative trojan?


    A lot of files are hidden on Windows systems usually by the OS itself,
    this is to protect the user from deleting an essential file among other
    things. To see the hidden files you can from windows explorer go to
    | tools | Folder Options | View |
    Click 'Show hidden files and folders'

    Don't get rid of any files until you find out what they are. If you are
    worried about virus or trojans, run a virus scan program, they can
    safely delete the files.

    Hope that helps
    Dave


  7. #7
    Adam Pepper Guest

    Re: need info re: possible trojan


    "johnyboy" <johnyboya3@netscape.net> wrote in message
    news:bfeb4c08.0312021122.5475635d@posting.google.c om...
    > Windows on my system is set to show ALL files & folders.
    > However, scandisk shows 41,824,256 bytes in 190 hidden files.
    > I need some way to identify what kind of files these are & get
    > rid of them, (without having to go thru the hassle of reformatting my HD).
    > Is somebody hiding illicit files on my hard disk?
    > Are these files created by some sort of "remote administrative trojan?


    First off I usually put the fie/folder names into Google. It's amazing how
    good that search engine is.

    OT:
    Google is also good for checking files you're not sure about that are
    reported by HijackThis

    --
    acmp<><
    adam@tech.heaven <not real duh!
    acmp at ntl world dot com

    http://www.HacksMeOff.pagehere.com



  8. #8
    Richard Edward Guest

    Re: need info re: possible trojan


    -----BEGIN PGP SIGNED MESSAGE-----

    On 2 Dec 2003, johnyboya3@netscape.net (johnyboy) wrote:

    >Windows on my system is set to show ALL files & folders.
    >However, scandisk shows 41,824,256 bytes in 190 hidden files.
    >I need some way to identify what kind of files these are & get
    >rid of them, (without having to go thru the hassle of reformatting my HD).
    >Is somebody hiding illicit files on my hard disk?
    >Are these files created by some sort of "remote administrative trojan?


    Don't panic.

    There's probably nothing at all wrong with your machine, at least not with
    having hidden files. SCANDISK is reporting file attributes. A file, or even
    a folder/directory can be "marked" as hidden, system, read only, or any
    combination of the three. This doesn't mean there's something wrong with
    the file, just that your operating system assigned it special qualities.
    Examples of "hidden" files would include your Windows registry and print
    spool folder. I doubt you want to get rid of those.

    For what it's worth, these "hidden" files will show up in Explorer with
    "view all files" and "show details" turned on. Scroll to the right in the
    list of files and you will see a column called "Attributes". Anything with
    an 'H' in that column is a hidden file.

    - --

    It was once thought that a million monkeys, banging on
    a million typewriters, would eventually reproduce the
    entire works of Shakespeare.

    Thanks to the Internet, we now know this is untrue.

    -----BEGIN PGP SIGNATURE-----
    Version: N/A

    iQEVAwUBP8zsvgQjMfz1bq39AQFj0Af/fJdm/ZtkEk41IEMEyb+Jiprt3vz6NX9B
    3GyPLTS9n+u5cHWeYbYya/GV1BO8/e4N1EZQ5sq46CQXUNwfpljLndLWsJF5rytu
    I316vC+2jY9CDaAa5rpGDtbZRz50mHhMhwaQLykBL3WO6qZwW2 ldei8SQ0Ek9bcW
    zTVUqpD8SLPjcOCZqcWCMR2tbNSRcyZ5cg7Mz+/3M2tbPJwzC0UOShe3EN8n4WSP
    uK6vq7g3nhuyzScz5be5KLmo7aYFItuLBe4r2qhmu95+E0rTNs D4DtU4Fd78jk1g
    z30lFob+iXGIpzNAF59+TFFSJqehuredrRLtOmVnj+KE/gr1FIFlsQ==
    =uZnW
    -----END PGP SIGNATURE-----


  9. #9
    Bill Sanderson Guest

    Re: need info re: possible trojan

    This procedure can be useful, on a system known to have been compromised: I
    did the same search, using Al Bundy's command-line, on a machine which had a
    number of virus/trojan infections, via IM or Kazaa channels. These
    infections had been effectively negated via manual procedures, antivirus,
    ad-aware, and Spybot Search & Destroy. However, a search today for hidden
    files, turned up a cluster of such files, both apparent data files, and a
    variety of randomly named executables, all with the same date, which I've
    removed. These weren't active, but the data files probably contained
    keystroke recording data which is better deleted, and I'd just as soon not
    have the executables lying around, even though they weren't in use, or in
    danger of being executed.

    These weren't flagged by the antivirus--I may do some more work to see
    why--i.e. submit them and see what they say.

    "Bill Sanderson" <Bill_Sanderson@msn.com.plugh.org> wrote in message
    news:Oay16aRuDHA.2544@TK2MSFTNGP10.phx.gbl...
    > "johnyboy" <johnyboya3@netscape.net> wrote in message
    > news:bfeb4c08.0312021122.5475635d@posting.google.c om...
    > > Windows on my system is set to show ALL files & folders.
    > > However, scandisk shows 41,824,256 bytes in 190 hidden files.
    > > I need some way to identify what kind of files these are & get
    > > rid of them, (without having to go thru the hassle of reformatting my

    HD).
    > > Is somebody hiding illicit files on my hard disk?
    > > Are these files created by some sort of "remote administrative trojan?

    >
    > I did Al Bundy's command-line procedure on my machine and came up with

    52.5
    > megs of hidden files--far more than I would have expected. At a quick run
    > through, there's nothing strange about them--chief larger offenders are
    > music and digital rights management (DRM) stuff and fonts. Besides these
    > there are profiles and bits of the OS that are important, as well as many
    > many little zero bit critters used for various purposes.
    >
    >
    >




Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •