I am running a w2003 SP1 system. I use Windows Defender and Malwarebytes to check for virus etc.
The system is setup as an application server, terminal server and file server
I have what appears to be a virus -
it creates files such as w19d4d928.exe in the following directories ( it chooses the directory on a random basis it appears.)
C:\WINDOWS\Temp
C:\Documents and Settings\Administrator\Local Settings\Temp
The virus appears to create an 8Kb file which appears to run and create another file in the same file name type as above but with 12K or 64K
The internet access will slow right down when these files are created
If I delete the file ie go into process explorer and kill the file then delete it from the directory it will again reappear after some time but may appear in another directory.
Its appearence appears random ie I cannot link any running program to its appearance.
If I let the thing run then it will over time create more of these exe files
There are no pop ups etc and windows defender has no problem with these exe's
I dump the strings in these exe files to see if there is any tag but can't find any - search the web but can't find any reference - the antivirus programs do not see these exe's as virus
At present I simply suspend the exe's when they load.
This is driving me around the bend
does any one out there have experience with similar incidents.
The most visual thing about this 'virus' is
it creates 9 character exe file that always starts with W
John
The system is setup as an application server, terminal server and file server
I have what appears to be a virus -
it creates files such as w19d4d928.exe in the following directories ( it chooses the directory on a random basis it appears.)
C:\WINDOWS\Temp
C:\Documents and Settings\Administrator\Local Settings\Temp
The virus appears to create an 8Kb file which appears to run and create another file in the same file name type as above but with 12K or 64K
The internet access will slow right down when these files are created
If I delete the file ie go into process explorer and kill the file then delete it from the directory it will again reappear after some time but may appear in another directory.
Its appearence appears random ie I cannot link any running program to its appearance.
If I let the thing run then it will over time create more of these exe files
There are no pop ups etc and windows defender has no problem with these exe's
I dump the strings in these exe files to see if there is any tag but can't find any - search the web but can't find any reference - the antivirus programs do not see these exe's as virus
At present I simply suspend the exe's when they load.
This is driving me around the bend
does any one out there have experience with similar incidents.
The most visual thing about this 'virus' is
it creates 9 character exe file that always starts with W
John