WIERD new folders in C drive....

Status
Not open for further replies.

HiFi

Posts: 8   +0
I am getting wierded out by 2 new folders that just poofed into my C: Drive under mysterious circumstances:

I was on my desktop minding my own business, then I clicked on My Computer (from the Start menu) and I got that "Windows Explorer has encountered an unexpected problem and has to close.." blah blah, Send, Dont Send, ETC.

Well I had to click on something so I did, and then the entire Windows interface blinked off for a couple seconds, then came back on.

I went into My Computer again, looked in my C: drive, and found these 2 wierd folders with HUGE hexidecimal-looking names.

One is called: 281885f0332ff0e167, the other is called: 025de114596b2c6a813859.They each contain the same file, exactly 699KB large, just called "update" with the subtitles "Microsoft Service Pack Setup/Microsoft Corporation". In Properties it says they were created and Modified August 11, 2006 (more than a month ago).

Could the error have poofed these files from a hidden state? or are they bad news?
Any ideas? What should I do?

Help.[posted an HJT log just as a standard protocol]
 
Windows Update and some hotfixes create temporary directories with that kind of "random" names. You should be able to delete them without problems.
 
Mict is more than likely correct.

However, just to be sure, rename HijackThis.exe to HijackThis1991.exe and post a fresh HJT log. The reason you need to rename HijackThis.exe is because certain malware can hide from that filename.

Regards Howard :)
 
howard_hopkinso said:
Mict is more than likely correct.

However, just to be sure, rename HijackThis.exe to HijackThis1991.exe and post a fresh HJT log. The reason you need to rename HijackThis.exe is because certain malware can hide from that filename.

Regards Howard :)


Really? When did this start happening Howard? Good safety tip! That's right up there with, "Don't cross the beams", Ghost Busters.
(that's not sarcasim incase it sounded like that).

Thanks.
 
This started happening a few weeks, maybe a couple of months ago. I noticed members were saying they were still having problems, even though their HJT logs appeared to be clean.

Once I researched the problem I quickly foundout that malware writers were targeting HijackThis.exe and that the way round this was to rename the HijackThis.exe file to something else. This then allows any malware to show up in HJT.

I have therefore altered some of our stickies to reflect this.

Regards Howard :)
 
Status
Not open for further replies.
Back