Thread: C:\Uploads
View Single Post
  #2 (permalink)  
Old June 3rd, 2005
Lanky_duke
Guest
 
Posts: n/a
Default

Thanks for the reply, I used another online scanner, Kaspersky I think. It came up with 4 viruses in 11 infected files. A few little notes that I discovered in the process:
1) During startup Ctrl-Alt-Delete AND Ctrl-shift-Esc were both disabled during startup, unless I hit it STRAIGHT away or after final loading,
2) XZ.exe was using a lot of CPU, which was visible on the C:\ base directory,
3) Along with xz.exe there was also temp.zip (which was the same file size as the unwanted uploads, b.tmp and z.tmp. All four of these disappeared after startup,
4) C:\Windows\System32 folder attributes were set to hidden, as well as C:\Uploads, therefore I couldn't view them, even with "show all hidden and system files"
5) Hidden in the System32 folder were the following nasties: cmd.com, netstat.com, ping.com, p2pnetworking.exe, regedit.com, taskkill.com, tasklist.com, tracert.com - all had hidden attribute.
6) Just before rectifying the situation MediaAccess.exe and MediaAcck.exe appeared in Processes in Task Manager, which I couldn't even end - it simply kept re-opening.
7) Start/Run regedit, command, and cmd wouldn't open. The only way I got around it was by typing cmd.exe and regedt32. This was a result of the files stated in 5).

I pity anyone else that get's hit with the same problem. Many hours have been lost as a result of it.
Reply With Quote