PC Review


Reply
Thread Tools Rate Thread

Directory C:\winnt\system32\drivers found on XP - Trojan?

 
 
Paul Moloney
Guest
Posts: n/a
 
      11th Dec 2003
While searching for the file "explorer.exe" on XP (due to it having a
high CPU usage), I found a copy in the folder
C:\winnt\system32\drivers. In this folder, I also found the following
files:

FireDaemon.exe
hexplore.exe
explore.exe
remote.ini
script1.ini
sec.bat
winini.bat

explore.exe had the name mIRC associated with it; doing a search for
it turned up the name of a trojan. Needless to say, this all looked
pretty suspicious. However, searching my registry turned up none of
the registry entries associated with this virus. And I run anti-virus
and anti-trojan software regularly, so am surprised nothing was
detected.

I found mIrc in the "Add/Remove Programs" dialog box, and I recall
installing IRC software a year or two back. (I removed it once found).
Is it possible this was a trojan, or does the legit mIrc install files
to the above folder, and therefore can be confused with the trojan?
Should I be worried, and if so, what should I look for, and can anyone
recommend a good anti-trojan program? (I moved from the now-default
Anti-Trojan 5.5.x to the new a(2)).

Thanks,

P.
 
Reply With Quote
 
 
 
 
Roger Abell
Guest
Posts: n/a
 
      11th Dec 2003
If you had a file named FireDaemon.exe on your
system and you malware scanning tools did not
trigger, then you should question the quality of
that scanning tool or your understanding of what
it is that it scans for.
Having these files tucked down in the drivers folder
is in itself suspicious. A legitimate installer would
not drop files there, let alone leave them there.
You should carefully examine that system with a
few good tools, monitor what ports have things bound
to them, etc.

--
Roger Abell
Microsoft MVP (Windows Server System: Security)
MCSE (W2k3,W2k,Nt4) MCDBA
"Paul Moloney" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> While searching for the file "explorer.exe" on XP (due to it having a
> high CPU usage), I found a copy in the folder
> C:\winnt\system32\drivers. In this folder, I also found the following
> files:
>
> FireDaemon.exe
> hexplore.exe
> explore.exe
> remote.ini
> script1.ini
> sec.bat
> winini.bat
>
> explore.exe had the name mIRC associated with it; doing a search for
> it turned up the name of a trojan. Needless to say, this all looked
> pretty suspicious. However, searching my registry turned up none of
> the registry entries associated with this virus. And I run anti-virus
> and anti-trojan software regularly, so am surprised nothing was
> detected.
>
> I found mIrc in the "Add/Remove Programs" dialog box, and I recall
> installing IRC software a year or two back. (I removed it once found).
> Is it possible this was a trojan, or does the legit mIrc install files
> to the above folder, and therefore can be confused with the trojan?
> Should I be worried, and if so, what should I look for, and can anyone
> recommend a good anti-trojan program? (I moved from the now-default
> Anti-Trojan 5.5.x to the new a(2)).
>
> Thanks,
>
> P.



 
Reply With Quote
 
ceedee
Guest
Posts: n/a
 
      11th Dec 2003
its a irc trojan
a very widespread trojan and it usually installs to the drivers or
drivers/etc dir
i would suspect your anti virus has at some point killed it already
these files are whats left

firedaemon is a legitimate program so a lot of v checkers wont pull it
it is used to install a program as a service
in this case explore.exe which is just mirc renemaed
the other files are scripts mirc uses

just delete them all and relax

ceedee

"Roger Abell" <(E-Mail Removed)> wrote in message
news:%235G$(E-Mail Removed)...
> If you had a file named FireDaemon.exe on your
> system and you malware scanning tools did not
> trigger, then you should question the quality of
> that scanning tool or your understanding of what
> it is that it scans for.
> Having these files tucked down in the drivers folder
> is in itself suspicious. A legitimate installer would
> not drop files there, let alone leave them there.
> You should carefully examine that system with a
> few good tools, monitor what ports have things bound
> to them, etc.
>
> --
> Roger Abell
> Microsoft MVP (Windows Server System: Security)
> MCSE (W2k3,W2k,Nt4) MCDBA
> "Paul Moloney" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
> > While searching for the file "explorer.exe" on XP (due to it having a
> > high CPU usage), I found a copy in the folder
> > C:\winnt\system32\drivers. In this folder, I also found the following
> > files:
> >
> > FireDaemon.exe
> > hexplore.exe
> > explore.exe
> > remote.ini
> > script1.ini
> > sec.bat
> > winini.bat
> >
> > explore.exe had the name mIRC associated with it; doing a search for
> > it turned up the name of a trojan. Needless to say, this all looked
> > pretty suspicious. However, searching my registry turned up none of
> > the registry entries associated with this virus. And I run anti-virus
> > and anti-trojan software regularly, so am surprised nothing was
> > detected.
> >
> > I found mIrc in the "Add/Remove Programs" dialog box, and I recall
> > installing IRC software a year or two back. (I removed it once found).
> > Is it possible this was a trojan, or does the legit mIrc install files
> > to the above folder, and therefore can be confused with the trojan?
> > Should I be worried, and if so, what should I look for, and can anyone
> > recommend a good anti-trojan program? (I moved from the now-default
> > Anti-Trojan 5.5.x to the new a(2)).
> >
> > Thanks,
> >
> > P.

>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
File is missing or corrupt: C:\Winnt\System32\Drivers\Pci.sys help =?Utf-8?B?RGFuIGs=?= Windows XP Performance 1 21st Aug 2006 11:38 AM
Problemr with file: \Winnt\System32\Drivers\etc\Services =?Utf-8?B?Q2Vkcmlj?= Microsoft Windows 2000 Networking 0 19th Apr 2006 12:10 PM
c:\winnt\system32\drivers\etc\hosts Mat Microsoft Windows 2000 6 29th Jul 2004 04:01 AM
default directory c:\winnt\system32? HVE Microsoft Dot NET Framework Forms 4 11th Feb 2004 04:05 PM
temp directory in \winnt\system32 john bailo Microsoft Dot NET 1 7th Oct 2003 11:53 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 02:12 AM.