Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

Question

Did Malware create these directories?

Oct 21, 2016 12:00PM PDT

I was looking through a quite old system running XP, when I noticed there were many "duplicate" index.dat files in places where they should not be. Below is an example- notice the "Temp".

C:\ Documents and Settings\ username\ Local Settings\ Temp\ History.IE5\ index.dat

This is what the normal one looks like;

C:\ Documents and Settings\ username\ Local Settings\History.IE5\ index.dat


There was also these weird directories for cookies and temporary internet files etc. Is this typical for Backdoor Trojans or RATs to create? Or perhaps adware?The system had a bit of everything (dont worry about getting it clean for me)

http://pastebin.com/6mWyX5Vn

I found a trojan that does create this directories, actually;

http://www.threatexpert.com/report.aspx?md5=47d2da33a1c0e446e42bcee6f5537b29

Is that 100% would caused this? Or are there other malware or even adware that could?

Discussion is locked

- Collapse -
Clarification Request
Since it has a trojan and rootkit.
Oct 21, 2016 12:08PM PDT

"1. C:\WINDOWS|SYSTEM32\drives\psec.sys(Trojan.FakeAlert)

2. Physical Sector 312576705 on drive 0 (Rootkit.Alureon.E.VBR"

I think temp folders, cookies are the least worries on this PC. Tell the forum how you will take care of these rather serious infections.

- Collapse -
I dont have to
Oct 21, 2016 12:17PM PDT

This computer is never used, has no confidential info on it or anything, I'm just trying to learn about what exactly is the cause of these extra directories.

- Collapse -
As the malware and more
Oct 21, 2016 12:29PM PDT

Does not publish source code you can't be sure. Most files and folders in the old IE5 folder are just caches with seemingly random names. As that is well discussed I don't duplicate the web priors here.

It does not matter if you used it for confidential info, these can be hijacked to participate in denial of service attacks or host porn that can in some countries cause legal issues.

As a famous leader told us "Wipe them out, .all of them." Never let a machine under your control remain infected and out of your control.

- Collapse -
good idea
Oct 21, 2016 12:52PM PDT

That probably is a good idea, but this computer is so messed up, I don't think I'll ever clean it. (Also its never connected to the internet, so I doubt its hosting anything anymore.) I'll probably destroy the thing when I'm done with it!


The thing that intrigues me is this duplicate file structure. I've been googling around and it seems this is not as uncommon as I thought.

So I wonder, the internet history that is found in the duplicate files... Is this data the trojan steals? Just really curious how this works.

- Collapse -
Sounds like a classic test bed
Oct 21, 2016 1:17PM PDT

For a full wipe and reinstall. Or Linux or ChromeOS. I really thing the ChromeOS can be a safe way to let users flail away on bad sites with no known infections or viruses.

- Collapse -
what is a test bed?
Oct 21, 2016 1:56PM PDT

Could you explain a bit, please?

- Collapse -
A PC that
Oct 21, 2016 2:44PM PDT

You can try out new (to you) stuff.

- Collapse -
Put Linux on it then.
Oct 21, 2016 2:10PM PDT
- Collapse -
Answer
Re: strange files
Oct 21, 2016 12:28PM PDT

I'd first uninstall/remove all malware and delete everything in Local Settings\Temp (for all users) and Windows\Temp (some file are in use and can't be deleted, maybe even after booting in Safe Mode).
Then see if they come back and when they come back.