Question About Deleting Files

Discussion in 'Malware Help (A Specialist Will Reply)' started by Chris_S, Mar 14, 2005.

  1. Chris_S

    Chris_S Private E-2

    Just wondering if it's possible that a CWS variant (or any other nasty sort of thing) could create phony modified and/or created dates. Looking through my WINNT and System32 folders, there's a bunch of seriously shady looking executables and DLLs. The reason I ask is that I'm certain that at least one point (before I ran through the proper steps) the about:blank hijack was pointing to a DLL with a modified/creation date a week or two older than when the problem came up. Then again, who knows how long some of this stuff had been hiding.
    Do you suppose zipping questionable files is a way to go? I figure that way they can't do any harm where they're at, and if I accidentally delete a legitimate file, I can restore it easily enough.
    Thanks,
    Chris
     
  2. Chris_S

    Chris_S Private E-2

    Well, I guess I've had some of this spyware for a little longer than I thought. At least no problems rebooting after zipping/deleting 170 or so various exes and dlls. :cool:
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HSA and about:blank hijackers are notorious for creating many files in a variety of folders. They have been known to create randomly named files with the following extensions .EXE, .DAT, .DLL, .INI, .DAT, and .TXT.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds