what is the "!" folder

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jhcochran, Jul 13, 2008.

  1. Jhcochran

    Jhcochran Private E-2

    I have a cpu I'm working on. Friend says they uninstalled Limewire, then bluescreened "Unmountable boot volume. Repaired MBR with recovery console, cpu starts again. Upon starting, I was amazed at the popups, without even opening ie. Started the usual scans, ad aware, ewido, spybot, etc.. Thing is that each started finding spyware in the folder c:\documents and settings\user\! What is the "!"? There are three users on this cpu, each user finds the same spyware, all of which are porn movie names starting with the letter "A" and going to "Z". The removal tools find so many that it causes the app to stop responding. Ewido ran for 17 hours, found over 100,000 traces, but locked up. It found it as "downloader.getcodec.b" with the 100,000 traces. I ran trojan hunter, which removed two trojans and avast which removed some, tried running ad-aware again and it didn't show any files being scanned in the user\! directory. Thought I had it, but when I ran Stinger it was listing those porno files again as being scanned. Stinger came up clean, but the files seemed to still be scanned. Please help.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    That folder has showed up recently due to some malware infections. You can just delete them. I recommend that you do the below to properly clean this PC.


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. Jhcochran

    Jhcochran Private E-2

    Ok, so I haven't run combofix or superantispyware, but I have ran, Ad-Aware, Ewido, Spybot, Malwarebytes, spysweeper, spyware doctor, hijack this, vundofix, avast, f-prot, mcafee, panda antivirus, trojan hunter, and some more. I have ran a pretty good arsenal of apps through this pc. Ewido has since taken most of the files out. Completely gone for one user, then on the second user, it sees some of the traces but is not finding it as a problem. Back to the original question, is there no way to manually navigate to that directory and delete all the files? Thanks again.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Just do what you said. Manually navigate to the folder and delete it. If this does not work, then you need to follow my original instructions.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds