Tag.sys files -- hacker?

Tag.sys files -- hacker?

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Tag.sys files -- hacker? Disciple 06-30-2006
Posted by =?Utf-8?B?RGlzY2lwbGU=?= on June 30, 2006, 3:41 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
On our lan, all our XP machines and even the server have a tiny file in the
root of c: called tag<computername>.sys, which increments every few days and
contains a single line: the date in yyyy-mm-dd format (ie, 2006-06-19). I
can't find any viruses or spyware on any of the machines, and they are
patched and scanned regularly. Anyone have any thoughts or ideas?
Thanks.

Posted by David H. Lipman on June 30, 2006, 4:03 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| On our lan, all our XP machines and even the server have a tiny file in the
| root of c: called tag<computername>.sys, which increments every few days and
| contains a single line: the date in yyyy-mm-dd format (ie, 2006-06-19). I
| can't find any viruses or spyware on any of the machines, and they are
| patched and scanned regularly. Anyone have any thoughts or ideas?
| Thanks.

Many *.SYS files are part of RootKits or Trojans employing RootKit Techniques.
Albeit, they
aren't usually in the root "C:".

Search the registry for TAG.SYS and report back your findings. Wheere it was
found, etc.

You may want to Export that branch (or branches) of the Registry where it is
found for
easier documentation.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by =?Utf-8?B?RGlzY2lwbGU=?= on July 11, 2006, 2:52 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Ok, I searched the registries for "tag" (w/o the quotes) on several machines
but couldn't find any mention of tag.sys (or tag"anything".sys) other than a
value called "tag" which appears repeatedly in
HKLM\SYSTEM\CurrentControlSet\Services in items like abiosdsk, acpi,
adpu160m, etc etc.

I also ran F-Secure Blacklight scan, as well as gmer.exe rootkit scan (only
works on XP) with no results.

I know whatever this is must still be active, because it eventually appears
on new machines as I load them, and has even jumped from our NT domain to our
new AD domain machines; the file dates keep incrementing as well.

I've run Stinger, Trend and LavaSoft on suspect machines -- all negative.

Thanks

"David H. Lipman" wrote:

>
> | On our lan, all our XP machines and even the server have a tiny file in the
> | root of c: called tag<computername>.sys, which increments every few days and
> | contains a single line: the date in yyyy-mm-dd format (ie, 2006-06-19). I
> | can't find any viruses or spyware on any of the machines, and they are
> | patched and scanned regularly. Anyone have any thoughts or ideas?
> | Thanks.
>
> Many *.SYS files are part of RootKits or Trojans employing RootKit Techniques.
Albeit, they
> aren't usually in the root "C:".
>
> Search the registry for TAG.SYS and report back your findings. Wheere it was
found, etc.
>
> You may want to Export that branch (or branches) of the Registry where it is
found for
> easier documentation.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Similar ThreadsPosted
think I may have been hijacked by a hacker... January 28, 2007, 3:05 pm
HELP! Chinese to Hacker-2 Monitor Worm. August 7, 2006, 6:58 pm
Strange behaviour of a virus or the hacker. February 13, 2008, 4:04 pm
X12-30107-DLM.EXE Virus or Hacker Hook October 16, 2008, 11:47 am
Zero kb files June 19, 2007, 12:08 pm
Re: Help with what to do with files August 15, 2007, 11:45 am
lost files July 1, 2005, 10:59 am
Something is blocking almost all .exe files! September 14, 2005, 2:05 pm
Files missing January 25, 2006, 3:46 am
Mystical files February 5, 2007, 12:47 pm

The site map in XML format XML site map

Contact Us | Privacy Policy