Trying to Make Sense of Strange Folder in C:\WINDOWS

Trying to Make Sense of Strange Folder in C:\WINDOWS

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Trying to Make Sense of Strange Folder in C:\WINDOWS Will 06-29-2008
Posted by Will on June 29, 2008, 7:23 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I have a very strange looking folder under my C:\WINDOWS folder, which if it
is not a trojan then it must be some kind of device driver install that went
very bad. I would like help identifying what it might be.

The folder is named:

C:\WINDOWS\EFUZEJYDIXC1AZ4D

and it contains copies of many Windows system files. The contents of this
folder are posted here:

http://pages.uschw.com/usenet/EFUZEJ-folder/folder-contents.txt

Of special note is a logfile in that folder whose name and contents are
linked here:

http://pages.uschw.com/usenet/EFUZEJ-folder/sthdae.log

You may want to open that logfile in an editor other than NOTEPAD that can
hand LF only at the end of each line. Word 2003 opened it fine here.

In that logfile I see attempts to add device drivers, that are failing with
various messages about an invalid pin. That almost looks like Bluetooth?

What I find most suspicious about this folder is that it copies over so many
critical Windows system files. Why would any device installation need its
own private copies of those files?

--
Will



Posted by Malke on June 30, 2008, 7:30 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Will wrote:

> I have a very strange looking folder under my C:\WINDOWS folder, which if
> it is not a trojan then it must be some kind of device driver install that
> went
> very bad. I would like help identifying what it might be.
>
> The folder is named:
>
> C:\WINDOWS\EFUZEJYDIXC1AZ4D
>
> and it contains copies of many Windows system files. The contents of
> this folder are posted here:
>
> http://pages.uschw.com/usenet/EFUZEJ-folder/folder-contents.txt
>
> Of special note is a logfile in that folder whose name and contents are
> linked here:
>
> http://pages.uschw.com/usenet/EFUZEJ-folder/sthdae.log
>
> You may want to open that logfile in an editor other than NOTEPAD that can
> hand LF only at the end of each line. Word 2003 opened it fine here.
>
> In that logfile I see attempts to add device drivers, that are failing
> with
> various messages about an invalid pin. That almost looks like Bluetooth?
>
> What I find most suspicious about this folder is that it copies over so
> many
> critical Windows system files. Why would any device installation need
> its own private copies of those files?
>

And what results do you get when you do virus/malware removal scanning?
http://www.elephantboycomputers.com/page2.html#Removing_Malware

Malke
--
MS-MVP
Elephant Boy Computers - Don't Panic!
FAQ - http://www.elephantboycomputers.com/#FAQ


Posted by MARK TURNER on July 2, 2008, 12:08 am
If you were  Registered and logged in, you could reply and use other advanced thread options
i have vista ultimate 64 bit and have trouble with CA INTERNET SECURITY
SUITE,it is a virus and spyware program from road runner you get free.it is
32 bit and i cannot get the virus protector to work right.i chatted online
with a ca helper and he said i have to upgrade to vista 32 bit.is there
another way to get it to work without upgrading?

mark0325

>I have a very strange looking folder under my C:\WINDOWS folder, which if
>it
> is not a trojan then it must be some kind of device driver install that
> went
> very bad. I would like help identifying what it might be.
>
> The folder is named:
>
> C:\WINDOWS\EFUZEJYDIXC1AZ4D
>
> and it contains copies of many Windows system files. The contents of
> this
> folder are posted here:
>
> http://pages.uschw.com/usenet/EFUZEJ-folder/folder-contents.txt
>
> Of special note is a logfile in that folder whose name and contents are
> linked here:
>
> http://pages.uschw.com/usenet/EFUZEJ-folder/sthdae.log
>
> You may want to open that logfile in an editor other than NOTEPAD that can
> hand LF only at the end of each line. Word 2003 opened it fine here.
>
> In that logfile I see attempts to add device drivers, that are failing
> with
> various messages about an invalid pin. That almost looks like Bluetooth?
>
> What I find most suspicious about this folder is that it copies over so
> many
> critical Windows system files. Why would any device installation need
> its
> own private copies of those files?
>
> --
> Will
>
>


Posted by David H. Lipman on July 2, 2008, 6:33 am
If you were  Registered and logged in, you could reply and use other advanced thread options

| i have vista ultimate 64 bit and have trouble with CA INTERNET SECURITY
| SUITE,it is a virus and spyware program from road runner you get free.it is
| 32 bit and i cannot get the virus protector to work right.i chatted online
| with a ca helper and he said i have to upgrade to vista 32 bit.is there
| another way to get it to work without upgrading?

| mark0325


Remove it and replace it with a Win64 compliant AV solution.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Similar ThreadsPosted
How do I make windows sec. center detect my own developed antiviru September 30, 2007, 6:46 pm
Serach, organise folder windows keep opening while using internet March 28, 2006, 7:52 am
Strange Windows 2000 Sever behaviour! Many problems. January 14, 2007, 10:50 pm
HELP BACKLIGHT DETECT STRANGE HIDDEN FILE(SEVERE WINDOWS 2000 INFECTION) February 2, 2007, 3:17 am
Re: Make 1 Million Dollars $$$ August 13, 2005, 1:52 pm
Re: Make 1 Million Dollars $$ August 14, 2005, 12:28 pm
Re: Make 1 Million Dollars $$ August 14, 2005, 10:51 pm
Re: I thought computers were supposed to make life easier.... May 24, 2008, 9:10 am
Folder sounds February 14, 2008, 3:13 pm
Re: Folder.htt & Desktop.ini Virus July 1, 2005, 11:11 am

The site map in XML format XML site map

Contact Us | Privacy Policy