Security Basics mailing list archives

Re: Strange files on C:\


From: John Groth <johng () purdue edu>
Date: Thu, 10 Jun 2004 15:02:20 -0500

I'm sorry I don't know what those files are but I do have a suggestion for you.

You said you used the sysinternals tool process explorer right?

Why not use one of their other tools, filemon?

Set it up on that machine, have it filter out all file access other than what you're interested in. I'd say filter out all but "C:\t*" and it can capture all access to those files or file creation in that folder. See what process is doing it. That should give you a start.

Good luck.

~johng

Di Fresco Marco wrote:

>
Do you have any idea from where these files came from? Is there any
other tool/procedure I can try to identify them?

Thank in advance.



Di Fresco Marco
http://home.comcast.net/~superdif/


---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off any course! All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. Visit us at: http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


Current thread: