Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Community Forums
 Community Discussions (All other subjects)
 40 GB Control Panel in Win 2k????
 New Topic  Topic Locked
 Printer Friendly
Next Page
Author Previous Topic Topic Next Topic
Page: of 2

redbrad0
Advanced Member

USA
3725 Posts

Posted - 12 July 2004 :  00:06:21  Show Profile  Visit redbrad0's Homepage  Send redbrad0 an AOL message
I got on one of the servers tonight and was just cleaning some things up when I noticed the C drive only had 20 GB of free space left. I knew this could not be the case so I starting going thru all the folders trying to pin down where the large file was. As you can see from the image below in C:\WINNT\system32\drivers\etc there is a dir for Control Panel which I know is not the location of this and if I right click on it tells me its 42.1 GB and if I double click on the file it takes me into my control panel. Does anyone have any idea on this?


Brad
Oklahoma City Online Entertainment Guide
Oklahoma Event Tickets

Nathan
Help Moderator

USA
7664 Posts

Posted - 12 July 2004 :  03:57:35  Show Profile  Visit Nathan's Homepage
Thats not even supposed to be there.

Right clik and go to explore, it says it has 3.3K files in it and 323 folders, what could those be.

Nathan Bales
CoreBoard | Active Users Download
Go to Top of Page

HuwR
Forum Admin

United Kingdom
20600 Posts

Posted - 12 July 2004 :  04:39:32  Show Profile  Visit HuwR's Homepage
sounds like someone has hacked into you server, use taskmanager to see if there is anything running that you do not recognise
Go to Top of Page

redbrad0
Advanced Member

USA
3725 Posts

Posted - 12 July 2004 :  08:36:20  Show Profile  Visit redbrad0's Homepage  Send redbrad0 an AOL message
quote:
Originally posted by Nathan

Thats not even supposed to be there.

Right clik and go to explore, it says it has 3.3K files in it and 323 folders, what could those be.



If I right click on the file or double click on the file I get what looks like the control panel which you can see at this image below.


Brad
Oklahoma City Online Entertainment Guide
Oklahoma Event Tickets
Go to Top of Page

HuwR
Forum Admin

United Kingdom
20600 Posts

Posted - 12 July 2004 :  09:03:12  Show Profile  Visit HuwR's Homepage
I still stick by my last statement, your server has been hacked.

The control panel does not physically exist, there is NO control panel directory, the control panel apps sit in system32 directory and are called *.cpl

the C:\WINNT\system32\drivers\etc directory should have very few files in it if any
Go to Top of Page

redbrad0
Advanced Member

USA
3725 Posts

Posted - 12 July 2004 :  10:19:23  Show Profile  Visit redbrad0's Homepage  Send redbrad0 an AOL message
That was my first thought Huw, and I am looking at all the things in the Task Manager now but here is a screen shot.


Brad
Oklahoma City Online Entertainment Guide
Oklahoma Event Tickets
Go to Top of Page

redbrad0
Advanced Member

USA
3725 Posts

Posted - 12 July 2004 :  10:41:50  Show Profile  Visit redbrad0's Homepage  Send redbrad0 an AOL message
Sorry I just updated the process image above to show processes from all users.

Brad
Oklahoma City Online Entertainment Guide
Oklahoma Event Tickets
Go to Top of Page

HuwR
Forum Admin

United Kingdom
20600 Posts

Posted - 12 July 2004 :  13:09:42  Show Profile  Visit HuwR's Homepage
i made my statement mainly because the C:\WINNT\system32\drivers\etc is quite often used as an ftp root by hackers who have managed to get in, although I can't see anything that looks out of place, it doesn't mean there isn't they could be hiding behind one of the svchost instances.

Also take a look in your registry and see if there is anything you don't recognise in the \run folders, and run through the service list to make sure nothing strange is there either
Go to Top of Page

HuwR
Forum Admin

United Kingdom
20600 Posts

Posted - 12 July 2004 :  13:17:19  Show Profile  Visit HuwR's Homepage
There are also many Trojans which use this directory to drop their payloads into
Go to Top of Page

redbrad0
Advanced Member

USA
3725 Posts

Posted - 12 July 2004 :  14:26:06  Show Profile  Visit redbrad0's Homepage  Send redbrad0 an AOL message
Thanks huw for your information I will look into all of this today or tonight and will post back on what I see.

Brad
Oklahoma City Online Entertainment Guide
Oklahoma Event Tickets
Go to Top of Page

Gremlin
General Help Moderator

New Zealand
7528 Posts

Posted - 12 July 2004 :  18:37:38  Show Profile  Visit Gremlin's Homepage
Don't forget it is actually possible for programs "root kits" to completely hide themselves from the task manager too, so funny things often won't turn up there.

Use some of the tools over at sysinternals like filemon etc to see if you can see anything accessing that "file"

http://www.sysinternals.com/ntw2k/utilities.shtml

Kiwihosting.Net - The Forum Hosting Specialists
Go to Top of Page

redbrad0
Advanced Member

USA
3725 Posts

Posted - 12 July 2004 :  19:26:47  Show Profile  Visit redbrad0's Homepage  Send redbrad0 an AOL message
quote:
Originally posted by Gremlin


Use some of the tools over at sysinternals like filemon etc to see if you can see anything accessing that "file"

http://www.sysinternals.com/ntw2k/utilities.shtml



Well its really not a file, its a directory. Its a really odd thing.

Brad
Oklahoma City Online Entertainment Guide
Oklahoma Event Tickets
Go to Top of Page

redbrad0
Advanced Member

USA
3725 Posts

Posted - 12 July 2004 :  19:33:37  Show Profile  Visit redbrad0's Homepage  Send redbrad0 an AOL message
Just looked at the dir in DOS and saw this...


Brad
Oklahoma City Online Entertainment Guide
Oklahoma Event Tickets
Go to Top of Page

RichardKinser
Snitz Forums Admin

USA
16655 Posts

Posted - 12 July 2004 :  20:40:29  Show Profile
rename the directory in the Command Window and remove everything after the word Panel. Then you should be able to open the directory using Explorer.
Go to Top of Page

gpctexas
Junior Member

320 Posts

Posted - 12 July 2004 :  21:14:11  Show Profile  Visit gpctexas's Homepage
MSN uses directories like that, right clicking them and clicking explore can get you into them too. At on on Win XP it can.

ipgate 2.4.4 RC3
http://www.gpctexas.net/ipgate_v244.zip
Go to Top of Page

sr_erick
Senior Member

USA
1318 Posts

Posted - 12 July 2004 :  23:13:58  Show Profile  Visit sr_erick's Homepage  Send sr_erick a Yahoo! Message
I renamed the directory in DOS. Wow for losts of junk in there. There must have been a trojan on there (that would explain such high bandwidth usage at that time) but it's been long removed. There are things in there having to do with speedtests to other countries, etc....lots of files and generally a lot of stuff. I'm sure there is a lot of pirated things in a lot of those folders as well.




Erick
Snowmobile Fanatics

Go to Top of Page
Page: of 2 Previous Topic Topic Next Topic  
Next Page
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.36 seconds. Powered By: Snitz Forums 2000 Version 3.4.07