Log in

View Full Version : Need an Explanation, Please


NineOfSix
07-04-2010, 02:16 PM
<p>So, I was doing my Sunday PC maintence and while running a deep scan on my AV software I happened to look at the monitor and saw something that alarmed me. I saw that is was scanning a directory called "C:WindowsSystem32TestServer". Of course, seeing server anything in my system directory raised a brow so I investigated. It seems there is almost 13 gigs of data stored here and it seems to be EQ2 stuff. I've played on the Test Server before and it's always lived in the "C:ProgramDataSony Online EntertainmentInstalled GamesEverQuest IITestServer" directory.</p><p>Can anyone tell me what this is? That's a whole lot of data written with a whole lot of exe files in an area for a product I didn't authorize to write into. I am running Windows 7 Enterprise. Thanks for any insight into this. </p>

Pervis
07-04-2010, 03:09 PM
<p>As a guess, at some point you accidently installed the test server client to that directory.</p>

NineOfSix
07-04-2010, 03:15 PM
<p>Perhaps. I don't deny that it might have happened that way; however, I have installed for Test before and these files are foreign to me.</p><p><strong>Files like:</strong><ul><li>append.exe</li><li>appidpolicyconverter.exe</li><li>certreq.exe</li><li>eudcedit.exe</li></ul></p><p><strong>And directories like:</strong><ul><li>NetworkList</li><li>icsxml</li><li>bg-BG</li><li>Boot</li></ul></p><p>Just doesn't look like it did a year ago when I had to do it manually. </p>

Wingrider01
07-05-2010, 10:16 AM
<p><cite>NineOfSix wrote:</cite></p><blockquote><p>Perhaps. I don't deny that it might have happened that way; however, I have installed for Test before and these files are foreign to me.</p><p><strong>Files like:</strong></p><ul><li>append.exe - <strong>listed as a microsoft executable</strong></li><li>appidpolicyconverter.exe - <strong>listed as a Microsoft executatable, present with a MS digitial signature</strong></li><li>certreq.exe - <strong>listed as a microsoft executable, present with a MS digitial signature</strong></li><li>eudcedit.exe - <strong>defines as end user character editor, can be valid but also can be a inidication of pws.qqpass.c trojan, present with a MS digitial signature</strong></li></ul><p><strong>And directories like:</strong><ul><li>NetworkList</li><li>icsxml</li><li>bg-BG</li><li>Boot</li></ul></p><p>Just doesn't look like it did a year ago when I had to do it manually. </p></blockquote><p>The directories are present on 3 other Windows 7 machines that I have, the code that is contained inside of some of the directory detial out to Microsoft OS related directories. Checked the executables, all are present on the 3 machines, 3 had MS digital signatures the one that did not was append.exe, but thie has been present since the dos days</p><p><a href="http://technet.microsoft.com/en-us/library/cc731163(WS.10).aspx">http://technet.microsoft.com/en-us/...163(WS.10).aspx</a></p><p>An executable in question you can right click then select properties, then the Signature tab to get an idea of who owns it, most, if not all of the MS supplied files will have their digitial signature present</p>

Shareana
07-06-2010, 11:23 AM
<p>Ok now..  It is cleaned up without the arguements and opinions on advice given <img src="/smilies/8a80c6485cd926be453217d59a84a888.gif" border="0" alt="SMILEY" /></p><p>Please keep in mind thatthese forums SHOULD be a place to come with issues and questions without fear of being insulted.  Thank you!</p>