PDA

View Full Version : Hacked - hidden files in recycler directory


wmann
06-06-2006, 01:58 PM
I have been hacked! I discovered 41GB of hidden files in a recycler directory :mad:

The files do not show even after the view is changed to display hidden and system files. They were discovered while reviewing backups where they do show. When the attrib is changed they show now and they seem to be movies and games.

There is a directory that is called "hack by gaucci"

The files are older, before we added a new firewall.

Anyone know about this? :confused:

Please advise....Thanks!

mjc
06-06-2006, 02:29 PM
Well, it looks like are/were an unwitting file server.

The first thing would be to disconnect the machine from the internet, for as long as it take to purge the files.

Then get Blacklight (http://www.f-secure.com/blacklight/try.shtml) and run it...

Also post a HijackThis (http://www.merijn.org/files/hijackthis.zip) log.