View Single Post
Old 02-28-2007, 05:40 AM   #42 (permalink)
amateur
Moderator, Analyst, Security Team ; Rangemaster, TSF Academy
 
amateur's Avatar
 
Join Date: Jun 2006
Location: USA
Posts: 7,508
OS: XP SP3


Hi,

Quote:
I ran the chkdsk and fix dsk program again and it found more problems. it had only been one day and I hadn't used my systme but to try to resolve these problems. I haven't been online since because I'm now worried about losing my harddrive entirely.
The errors reported by chkdisk indicate damage/corruption on the hard disk.

I have been re-reading your previous posts in other forums as well as this one. Looks like you've been having system problems/errors all along and chkdisk keeps giving more errors. There appears to be two different issues in our hands: one is a currupt hard disk which we cannot do anything about, it would be a hardware problem and I would suggest you visit the hardware forum for it; second is the malware (virus, spyware, adware, trojans, etc.) issue.
There is also a couple of points that I would like to bring up.

One is that you are and have been using an unpatched operating system, i.e. XP SP1. If you have not upgraded to Windows XP SP2 then you have been doomed to be infected. There have been hundreds of exploits used to infect your system and Microsoft issues patches monthly via Windows Update. Simply connecting to and browsing the net will get you infected if you have not kept your system patched. Not patching your system not only keeps your system infected but allows it to be used to spread infections and allows hackers to use your system for their criminal deeds. It is your duty as an internet citizen to keep your system patched. Having said all that, I would also point out that an infected system must be cleaned before updating to SP 2. Dr. WebCurit and SysClean did not find any problems, but your TrendMicro did. If you still don't want to reformat & reinstall and continue to try to clean up (which can never be guaranteed with the kind of infection you had) I would like you to download ONE of each of the following antivirus and firewall software to your desktop (using the "save" option). Then, disconnect from the internet, go to Start>Control Panel>Add/Remove Programs and remove all TrendMicro products. Next, go back to the desktop click on the setup icons of the AV and the firewall applications you've downloaded and intall them. Re-connect to the internet and update your new antivirus application. Run a full system scan and let me know if you're still receiving the virus alerts.

AVG Free here
AntiVir here
Avast here

Make sure that you have only ONE antivirus running on your computer

firewalls:
ZoneAlarm here
Sygate here
Kerio Personal Firewall here

Make sure that you have only ONE firewall running on your computer

Second issue is the fact that there is a certain key in the windows registry that is not showing in any of your logs, be it in this thread or the previous ones.

Please click HERE
(Use Internet Explorer ONLY !! Firefox or other browsers wont work)

Click on Windows Validation Assistant on left
Click on the Validate Now button.
Be patient while the ActiveX loads, do not click on any links.
Read the instructions on this page while it's loading
You will be prompted to install - click YES
Enter your Product key
To Find Key :Click Start, right-click My Computer, and then click Properties On the General tab, under Registered to, enter that number
Then click Continue
When it says "Validation Complete" please click Continue to return to your previous activity
Copy what it says and paste it here please.

Quote:
I very much appreciate all of your help here and sticking through this even though your best judgement was that I should reformat and reinstall. I take full responsibility for my decision to try to fight the virus instead. When I finally get this situation fixed, I'll be back to contribute something for all your hard work.
I am not familiar with x-cleaner. Therefore, I cannot make any comments on it. This page has some info on it. It just doesn't look like a product that would cause the kind of problems you've been having.

Quote:
I was looking over some of the info you gave me about reformatting and i see that some virus' can survive reformatting, specifically boot virus'. do I have one of those? is there any way to know?
I honestly don't know. I would like to quote my earlier statement:

Quote:
We can clean the infections. But even with doing so I, unfortunately, cannot guarantee the security of your computer afterwards as I have no way of knowing what other damage has been done by the RootKit/RAT.
__________________
My services are free. However, you can donate to TSF to help keep it running.




Member of ASAP since 2005
Member of UNITE since 2006
amateur is offline