Our November Competition
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Operating Systems » Windows XP/2000
Register for a Free Account

Windows XP/2000 - [Fixed] Some questions... posted in the Operating Systems forums; For a couple months I have been ridiculously paranoid about my computer being hacked and I can't even remember why anymore, but there have been signs in the past. 4 ...


Reply
Free PC Performance Scan
Old 11-27-2006   #1
Silver Member
 
Join Date: Nov 2006
Posts: 100
Unhappy [Fixed] Some questions...

For a couple months I have been ridiculously paranoid about my computer being hacked and I can't even remember why anymore, but there have been signs in the past. 4 things came up on RootkitRevealer which just finished scanning a few minutes ago, I sometimes get something similar to "IRQL_Not_Equal" when trying to boot Windows, my computer has been running very slow compared to usual and sometimes freezes, and my internet randomly shuts off or slows down sometimes. I have Freedom, Spy Sweeper, Avast Anti-Virus, McAfee Firewall, McAfee Privacy Service, and McAfee Virus scan on this computer and none of them are warning me of anything. I am willing to do whatever it takes to just fix whatever is going on and make sure it doesn't happen again. If it is relevant, there is also another computer on my network. It is my mother's Windows XP Pro.

Soon I am going to format my hard drive and reinstall Windows. As far as I know, this should get rid of any rootkits or viruses or anything really causing me problems. So:

1) If I do format my HDD and reinstall Windows XP, would any possible hackers currently in my system still have any access to my system in any way after the format and reinstall?

2) If not, what are some things you guys would recommend doing to make my PC as secure as possible?
If the hacker would still have access to my system, what should I do?

Thank you so much to anyone who responds. I can't deal with these things anymore, and I am ready to do ANYTHING I have to do make and keep my computers secure. This is a wonderful site and I commend everyone here who helps.

Last edited by Wolfdue387; 11-27-2006 at 03:19 AM.
Wolfdue387 is offline   Reply With Quote
Advertisement - Register to Remove

Old 11-27-2006   #2
Tech Member
 
Arctos's Avatar
 
Join Date: Sep 2006
Location: Bundaberg, Australia
Posts: 3,707
PC Experience: RTM Assoc. Dip.
Default

Download the Sophos Anti Rootkit, this will detect and remove any rootkits it find's.

If you do reformat reinstall, make sure your intenet connection is disabled till you have your firewall and antivirus software installed. Once you have these installed reconnect to the web and download all Microsoft updates, and the latest av definiton updates.
Arctos is offline   Reply With Quote
Old 11-27-2006   #3
Silver Member
 
Join Date: Nov 2006
Posts: 100
Default

Originally Posted by Arctos
Download the Sophos Anti Rootkit, this will detect and remove any rootkits it find's.

If you do reformat reinstall, make sure your intenet connection is disabled till you have your firewall and antivirus software installed. Once you have these installed reconnect to the web and download all Microsoft updates, and the latest av definiton updates.
Thanks a ton. I'll use that program and see if it helps anything. If my enormous paranoia still bothers me, I'll reformat and reinstall, and I'll keep your advice in mind.
Wolfdue387 is offline   Reply With Quote
Old 11-27-2006   #4
Silver Member
 
Join Date: Nov 2006
Posts: 100
Default

Here are the results of my scan:

"Warning: Failed to flush drive \\.\C:. Registry scan may produce invalid results. The process cannot access the file because it is being used by another process."

"Warning: Registry call timed out - it may be blocked by malware. Please try again after a clean up and restart."

"Area: Windows registry
Description: Hidden registry value
Location: \HKEY_USERS\S-1-5-21-846320298-2487099434-1340660822-1006\Software\Microsoft\Windows\CurrentVersion\Exp lorer\TrayNotify\PastIconsStream
Removable: No
Notes: (type 3, length 102400) "\x14 \x05 \x01 \x01 \xbe\x03 \x14 IL \x06\xbe\x03\xc1\x03\x04 \x10 \x10 \xff\xff\xff\xff! \xff\xff\xff\xff\xff\xff\xff\xffBM6 6 ( \x10 \x10<" ... "\xcb\xff\xcf\xa7s\xff\x06\x06""

I don't have the option to Clean Up Checked Items. What should I do?
Wolfdue387 is offline   Reply With Quote
Old 11-28-2006   #5
Silver Member
 
Join Date: Nov 2006
Posts: 100
Default

Well, guys. I decided what I wanted to do. I'm going to format my external harddrive so there is no chance of a virus or rootkit on it, put all the information on it that I need, and then use system restore so it's like my system is brand new. I definatly appreciate the help you guys have given me anyway, though. Don't think I don't. I would consider being a mod or something here, just because you guys are so awesome and I feel that you guys deserve all the help you can get. Thanks.
Wolfdue387 is offline   Reply With Quote
Old 11-28-2006   #6
PCHF Founder & Owner
 
Hengis's Avatar
 
Join Date: Jan 2004
Location: The PCHF Bunker
Posts: 14,069
PC Experience: Microsoft Certified Professional
Default

Kind words indeed, we sure appreciate them
__________________
Hengis is online now   Reply With Quote
Old 11-28-2006   #7
Elite Member
 
Join Date: Mar 2006
Posts: 413
Default

You might want to follow the prework link in Hengis`s signature, and let the security team help you get rid of any infections you have. If i understand what youre going to do, transfer your data to an external drive, then do a system restore on your boot drive??? System restore wont get rid of the infection(s) , and its possible to reinfect your boot drive if you transfer the data back to it after a clean install. Something may be hiding in some of those files. Just a suggestion because, ive been there , done that, and have the tshirt. LOL
__________________
Every day we live, we`re one day closer to death! Learn to live, live to learn.

Of all the things ive ever lost, i miss my mind the most.

Life is full screen, movies should be too!!!
PREWORK
AFTERWORK
uncleed is offline   Reply With Quote

Reply

Bookmarks

Tags
fixed, questions

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 01:25 PM.
Powered by vBulletin
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2