Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Toughest nut to crack.


  • Please log in to reply

#1
IO-error

IO-error

    Member

  • Member
  • PipPipPip
  • 276 posts
Hi fellow geeks and tutors.

A few days ago I noticed I still had a persistent spy-/malware problem.
I'm unsure how to move on next. As buying a new harddisk is apparently the only way.
I changed harddisks four times now and it apparently installed itself as a rootkit on all of my harddisks and USB-sticks.

No scanner can find it, so I'm unsure what to do now.
I infected two other systems with this, which were first offline, but when I put it online, it also showed the same strange logs that my pc produced.
I'm throwing away the usb-stick as a precaution.

I'll include a logfile that I mined with Microsoft Network Monitor.
It also shows some other data, which is or might be privacy sensitive.
I don't censor them, because it might be related.

In the logfile you'll see a bunch of lines with DNS:QueryId = 0x1AF5, QUERY (Standard query)
They all go to websites that keep track of IP's and the visitor's time/amount.
There is no doubt about it, it's malware, written to visit websites to produce fake views.

I already scanned with every software you could image and I am willing to try each new program.
But if nobody can come up with something that fights new-age spy-/malware, then I would need to do buy a new harddisk.

Attached Files


  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP