specific hidden files?

Discussion in 'Malware Help (A Specialist Will Reply)' started by tamar, Dec 18, 2005.

  1. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    If you are wanting to do a Clean Install of your OS, that is your call.

    I would not do an upgrade to XP with the problems you are currently having, it may very well make things worse.

    You don't need 98 installed on teh hard drive to install XP using the upgrade CD, you just need the 98 CD available for when XP checks fora valid OS.

    Whater ever you do; do a Clean Install not an Upgrade install of XP.
     
  2. tamar

    tamar Private First Class

    It's mostly a matter of time... I would prefer to track down and resolve the problem but I'm already two weeks behind with work with deadlines looming.

    Thanks for your advice over clean install not upgrade of XP, and that it doesn't have to be installed first which I would have presumed...

    Thanks also for all your advice over the last week or more which definitely helped, and sorry that I can't see it through. Though it will be a few days before I can do a new OS install, so if anything gets much worse in that time I'll be back!
     
  3. tamar

    tamar Private First Class

    SPD - no need for a response, but in case it helps someone somewhere else I thought I'd give a quick roundup of what's happened on my system since 'dropping off' and before clean-installing XP tomorrow (which the friend who built the machine will do, I know my limitations...)

    Nothing detected in any updates. But the F-Prot update directly after windows announced the recent patch they had a new engine as well as defs. Downloaded engine twice, both times install cut out after about 40% and during that 40% kept stopping and starting. I tried again a day later, it was fine for the engine, but during the subsequent definitions ZoneLab indicated attempted port hacks at 1 or more a second sustained over the 10-11 mins of download. Didn't happen last time.

    Spyware doctor downloads are OK. But still causes hanging at shutdown sometimes, even after reinstall. Sometimes clicking the desktop icon it initiates (checks a drive noisily) but then goes back to sleep. Launching from the taskbar icon works fine, but sometimes it disappears altogether for no reason. Once even more icons disappeared.

    I thought I had uninstalled/removed all the anti-malware software I had downloaded via the sticky and after. On finding some back there checked again, carefully manually. But - I am sure I didn't miss it - the bdoscan exe and a related BDOscan was back in the C/windows file. I have deleted again, rebooted a few times, it's not back currently. But I'm sure reappeared itself. It was the first scanner I downloaded when following the sticky (I think), and had real problems.

    Sometimes on bootup config files are being updated, for no reason i'd expect.

    Have run HJT several times - shows everything clean.

    sfc /scannow still not working, also stumbled across a windows troubleshooter - lots of questions there - answer pages are blank!

    The 'specific hidden files' still show during the spyware scan. After I've got XP running I will come back on that and let you know if they are still there or not.

    Many thanks again for your help a few weeks ago. I learned a lot and that I know so little!
     
  4. tamar

    tamar Private First Class

    Still having trouble following two XP clean installs... aagh!

    First install done by friend, using m/board driver updates he downloaded onto CD. One of these drivers went onto a floppy on my system, directly from CD to floppy - for use during install.

    Install of XP went fine. Downloaded Spyware Doctor and F-Prot. SD scan showed clean until next download ZoneAlarm Firewall free (I'm referring specifically to 'hidden files'). Read all the licenses first, and gather that garbage on your system is what you agree to, along with that firewall. Can hardly believe how much was downloaded! So, taking instructions by phone from my friend, I began a new XP install myself including re-reformatting the partition. (I have 3 partitions, C for drivers & windows, D for programmes, E for data files - only C was initially repartitioned. D was done after first install before any other downloads and is still empty, E is left as before).

    But this time needed to use my m/board etc driver update downloads on CD, done while still on Win98. Perhaps stupidly I also saved the new Spyware doctor and F-Prot downloads onto CD, and re-installed from these. Did the Windows updates first this time - at least I thought I had, then found there were more to download.

    The 'hidden files' are still showing in spyware doctor's disc scan - presumably via the drivers CD, and getting there from Zone Alarm's 'partner programmes'. If you know this to be wrong, please say so, don't want to accuse what I thought good software wrongly. The first attempt to burn the drivers to CD didn't go through, the second did but my friend noticed options had changed themselves in the software (Ahead Nero) - something I had suspected when making 'emergency' backup files of my data a few weeks ago.

    Anyhow, I didn't include ZA in this new install, nor did the licence say that their partner programmes could copy themselves invisibly to any CD I made, and then on to anywhere else. So this time around they aren't "legit".

    Checking email in Mailwasher Pro, I see spam only coming to both my addresses under mail@ not all other sorts of names@ that I got before clean install. I always wondered if "I" was generating my own spam.

    Have since run sfc /scannow several times (yes it works this time!). It picks up many files changed since first install - as requested I put the disk back and let the reverts go through. The second and subsequent runs still asked for the CD and reverts. Then thought they might be the windows updates and not corrupt files - windows updates site says all critical updates are installed (but are they all functioning correctly?). Deleted a couple and reinstalled them just to be sure (but am still not sure, mainly because they aren't showing in hjt logs, like before).

    On the 3rd or 4th run and only then, a file was listed as corrupt and unreadable: WINDOWS\system32\dllcache\typeperf.exe

    Obviously have learnt a lot through all this install business, including depths of my ignorance, eg playing with tools I don't understand like sfc /scannow.

    So, can I ask for advice on what to do to get rid of those programmes?

    Also, whether using sfc scannow and 'reverting' files has disabled any windows updates? (My own test - I can see pics displayed in the preview pane of OE).

    Many thanks in advance and sorry it's a long message!
     
  5. tamar

    tamar Private First Class

    realised after writing that last post that I need to do another clean install without using my driver update CD, or any CD that was in my system before. Fresh download of everything.

    Sorry to have taken up time unnecessarily.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds