G
Guest
A month ago, a hacker got into my system and wiped clean all the data from
two computers -- and my automated backup hard drive. I have become something
of a madwoman about this, as you can imagine.
In the weeks since then, every security certificate I examine has an expired
date on it. This includes the ActiveX control for automated updates from
Microsoft!
I just ran the system recovery media on an Averatec computer that has not
yet been on the internet, and it has 25 compressed files that have names like
DSOExploit (and DSOExploit1, 2, 3, 4), or are tucked in a directory called
C:\program files\Spybot - Search & Destroy\updates, when Spybot Search and
Destroy has not been installed on this computer.
Another suspicious category is eight zip files with apparently identical
contents, each named a different combination of 8 alphanumeric characters,
filed in C:\windows\java\packages. So, for example, it's
C:\windows\java\packages\7BRR3PZV.
The thing that makes me really crazy is when I went into Recovery console
from a Windows XP disk, I am asked for an administrator password, and I did
not set an administrator password.
What I think is happening is that this is a very clever hijack program that
makes a copy of everything I have ever put on this computer. Thus, every
method I have used to reformat the hard drive (and believe me, I have used a
lot of different methods for this), or to control this menace, is copied as I
shut down, and when I reboot, they have engineered the program so as to make
it appear to work when it is not.
I just read this thread called "Security Problem?" and it sounds like this
is something that would be easy enough to do.
Or am I really just crazy?
Thanks!
two computers -- and my automated backup hard drive. I have become something
of a madwoman about this, as you can imagine.
In the weeks since then, every security certificate I examine has an expired
date on it. This includes the ActiveX control for automated updates from
Microsoft!
I just ran the system recovery media on an Averatec computer that has not
yet been on the internet, and it has 25 compressed files that have names like
DSOExploit (and DSOExploit1, 2, 3, 4), or are tucked in a directory called
C:\program files\Spybot - Search & Destroy\updates, when Spybot Search and
Destroy has not been installed on this computer.
Another suspicious category is eight zip files with apparently identical
contents, each named a different combination of 8 alphanumeric characters,
filed in C:\windows\java\packages. So, for example, it's
C:\windows\java\packages\7BRR3PZV.
The thing that makes me really crazy is when I went into Recovery console
from a Windows XP disk, I am asked for an administrator password, and I did
not set an administrator password.
What I think is happening is that this is a very clever hijack program that
makes a copy of everything I have ever put on this computer. Thus, every
method I have used to reformat the hard drive (and believe me, I have used a
lot of different methods for this), or to control this menace, is copied as I
shut down, and when I reboot, they have engineered the program so as to make
it appear to work when it is not.
I just read this thread called "Security Problem?" and it sounds like this
is something that would be easy enough to do.
Or am I really just crazy?
Thanks!