View Single Post
Old 08-09-2008   #12 (permalink)
ZeroDown!
Patriot Guard Rider - PA
BTK Intermediate
 
ZeroDown!'s Avatar
 
Join Date: Mar 2008
Location: York County, Pennsylvania
Posts: 270
Default

'Poke -

As a tech that troubleshoots virus crap on a regular basis (and wants to shoot the a$$hats responsible for them), never assume that it's totally clear.

If you've never heard of a program called a rootkit, bone up on them. Use several rootkit detecting programs to check for processes and services that are flying under the radar (below kernel level) that searching through XP and the drive by conventional means won't detect, and most if not all anti-virus / malware software programs can't detect, either.

For those that aren't 'puter savvy, if your PC starts acting a bit flaky all of a sudden, and at next restart starts to reboot itself constantly, you're probably infected with something that is trying to call back to another server; when it can't reach that server, it throws an error code that causes the system to fail and since most XP installs remain as default for the 'automatically reboot upon system failure', it will keep rebooting until it can get through.

Windows Sysinternals: Documentation, downloads and additional resources is a good site for utilities, especially the Rootkit Revealer.

F-Secure Blacklight > Rootkit Elimination Technology is another good one - Blacklight Revealer for rootkit detection.

Personally, if my system gets infected with anything, it's an immediate dump of my working files folder and the drive gets formatted. I've seen too much of the identity theft problems (I got that call from the bank saying "did you charge airline tickets in England yesterday? - NOT!) that I take no chances. Rootkits are a royal PITA x1000 - you're never sure if you've gotten everything and it's worth an hour to wipe out and rebuild the PC.

Just my $0.02 on the subject - hope it helps.....

ZD
__________________
"There is no distinctly native American criminal class...save Congress." -- Mark Twain
ZeroDown! is offline   Reply With Quote