Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 20 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Otherarrow shadow copies and virus???
EH-Net
May 25, 2013, 05:46:19 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: shadow copies and virus???  (Read 2110 times)
0 Members and 1 Guest are viewing this topic.
mkochendorfer
Newbie
*
Offline Offline

Posts: 2


View Profile
« on: December 18, 2012, 07:51:19 PM »

 Shocked   Huh   Undecided     Cry   
So I have re-installed windows on my barely 4 month old laptop 2 times already. I have a toshiba s855-s5251 that has 6GB RaM 750 GB HDD and is now rockin W8 but came oem style with 7 home premium.
For whatever reason I have shadow copies being made on my system without having set that up. I also seem to be forever unadding xml and fax printers that were never used from the home LAN. Now I noticed Windows SQL making outbound connections and there is always a delay in my internet connection starting up. It seems that it connects just fine but then a caution sign gets thrown up on the internet connection bar and then after x number of seconds  it finally has internet access. Right now as i type my mouse pointer has an hour glass next to it and it looks more like a strobe light for how fast it is flashing...sumone pease help me I feel like I should pull out every hair on my damn head.
oh yes and there is unauthorized access attempts to access process data or sumthin to that effect. Oh yes last but not least it seems like everytime i restore modem n router to factory settings within days i am locked out of it
Logged
3xban
Hero Member
*****
Offline Offline

Posts: 608


View Profile WWW
« Reply #1 on: December 18, 2012, 09:30:27 PM »

When you reinstalled, did you also restore your old data?  you may have the malware in your profile directory and if you just copy your whole folder from \Users, you will only continue to reinfect yourself.  Also some tools to use to check some things out, Microsoft Sysinternals has a number of free tools available.  A good one to use is Process Monitor, which logs all active processes on the system.  It also logs the network activity that a process us causing.

Another app in the Sysinternals suite is Rootkit revealer, you mean want to run that and see if you have a rootkit.  Make sure AV is installed and updated, as well as something like MalwareBytes.  Then reboot the device into Safemode, no networking.  Run full scans using both AV and Malwarebytes.  Another tool to try is the free tool from McAfee call Stinger.  This is a scanner that runs standalone and is typically updated regularly, so no need to run an update after downloading.

You also may want to re-evaluate your internet behavior.  If you are a torrent fan, you may have picked something up there.  I would recommend in the future to install something like Virtual Box and build a nifty linux Virtual machine.  Then run your internet surfing from there.

Good luck!
Logged

Certs: GCWN
(@)Dewser
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.058 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.