[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

Question
[x]
Attachment Details
[x]
The Solution Rating System

With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.

  • The Grade of the Solution
  • The Zone Rank of the Expert Providing the Solution
  • The Number of Author and Expert Comments
  • The Number of Experts Contributing
  • The Feedback of the Community

Your Input Matters
Because of the way the system is set up, the most important variable in this equation is you. As a member of Experts Exchange, you are able to cast your vote on the quality of the solutions in regard to how complete, accurate, helpful and easy to understand each solution is. When you provide your feedback, each rating is adjusted accordingly. So, if you see a solution that has a poor rating that you think is a good solution, let us know by rating it. As you do, the rating will be adjusted and will become more accurate for other members of our site.

If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support.

Thank you!

8.0

Unwelcome visitors in Boot Sector (s)

Asked by seashell55 in Windows Network Security

This is a sorrowful, tangled tale-but I am on my 3rd computer since Jan.16th. On 11/20/03 the 1st computer (80 GB HD, 1 partition, FAT32, W2K) was infected by neighbor who was file sharing AND sharing my DSL. I knew something was wrong but the computer was updated, patched, behind a router and Norton said all was well. Also ran Ad-Aware, SpyBot and SpyWare Blaster regularly and other than the ever-present data miners, they too came up with zilch. That computer crashed hard on 1/16/04 in the middle of a project. Quickly hooked up #2, a Dell that had just been delivered 3 days prior for mother who wanted to learn to email. This was a 40GB HD, 1 partition, NTFS, WIN-XP HOME. Installed the security updates, sp's, Norton, Ad-Aware, etc and back-tracked several days on by now critical project with the last backup from #1 which was on a read-only CD. On the weekend of Feb 20, 21 & 22, Wallwatcher logged over 12,600 incomings to Linksys BEFSR-41 wired router. I was the only one on the network as neigbors line has been physically cut, although I had not yet investigated #1. The odd thing about the incomings was that they were from about 40 different countries, mostly Europe and Asia. Had installed a critical update on 2/11 which caused a BSOD and an error code pointing to new drivers, of which there weren't any.  BSOD again on 2/24, same error code. Started looking around.

Services that I had disabled on 1/16, such as telephony, terminal services, remote access connection manager, etc., were running although the "startup type" still showed disabled. Then I discovered that there seemed to be an IIS and an SQL server not only installed, but also running. About that time, I also realized that I had no admin rights and was "blocked" from many files and unable to change any registry values. Norton and his sidekicks were still singing Happy Days, but MS Baseline Analyzer claimed I had no security updates . Then started getting redirects from MS, Symantec, etc. Went to my neigbor's house to use his computer, and to utter horror found the same story on his W2K, 20 GB HD, 1 partition, FAT32 computer. I thought it was because I had borrowed his router a couple of weeks earlier, while troubleshooting my mess. Except that I went to another neighbor who has W2K and again found the same story and we have never exchanged an email or anything else computer related.

Unhooked computer #2 and hooked up computer #3, a newly refurbished 6GB, W2K, 1 partition, FAT32 computer from former boyfriend that had not been used since refurbishment. He also gave me a new DSL modem. NOW it gets really wierd..on computer #2 (Dell) I could get a DSL sync light, but not a LAN light with my modem and a LAN light but no DSL SYNC light with his modem, with or without the router. I have not seen Andy since the same exact NO LAN on mine and  NO SYNC on his, happend with the modems on #3 that  he just brought over and that had worked fine at his house.

Sorry this is so long,..but while this was going on the phone was acting wierd, also. Phone company came and found my line not only hooked up to my building "B" (Townhouse condominium complex), but it was also hooked up to Building "C" on an empty pair, but alive and well with dial tone. They urged me to call the police who had no clue what we were talking about. I did contact Sans and Cert, and now my old router and HD are in Mass with Sans, but I haven't heard anything yet.

The files that I can find and read are slippery.  They change dates, directories, and even their names and file sizes.  They are encrypted and I have no experience with that. I have reformatted #3 three times, with no success. I wipe out the "unallocated" space when reinstalling, but it shows right back up. Tried Partition and Boot Magic, who sometimes see the space, but mostly don't. I download updates, only to happen on the Uninstall file later.

Now for the end at last...from what I can tell, and this is by booting from a Linux Knoppix disk, "they" are involved with VoIP and use telephony and terminal services constantly. I have all the video and audio codecs that seem to be associated with VoiP installed.There are all kinds of files relating to country phone codes and Sprint, MCi, etc. charges.  I also have files for Windows 3.1, 95, 98, ME and XP on this W2K box. There are 10 different languages and fonts installed, mostly from Eastern Europe and the Middle East (including I think, Iraq). "They" have full control of the printer and floppy drive and sometimes they show up in Explorer, but mostly they don't. If I'm in an unwelcome place, I get some not very convincing windows "error" message or just thrown out completely to another directory. I have been using my web mail, but I think they are with me there, too. I can't email an attachment (not that anybody wants one from me) as it just gets wiped out.

I have been all over the Internet and can't find anything like this. HELP! I want my life, my privacy and my computer back. This isn't about money, as I constantly order over the net and my back account is fine, although I have now changed cards. And my phone is still acting strange, with "open line" like sounds on it. Also, #1 had not had Yahoo Chat since 10/03, #2 and #3 never had it. I'm a distance learning student, in my last year,  and I may never graduate because it's all done over the web. As the most computer literate of the bunch, the neighbors are waiting on me to figure it out. After the 2nd neighbor, I quit asking, but a laptop (W2K) that I had fixed for a friend and put on the network to install updates has since shown to also have the by now familiar story. Two of us use Earthlink, the other neighbor uses Bell South.

I feel like typhoid Mary caught in a bad dream. I'm looking forward to your suggestions and thank you for reading this all the way through. I just hope it posts.

Carole
[+][-]03/26/04 02:46 AM, ID: 10685854Accepted Solution

View this solution now by starting your 30-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

About this solution

Zone: Windows Network Security
Sign Up Now!
Solution Provided By: trywaredk
Participating Experts: 2
Solution Grade: B
 
[+][-]03/26/04 02:11 AM, ID: 10685667Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03/26/04 02:11 AM, ID: 10685669Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03/26/04 02:12 AM, ID: 10685671Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03/26/04 02:20 AM, ID: 10685727Assisted Solution

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 30-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]03/26/04 02:28 AM, ID: 10685770Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03/27/04 05:38 AM, ID: 10694572Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]03/27/04 09:50 AM, ID: 10695379Assisted Solution

Assisted solutions are selected by the member who asked the question as a comment that contributed to their question's solution.

Start your 30-day free trial to view this Assisted Solution or ask the Experts your question.

 
[+][-]03/27/04 12:31 PM, ID: 10695965Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]03/27/04 12:36 PM, ID: 10695978Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04/05/04 12:25 AM, ID: 10755407Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04/23/04 04:20 AM, ID: 10898269Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04/23/04 01:17 PM, ID: 10903516Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20091111-EE-VQP-92