questionable sequel lite fills found in Windows temp files et al.
Hi,
I have Window XP media center 2005 Edition on a Entertainment HP Pravillon notebook, model dv2125nr. Recently i was hijacked. It was a serious because I found someone using my notebook to try to log into an endless number of banks- 35 pages of this which I found under a false default user in the cache.
To begin to fix this problem, I first zeroed out the HD drive, repartitioned and formatted it, loaded the OS on it and then I found some questionable things after doing sysinteral rootkit scan where many security files had been disconnected from showing up on Windows API while still being in the registry. Also I found sequel lite files in the Windows temp folder, one of which I could not delete since it was actively in use. (I thought that the hijacker used Sequel lite to try to log into the banks but I am not familar with this language.) Are these normal files to find in the temp folder after a clean install? I have never seen files like these before in the temp folder. Moreover, besides drive C, and the recovery partition there was a third 1 GB drive after the recovery partition; at the very end! Is this normal? I did not think it was. Also, I could not copy the rootkit scan because low and behold Print Screen would not work! To be safe I decided to buy a new drive. After I installed it, those sequel lite files are still in the temp file and print screen will not work, and the drive is still partition in the same way as above.
Maybe at this point I am just paranoid after what happened. I am going to flash the Bios now to see if this will help. I will do another root kit scan and use another screen copy program which I will install to capture it. Anyway, anything you can do to help would be greatly appreciated.
Sincerely,
Molly
|