Hi
I wanted to know if a rootkit can survive after a a complete format .i.e. me installing a fresh cpy of windows and deleting all partitions and creating new ones.
If so how to identify well rootkits aren`t visible in the taskmanager or msconfig so how to Detect it is easy when a program dial a net connection or open IE/prevent access to tech sites.Disable task manager/msconfig/gpedit /regsitry
will installing a firewall
zoneAlarm Pro or change NIS firewall to advanced
Well alert the user when an application is making a connection. or is it possible it can integrate it self to a process or application and download malware while downloading updates for say an application
For egHappened during 2007 (late november)
I had a prob. when I had infection of W32.spybot.Worm,Hactool.Rootkit,Surfsidekicks,Backdoor.trojan,Downloader.
When i tried updating norton its update took quite sometimes(due to malware) and after a i ran a full scan it detected 2 Downloaders in the live update Folder
got the threats via Limewire
Norton Antivirus 2007
Windows XP Media center Edition(not Updated)
Pentium III 870Mhz 256 MB ram
I formatted the C drive.
I installed McAfee virus scan enterprise 8.0(updated)
I inatlled limwire as was my primary mp3 search and download app.
immediately after that McAfee alerted me saying 4 threat were blocked/quarantined the names of the 4 threats were the same
before so did limewire automatically downloaded those threats or were they still present in my comp. after the format???
typhonxx.dll(the only one I can remember)
Is it possible that those downloaded into my system again(like they started liking it or sumthin)
Another thing i notice was their were a lot of stupid emails being sent suprisingly I dont have a outlook account too.
(This happened before format when I was running the scan with Norton 2007)Was my comp. used as a spam bot by the threat/person