"Worm" question about 2nd drive

Discussion in 'malware problems & news' started by darkfires, Jun 7, 2005.

Thread Status:
Not open for further replies.
  1. darkfires

    darkfires Registered Member

    Joined:
    Jun 3, 2005
    Posts:
    2
    Hi,

    Running XP Pro, 2 drives, 2nd drive as slave for storage, no OS.

    I'm new here and not sure where to post this so if it needs to be moved let me know. Sorry If this gets lengthy but want to give you enough background about what happened.

    I was directed to the forum while searching for solutions for an ongoing problem I was having. I was on my 5th reformat in 5 months and a friend suggested trying TDS-3 and HJT, hence my arrival in forums. TDS-3 gave me my first clue, no trogans found, but alerted me of sys. changes and 2 suspicious files with bad or inavlid extensions. I never got to post HJT log, unfortunately, before the last big crash but this time not before it reared it's ugly face. The bug was "W32.Petch". The worm was awaiting execution in my 2nd drive and I realize by reformatting I only re-infected my computer again because I only reformatted my main drive.

    My question is: Would HJT have solved the 2nd drive hiding worm problem? Sorry if this is a stupid question. I'm sure I've missed the answer somewhere along the line.

    Thanks for everyone's patience with neebies like me. :doubt:
     
  2. TopperID

    TopperID Registered Member

    Joined:
    Oct 1, 2004
    Posts:
    1,527
    Location:
    London
    HJT is intended to assist with the diagnosis and removal of spyware problems and requires 'expert' use. A beginner could not effectively use it themselves and may cause more harm than good (though of course they can post a log for others to assist).

    HJT is not designed to help with the removal of self replicating malware like viruses and worms.

    See if this helps though:-

    http://securityresponse.symantec.com/avcenter/venc/data/w32.petch.html

    http://securityresponse.symantec.com/avcenter/venc/data/w32.petch.b.html
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.