Hi,
Currently I have a very clean install XP-SP3 with avast free edition (that’s what I would like to believe). Prior to reinstalling I had virus problems so had to delete all partitions, reinstall XP on C: however I could not delete D: partition because of 30 gigs of data.
Before reinstall there was always a svchost (see screenshots attached) attached to System Volume Information folder (hidden) on all partitions even though I never keep Sys restore turned on. Tried most of AV scanner, ComboFix etc but none was able to remove the actual virus,malware (or I dont know what, so f***ing fedup) which I very strongly believe is related to svchost and system volume information folder.
Anyways onto new install of XP-SP3 as I told u I could not delete D: partition so surely the system volume information folder was to be found there. Now even before accessing D: drive after the new install, one of the first thing I did was to turn off SYS Restore turned off SYS Restore, TURN AUTOMATIC UPDATES OFF, REMOTE SHARING ETC installed UNLOCKER browsed to d: found SYS vol info folder tried to delete it, unlocker popped up showing the SVCHOSt process attached to it, killed off the process in unlocker and it was able to successfully delete the folder and Recycler folder. Rebooted and as expected SYStem vol info folder was again to be found on D: (Pls note SYS Volume Information folder can now be found on all drives, system restore turned off.)
I downloaded & transferred SDFIX to laptop via pendrive, ran as instructed ON BC forum and sdFix found virus in system32 folder(check the LOG attached). As soon as SDFIX rebooted system and generated the log, WINDOWS Security Alerts reminds me “Your Automatic Updates are turned off”, pls remember just after the clean install I had turned off Automatic updates and this is exactly the same behaviour I used to experience prior to new install, whenever any AV used to detect any sort of virus related to SVCHOST and SYSTEM VOLUME INFORMATION so this confirm the virus,malware is still present on my system after successfully managing to waste three months of my life.
As from my past experiences at supposedly helpful guys at Kaspersky forums (http://virusinfo.info/showthread.php?t=70506) and many other forum, I am very positive that this post will not get many comments/resolutions to my problem and if at all, would be of reinstalling xp r wiping of my HDD completely. That is not an option since I have some really valuable data on my D: and even if I was to transfer it to another HDD, clean install xp on wiped off HDD and retransfer the problem would not go away since the virus, malware would also be propogated along with data.
I have scanned my laptop innumerable times with avast but no traces ever so found. I have also tried most other spyware and antivirus scanners such as vipe, cureit, avg, panda, rootkitreveler, ad-aware, superantispyware and many many more before posting here.
I am sure expert folks here would be able to find me a way out if they really want to, which would be nothing short of a blessing.
regards,
rseni
Attachments:
Unlocker_system volume information folder screenshots
Sdfix log
Hijackthis log