| Windows 7: Virus remains after formatting |
24 Jul 2012
|
#1 | | |
Virus remains after formatting Hi all,
Upon running MalwareBytes it reports that I have "Trojan.DNSChanger". The log says quarantined successfully and then requires reboot. Next time I run it, though, and it's still there.
So I decided to reformat and reinstall OS. I'm never had to do this before but am certain I did it correctly, having watched a youtube tutorial. I booted from my CD, highlighted the partition, clicked "delete". It then says 'unallocated space' as expected. I proceed with the install. But upon completion, the trojan remains!
In normal mode, I keep getting repetitious messages appearing on the taskbar saying something like 'malwarebytes: stopped outgoing message (svchost.exe).
I'm quite the novice, so any help you could provide is greatly appreciated.
Thank you. | My System Specs |
| |
24 Jul 2012
|
#2 | | Windows 8 Pro with Media Center x64 Southern California, USA |
Try this out for a reinstall: SSD / HDD : Optimize for Windows Reinstallation
Whenever it says to "clean all", do it, not just a "clean", as in: Quote: Now type clean all <enter> you will get a blinking cursor telling you that clean all is working like in the second snip down, just relax and let it work. NOTE: You could type clean instead to do the same thing quicker, but just without a secure erase.
Let me know how it goes. Tutorial Credit: Bare Foot Kid | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Dell Inspiron M5040 OS Windows 8 Pro with Media Center x64 CPU AMD E-450 APU 1.65 GHz Memory 4GB Graphics Card Built-in Radeon HD 6320 Graphics Screen Resolution 1366 x 768 Mouse Microsoft Wireless Mobile Mouse 3500 Cooling fan Hard Drives 500GB Internet Speed 2.86Mbps Download Speed, 2.85Mbps Upload Speed & 26ms Ping Antivirus Defender Browser IE10 |
24 Jul 2012
|
#3 | | Windows 7 Ultimate 64bit SP1 Baldivis, Western Australia |
What are you reinstalling after the Win install? | My System Specs | | System Manufacturer/Model Number Home Build (Upgrade in Progress) OS Windows 7 Ultimate 64bit SP1 CPU i5 3550 Ivy Bridge Motherboard Gigabyte Z77MX-D3H Memory 8gb 1600 GSkill 9-9-9-24 xmp Graphics Card Gigabyte GTX 560 Sound Card VIA VT2021 onboard Monitor(s) Displays LG Flatron E2351 23inch hdmi Screen Resolution 1920x1080 Keyboard Logitech USB Mouse Logitech USB PSU Corsair HX520W (in 2 weeks a 850AX) Case Coolermaster HAF 912 Advanced Cooling Standard Hard Drives 1x 1TB WD Sata 3
1x 2TB WD Sata 2
1x 1TB WD Sata 2
1x 1TB WD Sata 3 Internet Speed Broadband Other Info It's been the worst day since yesterday (thanks Flogging Molly) so apt! |
24 Jul 2012
|
#4 | | Windows 8 Pro with Media Center x64 Southern California, USA |

Quote: Originally Posted by dwarfer66 What are you reinstalling after the Win install? Dwarfer makes a good point, make sure you aren't downloading anything until you have an antivirus installed | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Dell Inspiron M5040 OS Windows 8 Pro with Media Center x64 CPU AMD E-450 APU 1.65 GHz Memory 4GB Graphics Card Built-in Radeon HD 6320 Graphics Screen Resolution 1366 x 768 Mouse Microsoft Wireless Mobile Mouse 3500 Cooling fan Hard Drives 500GB Internet Speed 2.86Mbps Download Speed, 2.85Mbps Upload Speed & 26ms Ping Antivirus Defender Browser IE10 |
24 Jul 2012
|
#5 | | MS Windows 7 Ultimate SP1 64-bit Austin, Texas |
fralo,
After carrying out the instructions given by Dust Sailor then:
1. Install immediately MSE (Microsoft Security Essentials). Use the link in my signature.
2. Fully and completely update your Win 7.
3. Make a system image backup using Windows Backup and Restore to an external USB drive. This is so that you can reinstall a known good system in case you immediately reinfect yourself which shouldn't happen if you have carried out Step 1.
Here is the link to the tutorial for a system image backup: Backup Complete Computer - Create an Image Backup | My System Specs | | System Manufacturer/Model Number Toshiba Satellite S875D-S7239 laptop OS MS Windows 7 Ultimate SP1 64-bit CPU AMD A10-4600M Motherboard AMD Pumori (Socket FT1) Memory 6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28) Graphics Card AMD Radeon HD 7660G Sound Card High Definition Audio Device Monitor(s) Displays Generic PnP Monitor (1600x900@60Hz) Screen Resolution 1600x900@60Hz Keyboard Standard PS/2 Keyboard Mouse HP Wireless Optical Mobile Mouse Model FHA-3410 Hard Drives SSD 119GB Corsair CSSD-V128GB2 ATA Device Internet Speed What the local pub, local coffee shop offers. Other Info Optical Drive:MATSHITA BD-CMB UJ160B ATA Device
Also have an Asus ha1002xp netbook with Win 7 Ultimate installed. |
24 Jul 2012
|
#6 | | |
Okay, I followed the instructions to no avail. But here's what I did step by step.
1) Booted from WINDOWS 7 CD.
2) At language screen, hit shift/f10 to go cmd prompt
3) diskpart
4) list disk
5) select disk 0
6) clean all
7) exit
8) exit
Now back at the install screen, I made it to the listing of partitions. Selected disk 0 (unallocated space).
After install, trojan remains.
It also affects the screen when booting up. There are different colors, checked background. Before it actually gets to the Starting Windows logo, there are a bunch of "aa" scattered across the screen.
Thank you all for your help thus far. I may have to just get a new hard drive. | My System Specs | | |
24 Jul 2012
|
#7 | | MS Windows 7 Ultimate SP1 64-bit Austin, Texas |
and where did you get this windows 7 "cd"? | My System Specs | | System Manufacturer/Model Number Toshiba Satellite S875D-S7239 laptop OS MS Windows 7 Ultimate SP1 64-bit CPU AMD A10-4600M Motherboard AMD Pumori (Socket FT1) Memory 6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28) Graphics Card AMD Radeon HD 7660G Sound Card High Definition Audio Device Monitor(s) Displays Generic PnP Monitor (1600x900@60Hz) Screen Resolution 1600x900@60Hz Keyboard Standard PS/2 Keyboard Mouse HP Wireless Optical Mobile Mouse Model FHA-3410 Hard Drives SSD 119GB Corsair CSSD-V128GB2 ATA Device Internet Speed What the local pub, local coffee shop offers. Other Info Optical Drive:MATSHITA BD-CMB UJ160B ATA Device
Also have an Asus ha1002xp netbook with Win 7 Ultimate installed. |
24 Jul 2012
|
#8 | | MS Windows 7 Ultimate SP1 64-bit Austin, Texas |
Incidentally,
I guarantee you that if you performed a CLEAN ALL, then no virus survived.
This means you infected the system after the clean all.
The clean all writes zeroes to each and every byte on your hard disk. | My System Specs | | System Manufacturer/Model Number Toshiba Satellite S875D-S7239 laptop OS MS Windows 7 Ultimate SP1 64-bit CPU AMD A10-4600M Motherboard AMD Pumori (Socket FT1) Memory 6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28) Graphics Card AMD Radeon HD 7660G Sound Card High Definition Audio Device Monitor(s) Displays Generic PnP Monitor (1600x900@60Hz) Screen Resolution 1600x900@60Hz Keyboard Standard PS/2 Keyboard Mouse HP Wireless Optical Mobile Mouse Model FHA-3410 Hard Drives SSD 119GB Corsair CSSD-V128GB2 ATA Device Internet Speed What the local pub, local coffee shop offers. Other Info Optical Drive:MATSHITA BD-CMB UJ160B ATA Device
Also have an Asus ha1002xp netbook with Win 7 Ultimate installed. |
24 Jul 2012
|
#9 | | Windows 7 Ultimate x64 Solo. |
Hi Fralo.
Just another question. Do you have multiple partition? (C:, D:. E:, etc)
If yes, then it most likely the viruses or malwares reside in any drives other than C: drive.
As we always aware, when windows done installing, it then initially search for any other drives, read it, and lettering it. But it also will read a folder named "System Volume Information" on each drive. The problem is most of recent viruses and malwares reside inside those system protected folders and manipulate windows to read and execute them.
My suggestion is before reinstalling windows try to delete any files or folder inside "System Volume Information" on each drive. It sometime can be reached using bootable linux system.
Hope that helps a little.
Kevin
Edit: You have to know the folder also has some saved automatic or manual system restore data. When deleted, it will loss. But with newly installed windows, you might not need it anyway. | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Self built system OS Windows 7 Ultimate x64 CPU CORE i5 Motherboard Intel DH55PJ Memory 4GB Graphics Card ATI HD 4650 Sound Card Realtek HD Integrated Monitor(s) Displays LG Flatron L1742S; LG Flatron 19"; Toshiba 32" Screen Resolution 1280 x 1024; 1366 x 768 Keyboard Logitech Wireless Mouse Logitech Wireless PSU Power Case Simbadda Cooling Conventional Hard Drives Seagate Barracuda 500 GB
WDC 1 TB Internet Speed 256Kbps Other Info External HDD Transcend 500GB
Dial Up Modem Huawei
Home-made Home Theater
Laptop ASUS K42F, Core i3, 4GB memory, 320GB HDD.
LAptop Fujitsu LH531, Core i3, 4GB Memory, 500 GB HDD, Nvidia VGA |
24 Jul 2012
|
#10 | | MS Windows 7 Ultimate SP1 64-bit Austin, Texas |
kevin,
Clean ALL will take care of that if they are all on the same physical drive.
If he has multiple physical hard drives, then the other drives should be physically removed.
After Win 7 is installed, then running WDO over all hard drives will be a necessity. | My System Specs | | System Manufacturer/Model Number Toshiba Satellite S875D-S7239 laptop OS MS Windows 7 Ultimate SP1 64-bit CPU AMD A10-4600M Motherboard AMD Pumori (Socket FT1) Memory 6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28) Graphics Card AMD Radeon HD 7660G Sound Card High Definition Audio Device Monitor(s) Displays Generic PnP Monitor (1600x900@60Hz) Screen Resolution 1600x900@60Hz Keyboard Standard PS/2 Keyboard Mouse HP Wireless Optical Mobile Mouse Model FHA-3410 Hard Drives SSD 119GB Corsair CSSD-V128GB2 ATA Device Internet Speed What the local pub, local coffee shop offers. Other Info Optical Drive:MATSHITA BD-CMB UJ160B ATA Device
Also have an Asus ha1002xp netbook with Win 7 Ultimate installed. Virus remains after formatting problems? All times are GMT -5. The time now is 08:03 PM. | |