ENTIRE HDD Erased!

   Warning
Ok no more arguing or I'll start handing infractions out.
 

My Computer My Computer

Computer type
PC/Desktop
OS
Windows 11
Sounds like it is "hiding" in memory or in the MBR which is NOT affected by format commands unless specified to do so.

Regards,
GEWB

Spybot run from Safe Mode will actually restart to somehow get to whatever it detects hiding in the memory.

Very cool :cool: Worth one-milllllllllllion dollars.
 
Sounds like it is "hiding" in memory or in the MBR which is NOT affected by format commands unless specified to do so.

Regards,
GEWB

Spybot run from Safe Mode will actually restart to somehow get to whatever it detects hiding in the memory.

Very cool :cool: Worth one-milllllllllllion dollars.


Spybot is not just scanning memory, and I don't think (but don't know) if it even touches the MBR.

On restart, it takes over as soon as possible to scan the drive before any files can get locked and become in use, so what it finds it can delete.
 

My Computer My Computer

Computer Manufacturer/Model Number
Self Built
OS
Win 7 Ultimate 32bit
CPU
C2D E6600 2.4Ghz
Motherboard
Intel D965WH
Memory
4G Kingston KHX5400D2
Graphics Card(s)
EVGA GTX 570 HD SC (012-P3-1573-KR)
Sound Card
On-Board
Monitor(s) Displays
Samsung 226BW
Screen Resolution
1680 x 1050
Hard Drives
2 x 250 Seagate Barracuda
2 x 500 Seagate Barracuda (Raid1)
PSU
Corsair TX750W
Case
In-Win C589
Cooling
Stock Intel Cooling
Sounds like it is "hiding" in memory or in the MBR which is NOT affected by format commands unless specified to do so.

Regards,
GEWB

Spybot run from Safe Mode will actually restart to somehow get to whatever it detects hiding in the memory.

Very cool :cool: Worth one-milllllllllllion dollars.


Spybot is not just scanning memory, and I don't think (but don't know) if it even touches the MBR.

On restart, it takes over as soon as possible to scan the drive before any files can get locked and become in use, so what it finds it can delete.

I think all this is a moot point. The OP is reinfecting the system himself. It's not "hiding" somewhere.
 

My Computer My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 Ultimate RTM (Technet)
CPU
3.00 gigahertz Intel Core2 Duo E8400
Motherboard
ASUSTeK Computer INC. P5K/EPU Rev 1.xx
Memory
4GB
Graphics Card(s)
ATI Radeon X1950 Pro
Sound Card
Built in HD Audio
Monitor(s) Displays
22" Gateway LCD
Screen Resolution
1920 x 1200
Hard Drives
ST3160023A [Hard drive] (160.04 GB) -- drive 0, rev 8.01, ST3500630AS [Hard drive] (500.11 GB) -- drive 2, rev 3.AAK
ST3500630AS [Hard drive] (500.11 GB) -- drive 1, rev 3.AAK
Keyboard
Logitech G11
Mouse
Microsoft Wireless Laser Mouse 5000
Internet Speed
13.44 Mbps
After reading through about 80% of the recommendations here it would appear that the OP is a little hard headed or just doesn't get the big picture.

Now I realize he is doing all he can to save all his information, albeit at this point it is only causing him problems, hence, the files are corrupted; so he needs to bit the bullet and start over. This is a lesson learned as to the necessity of backing up your files, keep UAC active, and ensure you have a good AV installed and activated.

In fact this "Thread should be used to demonstrate the importance of backing up your system, and ensuring that all your files should be placed on some form of external media."
 

My Computer My Computer

Computer Manufacturer/Model Number
HP Pavilion a4302f
OS
Win 7 Pro x64, VM Win XP, Win7 Pro Sandbox, Kubuntu 11
CPU
AMD Athlon(tm) II X4 640 @ 3.0 Gbz
Memory
12GB 1066MHz DDR3 SDRAM - 2x4GB, 2x2GB
Graphics Card(s)
ATI Radeon HD 4350 HD Graphics/Audio with 512MB
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
1. Dell 23" SP2307, 2. Mitsublishi 40" HDTV, Hannspree 25"
Screen Resolution
1. 2048x1152, 2. 1920-1080, 3. 1920x1200
Hard Drives
Int: 1 120 Gig SSD i
1 - 2.5" 500 USB External HDD
1 -1 Tb USB External HDD
Case
Mid Tower
Cooling
Standard Fans - 5 fans (very quiet)
Keyboard
Microsoft Wireless 2000
Mouse
Microsoft Wireless Mouse 5000
Internet Speed
10 Mbit (realistically 500 Kbit - 1.2 Mbit)
Other Info
Speakers - Bose Desktop (Excellent Sound)
1 external CD|DVD\Blue-ray Recorders/Players (Sony)
After reading through about 80% of the recommendations here it would appear that the OP is a little hard headed or just doesn't get the big picture.

Now I realize he is doing all he can to save all his information, albeit at this point it is only causing him problems, hence, the files are corrupted; so he needs to bit the bullet and start over. This is a lesson learned as to the necessity of backing up your files, keep UAC active, and ensure you have a good AV installed and activated.

In fact this "Thread should be used to demonstrate the importance of backing up your system, and ensuring that all your files should be placed on some form of external media."
May I also add that the theories of where the virus keeps appearing from are extremely rare cases...

I have never ever saw a "memory virus" in action...and I have been in the computing business since I was 7 so...13 years now

Will it happen in the future? Probably but right now this is just a little "off base"
 

My Computer My Computer

Computer Manufacturer/Model Number
Compal JFT02 (Custom Build Laptop)
OS
Windows 7 Home Premium x64 - Mac OS X 10.6.4 x64
CPU
Intel Core 2 Duo T9300 2.5 GHz
Motherboard
JFT02
Memory
4GB Kingston DDR2-800
Graphics Card(s)
NVIDIA Geforce 8600M GT (512MB Model)
Sound Card
Realtek HD Audio
Monitor(s) Displays
WUXGA Standard Laptop Display
Screen Resolution
1680*1050
Hard Drives
Toshiba 320GB 5400RPM Laptop HD
PSU
Standard Laptop Power Supply
Case
Standard Laptop Case
Cooling
Standard Laptop Cooling
Keyboard
Standard Laptop 105 Key-Keyboard
Mouse
Synaptics Touchpad
Internet Speed
Verizion Online DSL 3360/864 kbs (dl/up)
Zidance24, yes you may add, that is great advice.
 

My Computer My Computer

Computer Manufacturer/Model Number
HP Pavilion a4302f
OS
Win 7 Pro x64, VM Win XP, Win7 Pro Sandbox, Kubuntu 11
CPU
AMD Athlon(tm) II X4 640 @ 3.0 Gbz
Memory
12GB 1066MHz DDR3 SDRAM - 2x4GB, 2x2GB
Graphics Card(s)
ATI Radeon HD 4350 HD Graphics/Audio with 512MB
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
1. Dell 23" SP2307, 2. Mitsublishi 40" HDTV, Hannspree 25"
Screen Resolution
1. 2048x1152, 2. 1920-1080, 3. 1920x1200
Hard Drives
Int: 1 120 Gig SSD i
1 - 2.5" 500 USB External HDD
1 -1 Tb USB External HDD
Case
Mid Tower
Cooling
Standard Fans - 5 fans (very quiet)
Keyboard
Microsoft Wireless 2000
Mouse
Microsoft Wireless Mouse 5000
Internet Speed
10 Mbit (realistically 500 Kbit - 1.2 Mbit)
Other Info
Speakers - Bose Desktop (Excellent Sound)
1 external CD|DVD\Blue-ray Recorders/Players (Sony)

My Computer My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 build 7600 64 bit
CPU
Phenom II X4 955 retail 3.2GHz
Motherboard
ASRock M3A790GXH/USB3 ATX AMD AMD3
Memory
4x GeiL 2GB Value PC3-10660 CL9 DC DDR3-1333, CL 9-9-9-28
Graphics Card(s)
PowerColor Radeon HD5850 PCS+ 1024MB, 256-bit GDDR5
Sound Card
Built in
Hard Drives
G.Skill Phoenix Pro 120GB SATA2 SSD Sandforce SF-120
Samsung Spinpoint 500GB SATA2 7200RPM
PSU
Tacens Radix III Smart 520W
The irony is that after I low leveled formatted, (all my data and projects are now on my MacOS X partition/installation) I installed W7 again, I installed everything that I usually install, UAC, turned down to minimum, AVG Free Antivirus, and the system is TROUBLE FREE, it s been a week now ..... I am going to keep it there for a few weeks there and see if it gets infected or smt...
 

My Computer My Computer

Computer Manufacturer/Model Number
Intel
OS
W7 X64 Ultimate, OSX, Linux
CPU
Intel Core i3 540M
Motherboard
Intel DH55TC
Memory
2GB Kingston DDR3 @ 1333MHz
Graphics Card(s)
nVidia gForce 250GTs, 512MB
Sound Card
OnBoard
Monitor(s) Displays
2xBenq E2200HDA
Screen Resolution
1920x1080
Hard Drives
Linux - 160GB WD 8MB Cache 7200rpm
OSX - 320GB Seagate Barracuda 16MB Cache 7200rpm
W7 - 80GB Seagate Barracude 8MB Cache 7200rpm
PSU
Antec 700W
Case
Cooler Master MidTower
Cooling
Standard
Keyboard
DeLux
Mouse
Logitech Wireless
Internet Speed
LAN/T1
something doesnt seem quite right here.

the only way I know a computer can get affected whilst its idle is if there is a remote exploit through open network ports. So the question is, is this a machine behind NAT? if not get that firewall enabled on the router.

In such a scenario UAC may not save the user.

Generally speaking this is the ideal scenario.

PC behind a NAT or firewall enabled router.
Run as limited user account.
Enable software restriction policy.
Scan http/email/IM traffic for viruses.
Restrict activex
Install a security hosts file
Use an adblocker, as a side affect they tend to block various drive by viruses.
Restrict flash, even IE8 can now have the feature to enable flash per website.
Install spywareblaster
If possible use firefox, opera or chrome instead of IE but not necessary if done all the other stuff anyway.

In such a configuration the machine would very unlikely get a successful infection.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
home built
OS
windows 8.1 Pro x64
CPU
intel i5 4670k @ 4.3ghz
Motherboard
asus z87-plus
Memory
16 gig ram ddr3 @ 1600 corsair vengeance
Graphics Card(s)
evga 970 GTX 4 GIG FTW ACX 2.0
Sound Card
asus xonar D2X
Monitor(s) Displays
benq gw2765ht
Screen Resolution
2560x1440
Hard Drives
Samsung 850 pro SSD 512gig - boot device wooosh
WD black cavalier 640gig WD6401AALS
Seagate 500gig ST3500630AS
WD 2TB Green WDC20EARS
2 x WD Red 3TB WD30EFRX
Samsung 750gig HD753LG - on asmedia controller
PSU
coolermaster silent pro 600watt modular
Case
fractal define R4
Cooling
artic freezer i30, 3 case fans
Keyboard
microsoft business ps2 keyboard
Mouse
microsoft optical black mouse
Internet Speed
80/20 FTTC SkyBB
Antivirus
Nod32 AV v8, HitmanProAlert, SRP, System Hardening
Browser
Chrome x64
Other Info
Intel controller is in AHCI mode currently using IaSTOR 12.8.0.1016 drivers
The irony is that after I low leveled formatted, (all my data and projects are now on my MacOS X partition/installation) I installed W7 again, I installed everything that I usually install, UAC, turned down to minimum, AVG Free Antivirus, and the system is TROUBLE FREE, it s been a week now ..... I am going to keep it there for a few weeks there and see if it gets infected or smt...
This once again proves that your data (Projects, etc.) is where the infection lies...I doubt that the OSX partition will be infected nor will the Windows partition will be infected again unless....

1. You transfer that data back over...

Unless you can pinpoint the cause of the infection in your files...this problem is never going to go away
 

My Computer My Computer

Computer Manufacturer/Model Number
Compal JFT02 (Custom Build Laptop)
OS
Windows 7 Home Premium x64 - Mac OS X 10.6.4 x64
CPU
Intel Core 2 Duo T9300 2.5 GHz
Motherboard
JFT02
Memory
4GB Kingston DDR2-800
Graphics Card(s)
NVIDIA Geforce 8600M GT (512MB Model)
Sound Card
Realtek HD Audio
Monitor(s) Displays
WUXGA Standard Laptop Display
Screen Resolution
1680*1050
Hard Drives
Toshiba 320GB 5400RPM Laptop HD
PSU
Standard Laptop Power Supply
Case
Standard Laptop Case
Cooling
Standard Laptop Cooling
Keyboard
Standard Laptop 105 Key-Keyboard
Mouse
Synaptics Touchpad
Internet Speed
Verizion Online DSL 3360/864 kbs (dl/up)
I really hope that you are dead wrong, at the moment, I only copy from my dvd what I need for the current client and so on(his site layout etc, buttons). and when I stumble upon a virus, hopefully I'll know before everything is deleted
 

My Computer My Computer

Computer Manufacturer/Model Number
Intel
OS
W7 X64 Ultimate, OSX, Linux
CPU
Intel Core i3 540M
Motherboard
Intel DH55TC
Memory
2GB Kingston DDR3 @ 1333MHz
Graphics Card(s)
nVidia gForce 250GTs, 512MB
Sound Card
OnBoard
Monitor(s) Displays
2xBenq E2200HDA
Screen Resolution
1920x1080
Hard Drives
Linux - 160GB WD 8MB Cache 7200rpm
OSX - 320GB Seagate Barracuda 16MB Cache 7200rpm
W7 - 80GB Seagate Barracude 8MB Cache 7200rpm
PSU
Antec 700W
Case
Cooler Master MidTower
Cooling
Standard
Keyboard
DeLux
Mouse
Logitech Wireless
Internet Speed
LAN/T1
I really hope that you are dead wrong, at the moment, I only copy from my dvd what I need for the current client and so on(his site layout etc, buttons). and when I stumble upon a virus, hopefully I'll know before everything is deleted
I hope I am to but the evidence here is pretty damning as far as your data goes...
 

My Computer My Computer

Computer Manufacturer/Model Number
Compal JFT02 (Custom Build Laptop)
OS
Windows 7 Home Premium x64 - Mac OS X 10.6.4 x64
CPU
Intel Core 2 Duo T9300 2.5 GHz
Motherboard
JFT02
Memory
4GB Kingston DDR2-800
Graphics Card(s)
NVIDIA Geforce 8600M GT (512MB Model)
Sound Card
Realtek HD Audio
Monitor(s) Displays
WUXGA Standard Laptop Display
Screen Resolution
1680*1050
Hard Drives
Toshiba 320GB 5400RPM Laptop HD
PSU
Standard Laptop Power Supply
Case
Standard Laptop Case
Cooling
Standard Laptop Cooling
Keyboard
Standard Laptop 105 Key-Keyboard
Mouse
Synaptics Touchpad
Internet Speed
Verizion Online DSL 3360/864 kbs (dl/up)
How thoroughly have you scanned the data your retrieved?

I would run Malewarebytes, Avast, Adaware and Spybot over them at a minimum.

Then I would run the same in Safe Mode on my system with data DVD's removed.

Zidane probably knows what combo needs to be run to most assure clean, or not.

I tend to forget Adaware as I dont' use it any longer, but in Europe I helped remove 40,000+ Trojans from laptop using Avast, AVG and Spybot. Adaware found even more the others hadn't.
 
I would just like to point out my experience with those tools and others....

AVG Free Antivirus = Garbage... I know many people swear up and down one side and the other that it is great,, no,, it's not. I have seen many systems that were inundated with malware/viruses/god knows what else.
I would start AVG scanning and it found nothing.... Scan with an on-line scanner such as ESET and whammo,, AVG pops up "hey, i found a virus", just after Eset caught it and was trying to clean it. So, I'm sorry to say, but after seeing this more than a few times, AVG Free Antivirus (or pay for ware) is garbage.

Adaware - While it may still be good,, it has become bloated. Most of the additional stuff it finds is non-threatening (ie. cookies, garbage files, etc.).

The new Duo in my opinion is Malwarebytes and Spybot. ESET Online scanner (not the installed pay for ware). If the license lapses, it cripples the OS. Big no no in my book.

Microsoft Safety Scanner is pretty good. As are some others.

Just my 2 cents.

For installed AV I recommend Microsoft Security Essentials. It's free and so far has caught some things that could have been bad. Haven't had a problem yet.

Avast - While good, has some niggles I don't like personally. You have to activate it constantly (or it seems anyway). Maybe if you buy it, it's different. But....

KAV - has in the past been a resource HOG.

Norton - Garbage. Resource hog, viruses know how to bypass and disable it.

Mcafee - just plain garbage.

Panda - I don't know that much about.

Avira - while always gets top marks on http://www.av-comparatives.org/ ,, They require (force) you to make a donation to the owners charity. Fine by me, but I won't by the product because of it.
 

My Computer My Computer

Computer Manufacturer/Model Number
Self Built
OS
Win 7 Ultimate 32bit
CPU
C2D E6600 2.4Ghz
Motherboard
Intel D965WH
Memory
4G Kingston KHX5400D2
Graphics Card(s)
EVGA GTX 570 HD SC (012-P3-1573-KR)
Sound Card
On-Board
Monitor(s) Displays
Samsung 226BW
Screen Resolution
1680 x 1050
Hard Drives
2 x 250 Seagate Barracuda
2 x 500 Seagate Barracuda (Raid1)
PSU
Corsair TX750W
Case
In-Win C589
Cooling
Stock Intel Cooling
Agreed, AVG bloated up and never slimmed back to it's old bad self.

Avast took the freebie lead IMO and has stayed there.

Now everyone's talking about MSE. But why move from Avast after nearly 10 flawless years?

I use Malwarebytes and Spybot scanners, for deep scanning and rightclicking files.

But Spybot's teatimer and Internet protection is IMO a goofy mess.
 
I have been using Norton for years , and YES the older versions were resource hogs , but the 2010 Norton Anti-virus has a small footprint .. I have cleaned many systems with Mcafee and AVG free version , that were completely infected ..

My 2 cents ..
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 10 Pro - 64 bit
CPU
Intel i7 2600K
Motherboard
Asus P8P67
Memory
8 Gig ddr3 1600 mhz - viper extreme (Patriot)
Graphics Card(s)
EVGA 980 TI
Monitor(s) Displays
2 - Lg 21" LED , sony 48 " bravia LED
Hard Drives
one - samsung 840 series 465.76 GB SSD
two - wd 2 tB black
one - wd 1.5 tb black
one - wb 1 tb black
PSU
1000 Watt Coolmaster : Silent Pro Gold
Case
antec 1200
Cooling
watercooled
Mouse
logitech wireless
Antivirus
Norton Security 2015
Other Info
powerware 3.1 KVA FERRUPS with 4 - 1000 Amp Deep cycle batteries ...
Well,, after re-visiting AV Comparatives after a long while away from there.. it seems that things have changed, and Yes they hold weight on their findings. They are non-partison and not paid for in the way of buying results. They get paid a fee, but all the software is put through the same tests, They don't score on how much money they are given.

But, Norton was given their best of 2009 award. So, maybe it's worth looking at again.
MSE was given Gold for on-demand proactive malware detection and least false positives. That is nothing to shake a stick at either. They also got a bronze at cleaning malware.

If you go the website and look at the Summary Report 2009 you can see what I am talking about.

Oh yeah,, AVG didn't score jack.
 

My Computer My Computer

Computer Manufacturer/Model Number
Self Built
OS
Win 7 Ultimate 32bit
CPU
C2D E6600 2.4Ghz
Motherboard
Intel D965WH
Memory
4G Kingston KHX5400D2
Graphics Card(s)
EVGA GTX 570 HD SC (012-P3-1573-KR)
Sound Card
On-Board
Monitor(s) Displays
Samsung 226BW
Screen Resolution
1680 x 1050
Hard Drives
2 x 250 Seagate Barracuda
2 x 500 Seagate Barracuda (Raid1)
PSU
Corsair TX750W
Case
In-Win C589
Cooling
Stock Intel Cooling
Well,, after re-visiting AV Comparatives after a long while away from there.. it seems that things have changed, and Yes they hold weight on their findings. They are non-partison and not paid for in the way of buying results. They get paid a fee, but all the software is put through the same tests, They don't score on how much money they are given.

But, Norton was given their best of 2009 award. So, maybe it's worth looking at again.
MSE was given Gold for on-demand proactive malware detection and least false positives. That is nothing to shake a stick at either. They also got a bronze at cleaning malware.

If you go the website and look at the Summary Report 2009 you can see what I am talking about.

Oh yeah,, AVG didn't score jack.

I see that - http://www.av-comparatives.org/images/stories/test/summary/summary2009.pdf

I'm the IT person for a large company ( I'm referred to as cousin IT , by some of the workers , hehehe) and I have not deal with any infections since I have been using norton 2009 and upgraded for free to the 2010 version . I buy 10 pack licenses for 149.99 - you can't get anti-virus protection these days for 15 $ per computer ..
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 10 Pro - 64 bit
CPU
Intel i7 2600K
Motherboard
Asus P8P67
Memory
8 Gig ddr3 1600 mhz - viper extreme (Patriot)
Graphics Card(s)
EVGA 980 TI
Monitor(s) Displays
2 - Lg 21" LED , sony 48 " bravia LED
Hard Drives
one - samsung 840 series 465.76 GB SSD
two - wd 2 tB black
one - wd 1.5 tb black
one - wb 1 tb black
PSU
1000 Watt Coolmaster : Silent Pro Gold
Case
antec 1200
Cooling
watercooled
Mouse
logitech wireless
Antivirus
Norton Security 2015
Other Info
powerware 3.1 KVA FERRUPS with 4 - 1000 Amp Deep cycle batteries ...
I buy 10 pack licenses for 149.99 - you can't get anti-virus protection these days for 15 $ per computer ..

Maybe business can't get cheaper, but personal users can.

You'll find many of the experts around here consider the free AV solutions superior in every way.

After doing 100+ installs of Avast free home with no viruses or issues, it is hard to seriously consider a bloaty paid solution which IMO is an infection needing removal, even requiring a special removal tool like malware.
 
Back
Top