salvaging a TDL3 infected HDD

Diosoth

New member
Guru
Local time
3:53 AM
Messages
451
My main 1 TB HDD got infected with TDL3 late last month. It eventually escalated to redirecting google searches, an inability to use Windows Update as well as a few other online services and then finally I was left with a system that would not boot at all, only blue screen. Repeated safe mode reboots and MSE scans removed a few nasty infections but I was still left with an infected PC. Finally giving up I tried the onboard Gateway repair option to erase everything and reinstall Windows. Then I was left with an unbootable PC that would bluescreen before Windows could start and finish setting up.

Antivirus removal options proved too expensive so I ordered the Gateay recovery CDs, only for that to fail. A local shop confirmed it was likely TDL3 so I bought a new HDD and installed fresh. But all I could get was a cheap on-sale drive with less capacity. The local shop said they could purge all data for $10 so I took that choice, but when I plugged it in and booted Windows, Alureon.a tried to run from the E: drive 2nd HDD. MSE stopped the attempted run, I "cleaned" it, shut down and unplugged the 2nd HDD. I've downloaded and ran Hitman Pro(3 times) and Malwarebytes(once normal, once safe mode restart) and neither have found anything so it appears the trojan was stopped before it could infect this copy of Windows, thankfully. I do not need a recurring infection destroying my PC again.

So I am left with a 1 TB HDD that's been shop formatted but still infected. They might try to charge $75 to clean it. Are there any safe, cheap alternatives to do this myself or should I junk the drive totally, forget it and just buy another drive if I want the extra storage? Wich frankly, if I'd known they were not going to clean out the infected boot sector it'd be in the trash now.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Gateway DX4822-01
OS
Windows 7 Home Premium x64
CPU
Intel Pentium Dual Core 2.6 GHz
Motherboard
stock factory for this model
Memory
6 GB
Graphics Card(s)
stock factory for this model
Sound Card
stock factory for this model
Monitor(s) Displays
Dell P2010Ht
Screen Resolution
1600 x 900
Hard Drives
1 TB Western Digital
PSU
300 watt
Cooling
80mm case fan, CPU fan, 60mm front intake
Keyboard
Logitech
Mouse
HP 3-button optical wheel mouse
Internet Speed
fiber optic
Antivirus
MSE, SuperAntiSpyware, Malwarebytes Free
There is a bootable dvd I'm going to recommend to wipe your drive. This way, you won't have to load any OS for the Virus to spread.

DBAN Download | Darik's Boot And Nuke

Darik's Boot and Nuke ("DBAN") is a self-contained boot disk that securely wipes the hard disks of most computers. DBAN will automatically and completely delete the contents of any hard disk that it can detect, which makes it an appropriate utility for bulk or emergency data destruction.

I've used this quite a number of times when reformatting. And I can confirm that this low level drive wiping tool works perfectly. Give it a try mate.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Ultimate x64 Service Pack 1
CPU
AMD Athlon II x4 Propus 2.9 GHz
Motherboard
ASRock N68C-GS FX
Memory
2 x 4GB Corsair XMS 3 DDR3 -1600 CL9
Graphics Card(s)
AMD Radeon HD 5850 1GB GDDR5
Sound Card
On-board 6-Channel HD Audio
Monitor(s) Displays
18' LG Flatron E1942TC-BN on DVI, 18' Chimei 95ND on HDMI
Screen Resolution
1366 x 768 x 2
Hard Drives
1 x 500 GB Seagate
1 x 1 TB Western Digital Caviar Green
1 x 1 TB Hitachi Touro Mobile USB 3
PSU
Seasonic S12II 520W
Case
Generic with Cable Management
Cooling
Deep Cool Gammaxx 200
Keyboard
Dragonwar Desert Eagle
Mouse
Logitech B85
Internet Speed
5Mb/s DL, 0.9Mb/s UL
Antivirus
ESET Nod32
Browser
Google Chrome 64 Bit
Other Info
LG G4 H818P - Rooted with Xposed Framework
There is a bootable dvd I'm going to recommend to wipe your drive. This way, you won't have to load any OS for the Virus to spread.

DBAN Download | Darik's Boot And Nuke

Darik's Boot and Nuke ("DBAN") is a self-contained boot disk that securely wipes the hard disks of most computers. DBAN will automatically and completely delete the contents of any hard disk that it can detect, which makes it an appropriate utility for bulk or emergency data destruction.
I've used this quite a number of times when reformatting. And I can confirm that this low level drive wiping tool works perfectly. Give it a try mate.

Alright, I've downloaded and burned a copy. I'll probably run this later. It also gives me a repair option should I get infected again, which it looks like it did not tonight, but I've become so paranoid over this after dealing with it for almost 2 weeks I'm going to worry anyway.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Gateway DX4822-01
OS
Windows 7 Home Premium x64
CPU
Intel Pentium Dual Core 2.6 GHz
Motherboard
stock factory for this model
Memory
6 GB
Graphics Card(s)
stock factory for this model
Sound Card
stock factory for this model
Monitor(s) Displays
Dell P2010Ht
Screen Resolution
1600 x 900
Hard Drives
1 TB Western Digital
PSU
300 watt
Cooling
80mm case fan, CPU fan, 60mm front intake
Keyboard
Logitech
Mouse
HP 3-button optical wheel mouse
Internet Speed
fiber optic
Antivirus
MSE, SuperAntiSpyware, Malwarebytes Free
Sorry you lost me there mate. What gives a repair option?

Please let us know what happens.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Ultimate x64 Service Pack 1
CPU
AMD Athlon II x4 Propus 2.9 GHz
Motherboard
ASRock N68C-GS FX
Memory
2 x 4GB Corsair XMS 3 DDR3 -1600 CL9
Graphics Card(s)
AMD Radeon HD 5850 1GB GDDR5
Sound Card
On-board 6-Channel HD Audio
Monitor(s) Displays
18' LG Flatron E1942TC-BN on DVI, 18' Chimei 95ND on HDMI
Screen Resolution
1366 x 768 x 2
Hard Drives
1 x 500 GB Seagate
1 x 1 TB Western Digital Caviar Green
1 x 1 TB Hitachi Touro Mobile USB 3
PSU
Seasonic S12II 520W
Case
Generic with Cable Management
Cooling
Deep Cool Gammaxx 200
Keyboard
Dragonwar Desert Eagle
Mouse
Logitech B85
Internet Speed
5Mb/s DL, 0.9Mb/s UL
Antivirus
ESET Nod32
Browser
Google Chrome 64 Bit
Other Info
LG G4 H818P - Rooted with Xposed Framework
Sorry you lost me there mate. What gives a repair option?

Please let us know what happens.

Gateway has a repair option as part of the same menu that selects safe mode. It's basically the recovery software on a protected volume of the HDD. Unfortunately, while that can wipe data and reinstall Windows it doesn't clear out TDL3/Alureon or touch the MBR. It's why I had to buy another HDD to start with.

But now that I have DNAB I can hopefully totally purge this drive and should I get another infection I can use it to start fresh again. TDL3 is a very nasty bit of malware to get rid of.

EDIT: oh, you meant in regards to my posted sentence. DNAB would give me a quick way to wipe an infected W7 if I were to get it again. I simply can not afford the $150 or more local shops charge for antivirus services.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Gateway DX4822-01
OS
Windows 7 Home Premium x64
CPU
Intel Pentium Dual Core 2.6 GHz
Motherboard
stock factory for this model
Memory
6 GB
Graphics Card(s)
stock factory for this model
Sound Card
stock factory for this model
Monitor(s) Displays
Dell P2010Ht
Screen Resolution
1600 x 900
Hard Drives
1 TB Western Digital
PSU
300 watt
Cooling
80mm case fan, CPU fan, 60mm front intake
Keyboard
Logitech
Mouse
HP 3-button optical wheel mouse
Internet Speed
fiber optic
Antivirus
MSE, SuperAntiSpyware, Malwarebytes Free
Sorry you lost me there mate. What gives a repair option?

Please let us know what happens.

Gateway has a repair option as part of the same menu that selects safe mode. It's basically the recovery software on a protected volume of the HDD. Unfortunately, while that can wipe data and reinstall Windows it doesn't clear out TDL3/Alureon or touch the MBR. It's why I had to buy another HDD to start with.

But now that I have DNAB I can hopefully totally purge this drive and should I get another infection I can use it to start fresh again. TDL3 is a very nasty bit of malware to get rid of.

EDIT: oh, you meant in regards to my posted sentence. DNAB would give me a quick way to wipe an infected W7 if I were to get it again. I simply can not afford the $150 or more local shops charge for antivirus services.


Oh okay. :D Yup, I used it loads of times. It comes with several options on what method to use when wiping. But I do have to say that wiping a drive takes time. Using the "Quick Erase" option takes about an hour and a half on my 500GB disk.

Indeed! They charge loads of cash that free software and http://www.sevenforums.com/ can fix.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Ultimate x64 Service Pack 1
CPU
AMD Athlon II x4 Propus 2.9 GHz
Motherboard
ASRock N68C-GS FX
Memory
2 x 4GB Corsair XMS 3 DDR3 -1600 CL9
Graphics Card(s)
AMD Radeon HD 5850 1GB GDDR5
Sound Card
On-board 6-Channel HD Audio
Monitor(s) Displays
18' LG Flatron E1942TC-BN on DVI, 18' Chimei 95ND on HDMI
Screen Resolution
1366 x 768 x 2
Hard Drives
1 x 500 GB Seagate
1 x 1 TB Western Digital Caviar Green
1 x 1 TB Hitachi Touro Mobile USB 3
PSU
Seasonic S12II 520W
Case
Generic with Cable Management
Cooling
Deep Cool Gammaxx 200
Keyboard
Dragonwar Desert Eagle
Mouse
Logitech B85
Internet Speed
5Mb/s DL, 0.9Mb/s UL
Antivirus
ESET Nod32
Browser
Google Chrome 64 Bit
Other Info
LG G4 H818P - Rooted with Xposed Framework
Darik's Boot and Nuke ("DBAN") works very well, I used it on my old laptop that I gave away.
 

My Computer My Computer

Computer Manufacturer/Model Number
Home Built
OS
Windows 7 Professional 64-bit SP1
CPU
Intel E8400
Motherboard
MSI P35 Neo
Memory
4GB Crucial Ballistix
Graphics Card(s)
ATI ASUS Radeon HD 4830
Sound Card
Realtek ALC888 on Board
Monitor(s) Displays
Asus 22-inch VH226H Widescreen
Screen Resolution
1920 x 1080
Hard Drives
Two Western Digital 500GB
PSU
Hiper HPU-4M 530W
Case
Thermaltake Tsunami Dream Black
Cooling
Air/Fans
Keyboard
Saitek Eclipse
Mouse
Razer
Internet Speed
Sky Broadband
Other Info
USB Hub/Card Reader - 2 Pen Drives, 1 Phone Dock

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
You can try Hitman Pro. Its very good at detecting and removing rootkit. Upon removal, it will replace the infected file with a new one.
 

My Computer My Computer

OS
Windows 7 Home Premium x64 SP1
CPU
Intel Core i7 2720QM @ 2.20GHz
Memory
8.00 GB Dual-Channel DDR3 @ 665MHz
Back
Top