ENTIRE HDD Erased!

You need to back up your projects as soon as you can, from this running Windows installation - only data files of your projects, no programs or scripts at all.

After that, put your Windows DVD into your DVD ROM, and, FROM THAT disc, delete all partitions on your hard disk, format it (no need for a low level format) and reinstall Windows from scratch.

I hope you're not lying to us and it isn't really your Windows 7 installation that is corrupted.

Do not consider your PC clean just because antivirus scanners didn't find anything. Start anew, from a clean, clean disk.


Now why would I lie if I wanted help? the installation disk is an iso downloaded through MSDNAA academic program and licensed through the same institution.
 

My Computer My Computer

Computer Manufacturer/Model Number
Intel
OS
W7 X64 Ultimate, OSX, Linux
CPU
Intel Core i3 540M
Motherboard
Intel DH55TC
Memory
2GB Kingston DDR3 @ 1333MHz
Graphics Card(s)
nVidia gForce 250GTs, 512MB
Sound Card
OnBoard
Monitor(s) Displays
2xBenq E2200HDA
Screen Resolution
1920x1080
Hard Drives
Linux - 160GB WD 8MB Cache 7200rpm
OSX - 320GB Seagate Barracuda 16MB Cache 7200rpm
W7 - 80GB Seagate Barracude 8MB Cache 7200rpm
PSU
Antec 700W
Case
Cooler Master MidTower
Cooling
Standard
Keyboard
DeLux
Mouse
Logitech Wireless
Internet Speed
LAN/T1
You need to back up your projects as soon as you can, from this running Windows installation - only data files of your projects, no programs or scripts at all.

After that, put your Windows DVD into your DVD ROM, and, FROM THAT disc, delete all partitions on your hard disk, format it (no need for a low level format) and reinstall Windows from scratch.

I hope you're not lying to us and it isn't really your Windows 7 installation that is corrupted.

Do not consider your PC clean just because antivirus scanners didn't find anything. Start anew, from a clean, clean disk.
Now why would I lie if I wanted help? the installation disk is an iso downloaded through MSDNAA academic program and licensed through the same institution.
I have been reading through this thread and it has been a mess...let me jump in a bit...

So I understand...you had malware->your formatted/clean install->malware came back->you are now fighting against the same malware again

I imagine that in the new installation you would have at some point pulled your Data off the external devices...that is where the infection lies. It explains why a new clean install is being infected without you downloading any of the cracks like you used to...
 

My Computer My Computer

Computer Manufacturer/Model Number
Compal JFT02 (Custom Build Laptop)
OS
Windows 7 Home Premium x64 - Mac OS X 10.6.4 x64
CPU
Intel Core 2 Duo T9300 2.5 GHz
Motherboard
JFT02
Memory
4GB Kingston DDR2-800
Graphics Card(s)
NVIDIA Geforce 8600M GT (512MB Model)
Sound Card
Realtek HD Audio
Monitor(s) Displays
WUXGA Standard Laptop Display
Screen Resolution
1680*1050
Hard Drives
Toshiba 320GB 5400RPM Laptop HD
PSU
Standard Laptop Power Supply
Case
Standard Laptop Case
Cooling
Standard Laptop Cooling
Keyboard
Standard Laptop 105 Key-Keyboard
Mouse
Synaptics Touchpad
Internet Speed
Verizion Online DSL 3360/864 kbs (dl/up)
You need to back up your projects as soon as you can, from this running Windows installation - only data files of your projects, no programs or scripts at all.

After that, put your Windows DVD into your DVD ROM, and, FROM THAT disc, delete all partitions on your hard disk, format it (no need for a low level format) and reinstall Windows from scratch.

I hope you're not lying to us and it isn't really your Windows 7 installation that is corrupted.

Do not consider your PC clean just because antivirus scanners didn't find anything. Start anew, from a clean, clean disk.
Now why would I lie if I wanted help? the installation disk is an iso downloaded through MSDNAA academic program and licensed through the same institution.
I have been reading through this thread and it has been a mess...let me jump in a bit...

So I understand...you had malware->your formatted/clean install->malware came back->you are now fighting against the same malware again

I imagine that in the new installation you would have at some point pulled your Data off the external devices...that is where the infection lies. It explains why a new clean install is being infected without you downloading any of the cracks like you used to...




Yes, that is the long story short, but I recovered only PSD and mp3 files, no exe or scripts or anything in the neighborhood.

EDIT: It did return butnot completely, only partially, the first application that would start the unfortunate final destination 4 like chian of events, VIRTUAL GIRL HD, it came out of thin air with my UAC set to paranoid and AV+Firewall+Malware Shield on. It's like I would install it, even when I install files UAC jumps on my throat, accept or not, nothing like that ever happened.
 

My Computer My Computer

Computer Manufacturer/Model Number
Intel
OS
W7 X64 Ultimate, OSX, Linux
CPU
Intel Core i3 540M
Motherboard
Intel DH55TC
Memory
2GB Kingston DDR3 @ 1333MHz
Graphics Card(s)
nVidia gForce 250GTs, 512MB
Sound Card
OnBoard
Monitor(s) Displays
2xBenq E2200HDA
Screen Resolution
1920x1080
Hard Drives
Linux - 160GB WD 8MB Cache 7200rpm
OSX - 320GB Seagate Barracuda 16MB Cache 7200rpm
W7 - 80GB Seagate Barracude 8MB Cache 7200rpm
PSU
Antec 700W
Case
Cooler Master MidTower
Cooling
Standard
Keyboard
DeLux
Mouse
Logitech Wireless
Internet Speed
LAN/T1
Just plugging in that external drive, if infected, could be the transfer method of the files to your hard drive.
 

My Computer My Computer

Computer Manufacturer/Model Number
Self-Built in July 2009
OS
Windows 7 Ultimate x64
CPU
Intel Q9550 2.83Ghz OC'd to 3.40Ghz
Motherboard
Gigabyte GA-EP45-UD3R rev. 1.1, F12 BIOS
Memory
8GB G.Skill PI DDR2-800, 4-4-4-12 timings
Graphics Card(s)
EVGA 1280MB Nvidia GeForce GTX570
Sound Card
Realtek ALC899A 8 channel onboard audio
Monitor(s) Displays
23" Acer x233H
Screen Resolution
1920x1080
Hard Drives
Intel X25-M 80GB Gen 2 SSD
Western Digital 1TB Caviar Black, 32MB cache. WD1001FALS
PSU
Corsair 620HX modular
Case
Antec P182
Cooling
stock
Keyboard
ABS M1 Mechanical
Mouse
Logitech G9 Laser Mouse
Internet Speed
15/2 cable modem
Other Info
Windows and Linux enthusiast. Logitech G35 Headset.
Just plugging in that external drive, if infected, could be the transfer method of the files to your hard drive.
Exactly what I was thinking...it has to be the cause

Like I said it explains everything
 

My Computer My Computer

Computer Manufacturer/Model Number
Compal JFT02 (Custom Build Laptop)
OS
Windows 7 Home Premium x64 - Mac OS X 10.6.4 x64
CPU
Intel Core 2 Duo T9300 2.5 GHz
Motherboard
JFT02
Memory
4GB Kingston DDR2-800
Graphics Card(s)
NVIDIA Geforce 8600M GT (512MB Model)
Sound Card
Realtek HD Audio
Monitor(s) Displays
WUXGA Standard Laptop Display
Screen Resolution
1680*1050
Hard Drives
Toshiba 320GB 5400RPM Laptop HD
PSU
Standard Laptop Power Supply
Case
Standard Laptop Case
Cooling
Standard Laptop Cooling
Keyboard
Standard Laptop 105 Key-Keyboard
Mouse
Synaptics Touchpad
Internet Speed
Verizion Online DSL 3360/864 kbs (dl/up)
Just plugging in that external drive, if infected, could be the transfer method of the files to your hard drive.
Exactly what I was thinking...it has to be the cause

Like I said it explains everything


That external hard drive is COMPLETELY EMPTY, everything deleted on it(it was plugged in when the malware started to kick my pc in the balls), I didn't dare to format it yet until I recover at least my PSD's. After that, full format on everything, as i did with my other HDD on which W7 is installed...
 

My Computer My Computer

Computer Manufacturer/Model Number
Intel
OS
W7 X64 Ultimate, OSX, Linux
CPU
Intel Core i3 540M
Motherboard
Intel DH55TC
Memory
2GB Kingston DDR3 @ 1333MHz
Graphics Card(s)
nVidia gForce 250GTs, 512MB
Sound Card
OnBoard
Monitor(s) Displays
2xBenq E2200HDA
Screen Resolution
1920x1080
Hard Drives
Linux - 160GB WD 8MB Cache 7200rpm
OSX - 320GB Seagate Barracuda 16MB Cache 7200rpm
W7 - 80GB Seagate Barracude 8MB Cache 7200rpm
PSU
Antec 700W
Case
Cooler Master MidTower
Cooling
Standard
Keyboard
DeLux
Mouse
Logitech Wireless
Internet Speed
LAN/T1
Just plugging in that external drive, if infected, could be the transfer method of the files to your hard drive.
Exactly what I was thinking...it has to be the cause

Like I said it explains everything


That external hard drive is COMPLETELY EMPTY, everything deleted on it(it was plugged in when the malware started to kick my pc in the balls), I didn't dare to format it yet until I recover at least my PSD's. After that, full format on everything, as i did with my other HDD on which W7 is installed...
Well...either the External HD wasn't formatted as you thought (just because it appears empty doesn't mean it is) or you redwonloaded the malware un-expectantly...

Tews was quite right above...if the malware didn't resurface from the external drive or any other device that may have been corrupted...it had to have been re-downloaded (knowlingly or not)

That kind of malware just doesn't show up...the biggest clue is the fact that you are battling the SAME MALWARE as before
 

My Computer My Computer

Computer Manufacturer/Model Number
Compal JFT02 (Custom Build Laptop)
OS
Windows 7 Home Premium x64 - Mac OS X 10.6.4 x64
CPU
Intel Core 2 Duo T9300 2.5 GHz
Motherboard
JFT02
Memory
4GB Kingston DDR2-800
Graphics Card(s)
NVIDIA Geforce 8600M GT (512MB Model)
Sound Card
Realtek HD Audio
Monitor(s) Displays
WUXGA Standard Laptop Display
Screen Resolution
1680*1050
Hard Drives
Toshiba 320GB 5400RPM Laptop HD
PSU
Standard Laptop Power Supply
Case
Standard Laptop Case
Cooling
Standard Laptop Cooling
Keyboard
Standard Laptop 105 Key-Keyboard
Mouse
Synaptics Touchpad
Internet Speed
Verizion Online DSL 3360/864 kbs (dl/up)
Exactly what I was thinking...it has to be the cause

Like I said it explains everything


That external hard drive is COMPLETELY EMPTY, everything deleted on it(it was plugged in when the malware started to kick my pc in the balls), I didn't dare to format it yet until I recover at least my PSD's. After that, full format on everything, as i did with my other HDD on which W7 is installed...
Well...either the External HD wasn't formatted as you thought (just because it appears empty doesn't mean it is) or you redwonloaded the malware un-expectantly...

Tews was quite right above...if the malware didn't resurface from the external drive or any other device that may have been corrupted...it had to have been re-downloaded (knowlingly or not)

That kind of malware just doesn't show up...the biggest clue is the fact that you are battling the SAME MALWARE as before


Yep. I am almost finished backing up my projects, and I will reformat everything and fresh install everything, hopefully everything will be ok.
 

My Computer My Computer

Computer Manufacturer/Model Number
Intel
OS
W7 X64 Ultimate, OSX, Linux
CPU
Intel Core i3 540M
Motherboard
Intel DH55TC
Memory
2GB Kingston DDR3 @ 1333MHz
Graphics Card(s)
nVidia gForce 250GTs, 512MB
Sound Card
OnBoard
Monitor(s) Displays
2xBenq E2200HDA
Screen Resolution
1920x1080
Hard Drives
Linux - 160GB WD 8MB Cache 7200rpm
OSX - 320GB Seagate Barracuda 16MB Cache 7200rpm
W7 - 80GB Seagate Barracude 8MB Cache 7200rpm
PSU
Antec 700W
Case
Cooler Master MidTower
Cooling
Standard
Keyboard
DeLux
Mouse
Logitech Wireless
Internet Speed
LAN/T1
Could that malware be hiding in the Windows.old folder?
 

My Computer My Computer

Computer Manufacturer/Model Number
me / #1
OS
windows 7 x64 Home Premium
CPU
intel q6600
Motherboard
gigbyte ga ep45 ud3l
Memory
g.skill 8gb ddr2 1066 (pc2 8500)
Graphics Card(s)
evga geforce 9800 gtx 512 mb
Screen Resolution
1680 x 1050
Hard Drives
wd caviar black 500 gb
wd caviar black 1tb
wd elements 1tb external hd x2
PSU
raidmax 500w
Case
smilodon (yes, t'was the pretty blue lites that got me!)
Formatting is never enough, especially Win7 quick formatting.

You need full zeroing, which is CLEAN ALL in Diskpart, or use DBAN or your HD diagnostics Zero-disk option.
 
Formatting is never enough, especially Win7 quick formatting.

You need full zeroing, which is CLEAN ALL in Diskpart, or use DBAN or your HD diagnostics Zero-disk option.

I did not use W7 Quick Format, I used hiren Boot CD for full format.


Could that malware be hiding in the Windows.old folder?

Windows.old implies that I never formatted. And I did.



_________________________




So far everything Ok, I deleted last evening that Vghd.exe file and all it's registry entries and now nothign appeared since last night.
 

My Computer My Computer

Computer Manufacturer/Model Number
Intel
OS
W7 X64 Ultimate, OSX, Linux
CPU
Intel Core i3 540M
Motherboard
Intel DH55TC
Memory
2GB Kingston DDR3 @ 1333MHz
Graphics Card(s)
nVidia gForce 250GTs, 512MB
Sound Card
OnBoard
Monitor(s) Displays
2xBenq E2200HDA
Screen Resolution
1920x1080
Hard Drives
Linux - 160GB WD 8MB Cache 7200rpm
OSX - 320GB Seagate Barracuda 16MB Cache 7200rpm
W7 - 80GB Seagate Barracude 8MB Cache 7200rpm
PSU
Antec 700W
Case
Cooler Master MidTower
Cooling
Standard
Keyboard
DeLux
Mouse
Logitech Wireless
Internet Speed
LAN/T1
Formatting is never enough, especially Win7 quick formatting.

You need full zeroing, which is CLEAN ALL in Diskpart, or use DBAN or your HD diagnostics Zero-disk option.


A usual format is enough, provided the MBR is clean. MBR can be cleaned by using Diskpart clean command (without all), after that, any malware leftovers are quite beyond resurrection. Zeroing the drive is a time consuming overkill - in my opinion.
 

My Computer My Computer

Computer Manufacturer/Model Number
Asus N73SV
OS
Windows 7 x64 Ultimate SP1
CPU
Core i7-2630QM
Motherboard
Intel HM 65
Memory
6 GB DDR3
Graphics Card(s)
Nvidia GT 540M / Intel HD 3000 - Optimus switching
Sound Card
HD Audio (Intel Azalia/Realtek) ALC269
Monitor(s) Displays
LED flat panel
Screen Resolution
1920 x 1080
Hard Drives
2x Seagate Momentus 640 GB - 1,28 TB in total
Internet Speed
4 MB/256 kbps
Other Info
External HDs

WD Elements 1,5 TB
WD MyBook 500 GB
In this case the OP system was so infested that IMO a full zeroing of the drive was the only way of insuring that re-infestation would not occur ... we have yet to see what he/she has done...
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
LENOVO K450 @3.0GHZ
OS
64-bit Windows 8.1 Pro
CPU
Core(TM) i5 CPU 4330 Haswell @ 3.20GHz
Motherboard
LENOVO
Memory
12.00 GB
Graphics Card(s)
Intel(R) HD Graphics
Sound Card
Intel HD integtrated
Monitor(s) Displays
HP 25' ISP Monitor
Screen Resolution
1900/1020
Hard Drives
(1) ST1000DM003-1CH162 (2) Generic STORAGE DEVICE USB Device (3) Generic STORAGE DEVICE USB Device
Internet Speed
100mb down/10mb up
I agree.
Nuke the drive using DBAN or something similar.

Sorry, your pirating has removed all other options.

~Lordbob
 

My Computer My Computer

Computer Manufacturer/Model Number
Hera
OS
Windows 7 Ultimate x64, Mint 9
CPU
Intel i5-2500k
Motherboard
ASUS P8P67 Pro
Memory
2x 4Gb Corsair VENGEANCE DDR3-1600
Graphics Card(s)
NVidia GeForce N260GTX Twin Frozr
Sound Card
Realtek HD OnBoard Audio
Monitor(s) Displays
ASUS 24" Monitor
Screen Resolution
1920x1080
Hard Drives
G.SKILL Phoenix Series 60GB SATA II MLC Internal Solid State Drive (SSD)
SAMSUNG Spinpoint F3R 1TB 7200 RPM 32MB Cache SATA II
PSU
Cooler Master Real Power Pro 750W
Case
Cooler Master Haf 932
Cooling
Fans
Keyboard
Razer Tarantula
Mouse
Razer Lachesis
Internet Speed
not fast enough
Hey, everything seems OK now, I am scanning daily, nothing appeared so far. Why do people relate to pirating everytime, I know that is the biggest source of malware, as I told you, I use cracked software only if IT IS VERY NECESSARY(meaning I do not have the money to buy it, Romanian wages SUCK!), anyhow, there's much to comment on this, illegal, non-ethical, dangerous etc.

E.g. A full Master Collection CS4 license here in Romania equals 23months of not paying the rent.
 

My Computer My Computer

Computer Manufacturer/Model Number
Intel
OS
W7 X64 Ultimate, OSX, Linux
CPU
Intel Core i3 540M
Motherboard
Intel DH55TC
Memory
2GB Kingston DDR3 @ 1333MHz
Graphics Card(s)
nVidia gForce 250GTs, 512MB
Sound Card
OnBoard
Monitor(s) Displays
2xBenq E2200HDA
Screen Resolution
1920x1080
Hard Drives
Linux - 160GB WD 8MB Cache 7200rpm
OSX - 320GB Seagate Barracuda 16MB Cache 7200rpm
W7 - 80GB Seagate Barracude 8MB Cache 7200rpm
PSU
Antec 700W
Case
Cooler Master MidTower
Cooling
Standard
Keyboard
DeLux
Mouse
Logitech Wireless
Internet Speed
LAN/T1
E.g. A full Master Collection CS4 license here in Romania equals 23months of not paying the rent.
It is a shame that software like this is so expensive for you.

On the other hand...maybe it's not really necessary for you to need/use a full Master Collection CS4 license.

There are other alternatives out there which aren't this expensive...and maybe not as cool, trendy or the de facto standard...but when the defacto standard is so darn expensive sometimes sacrifices are necessary.

I have numerous computers at home, but I only run Windows 7 on one of them because paying the cost for windows upgrades is too expensive for me to justify on my other computers. So, some will stay with the Vista they came with, 1 still uses the Windows XP it was licensed with and the remainder run Linux as cost here is a non-issue.
 

My Computer My Computer

Computer Manufacturer/Model Number
Self-Built in July 2009
OS
Windows 7 Ultimate x64
CPU
Intel Q9550 2.83Ghz OC'd to 3.40Ghz
Motherboard
Gigabyte GA-EP45-UD3R rev. 1.1, F12 BIOS
Memory
8GB G.Skill PI DDR2-800, 4-4-4-12 timings
Graphics Card(s)
EVGA 1280MB Nvidia GeForce GTX570
Sound Card
Realtek ALC899A 8 channel onboard audio
Monitor(s) Displays
23" Acer x233H
Screen Resolution
1920x1080
Hard Drives
Intel X25-M 80GB Gen 2 SSD
Western Digital 1TB Caviar Black, 32MB cache. WD1001FALS
PSU
Corsair 620HX modular
Case
Antec P182
Cooling
stock
Keyboard
ABS M1 Mechanical
Mouse
Logitech G9 Laser Mouse
Internet Speed
15/2 cable modem
Other Info
Windows and Linux enthusiast. Logitech G35 Headset.
A usual format is enough, provided the MBR is clean. MBR can be cleaned by using Diskpart clean command (without all), after that, any malware leftovers are quite beyond resurrection. Zeroing the drive is a time consuming overkill - in my opinion.
True. As long as program code is not referenced/executed it is harmless. All kinds of malware that was active in the old file system is no longer active after a simple quick format.

A little edit-note: it was first in Vista that zeroing was introduced in the builtin formatting utility. Before that a full format didn't erase more sectors than a quick format did.
 

My Computer My Computer

OS
Windows
A usual format is enough, provided the MBR is clean. MBR can be cleaned by using Diskpart clean command (without all), after that, any malware leftovers are quite beyond resurrection. Zeroing the drive is a time consuming overkill - in my opinion.
True. As long as program code is not referenced/executed it is harmless. All kinds of malware that was active in the old file system is no longer active after a simple quick format.

A little edit-note: it was first in Vista that zeroing was introduced in the builtin formatting utility. Before that a full format didn't erase more sectors than a quick format did.



If you used Hiren's to format Win7, you should have applied Win7 formatting from the DVD before installing. XP formatting is incompatible; a slightly different partition table.
 
Last edited:
I've never had to zero a drive to remove a trojan or virus and I've been doing it for 15+ years. Your mileage may vary.
 

My Computer My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 Ultimate RTM (Technet)
CPU
3.00 gigahertz Intel Core2 Duo E8400
Motherboard
ASUSTeK Computer INC. P5K/EPU Rev 1.xx
Memory
4GB
Graphics Card(s)
ATI Radeon X1950 Pro
Sound Card
Built in HD Audio
Monitor(s) Displays
22" Gateway LCD
Screen Resolution
1920 x 1200
Hard Drives
ST3160023A [Hard drive] (160.04 GB) -- drive 0, rev 8.01, ST3500630AS [Hard drive] (500.11 GB) -- drive 2, rev 3.AAK
ST3500630AS [Hard drive] (500.11 GB) -- drive 1, rev 3.AAK
Keyboard
Logitech G11
Mouse
Microsoft Wireless Laser Mouse 5000
Internet Speed
13.44 Mbps
c.) Always, always, ALWAYS have a Backup Plan in place. Whether you burn your data to DVD, have a backup HDD, RAID configuration, online storage, etc. This is probably the single most important best practice that many PC users still neglect until it's too late.

Not trying to nitpick...but;

RAID should never be confused with a backup. Even with a mirrored config, if you accidentally delete a file or get a virus which wipes out files..it gets both hard drives instantly. RAID is strictly for performance or for using multiple drives to make a large single drive...even with the various levels or redundancy.

If you have a spare hard drive at home, disconnect your normal drive. Use the secondary as a test hard drive...just load the OS from your OS disc and see what you get. If you have something right from step 1..your OS is obviously been compromised.


My OP has been corrected and I appreciate your feedback.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Desktop PC
OS
Windows 7 / Windows 8.1
CPU
Devils Canyon i7-4790K @ 4.8 GHz ~ 1.33v
Motherboard
Asus Z97 Deluxe
Memory
Corsair Vengeance Pro PC3-19200 DDR3 2400MHz
Graphics Card(s)
EVGA GeForce GTX 980 SuperClocked ACX 2.0
Sound Card
Realtek ALC1150 8 channels
Monitor(s) Displays
BenQ XL2720Z 27"
Screen Resolution
1920 x 1080 @ 144Hz
Hard Drives
SSD1: 512GB Samsung 850 Pro
SSD2: 1TB Samsung 850 EVO
SSD3: 1TB Samsung 850 EVO
HDD: 4TB Western Digital Black
Backup: Western Digital My Book Duo 8TB
PSU
Corsair HX1000i / CyberPower CP1500PFCLCD PFC Sinewave UPS 1
Case
Corsair Graphite 780T
Cooling
Custom single loop liquid; CPU delidded; Aerocool DS Fans
Keyboard
Logitech G710 Cherry MX Blue
Mouse
LogitechG502 Proteus Core
Internet Speed
Download: 119MBs /Upload 39.12MBs via Optimum 101 Ultra
Antivirus
MYOB
Browser
Firefox
Other Info
Cooling: EK-Supremecy MX Waterblock, XSPC AX360 Radiator, Swiftech MCP655 Series 12VDC D5 Pump, EK-RES x3 250 Reservoir, Primochill Ice Intensified Coolant, 11x AerocoolDS fans, Primochill Primoflex Avanced LRT Tubing
Back
Top