ENTIRE HDD Erased!

I've never had to zero a drive to remove a trojan or virus and I've been doing it for 15+ years. Your mileage may vary.

My understanding is zeroing isn't to remove infections but to reinstall cleanly when using a previously infected HD.
 
Last edited:
Zeroing was the full format offered (and used by most tech enthusiasts) in XP and before. It was removed in Vista.

Uhm, no. Zeroing was introduced with Vista

Change in the behavior of the format command in Windows Vista

"The format command behavior has changed in Windows Vista. By default in Windows Vista, the format command writes zeros to the whole disk when a full format is performed. In Windows XP and in earlier versions of the Windows operating system, the format command does not write zeros to the whole disk when a full format is performed."
 

My Computer My Computer

OS
Windows
Zeroing was the full format offered (and used by most tech enthusiasts) in XP and before. It was removed in Vista.

Uhm, no. Zeroing was introduced with Vista

Change in the behavior of the format command in Windows Vista

"The format command behavior has changed in Windows Vista. By default in Windows Vista, the format command writes zeros to the whole disk when a full format is performed. In Windows XP and in earlier versions of the Windows operating system, the format command does not write zeros to the whole disk when a full format is performed."

I may be wrong about Vista. I don't go there often, and thought the quick format began then.

But what was the full format in XP?

Heard a lot of complaining when it was dumped in Win7, that it had been zeroing.
 
Last edited:
A full format in xp was just quick format plus scanning for bad sectors. Nothing more.
 

My Computer My Computer

OS
Windows
Best you can do at this point since all the messed up, is do a complete reformat/reinstall. Get a decent firewall like comodo firewall (it's free and works great). And leave UAC turned on (default settings) just in case. Also a basic antivirus like Microsoft Security Essential (free and effective). And be careful of what you download. The Adobe CS4 master collection was that pirated? If so possibly there might have been a virus in there. Also that keylogger...might want to get rid of it! Also while browsing try to use firefox as much as possible with addons like "No script", "Adblock Plus", and "WOT" these addons come in as a very handy security measure while surfing the web. No script will block all unwanted scripts. Adblock will block all stupid adds which could lead to malware. And WOT (web of trust) will warn you of dangerous websites.
 

My Computer My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 Ultimate 64bit
CPU
AMD Phenom II x3 720 @ 2.8GHz
Motherboard
Gigabyte MA-770T-UD3P
Memory
G.Skill 4GB DDR3 1333MHz
Graphics Card(s)
NVIDIA GeForce 9800GT DDR3 512 mb
Sound Card
Creative Sound blaster X-Fi
Monitor(s) Displays
Acer X193W+BD Black 19"
Screen Resolution
1680 x 1050
Hard Drives
Intel x25-m gen2 80GB SSD disk.
WD Caviar Black 500GB, 7200RPM 3.0GB/s
PSU
Rosewill 585W Power Supply
Case
COOLER MASTER Centurion 5 CAC-T05-UW Black Aluminum Bezel ,
I read most of the messages here. I really sorry to hear about your computer and HD.
One thing I would like to say is that it seems that your HD gets reinfected each time.
I would suggest you scan all the CD's or DVD's you have and used to install your Projects.
I think you have maybe copied the bad stuff when you made your backup copies.
Good luck and keep us posted on your progress.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Windows 10 Pro
CPU
Intel i5
Motherboard
I have a fatherboard
Memory
I'm old and lost a few chips
Graphics Card(s)
Yup
Sound Card
Yup
Monitor(s) Displays
Samsung 32" UHD
Screen Resolution
3840 x 2160
Hard Drives
Samsung 860 EVO drives
PSU
450 Watt and some fans that blow
Case
Small tower
Cooling
Yes I am cool. lol
Keyboard
Who needs a keyboard?
Mouse
Logitech Laser G7 wireless
Internet Speed
Zippy fast UP and DOWN
Antivirus
I got a shot
Browser
The new Improved EDGE 2020
In your opinion, is there any advantage to zeroing?
There is and isn't.

Zeroing can eliminate any data that may be accessible by addressing (ie. head, sector, blocks).
If a virus is capable of preforming such a task, then it could reinfect that way.
I do not know if zeroing hits the MBR, etc.

To be honest,, I have never had to zero a drive to eliminate a virus.
If i did it, it was just to wipe out all accessible regions of the drive. Just to make sure there was no data accessible to the OS or anything else. But then I learned about int13 debugging. Basically debug the HDD to set back to factory settings, as I understand it. But, this is not a good idea with Sata drive (i have read) and really bad idea on SSD.

(note: accessible regions) which brings up another caveat to the HDD realm that a lot of people don't know. When a HDD discovers a bad block, it marks that block as unusable. Whatever data was there when marked may get copied to a good block (if possible). That data remains and is never over-written by any software or other means cause the inner workings of the drive say that block no long exists. So, when you wipe a drive, those bad blocks never get touched. Forensics however, can read those blocks, so whatever data is there can be accessed.

In the newest drives, there is a built in command that you can invoke to wipe the entire drive including bad blocks. This won't make them not bad, but it will eliminate the data located there, or attempt to.

This article explains it better than I can.

and more importantly,, this one

and this

Cool eh?
 
Last edited:

My Computer My Computer

Computer Manufacturer/Model Number
Self Built
OS
Win 7 Ultimate 32bit
CPU
C2D E6600 2.4Ghz
Motherboard
Intel D965WH
Memory
4G Kingston KHX5400D2
Graphics Card(s)
EVGA GTX 570 HD SC (012-P3-1573-KR)
Sound Card
On-Board
Monitor(s) Displays
Samsung 226BW
Screen Resolution
1680 x 1050
Hard Drives
2 x 250 Seagate Barracuda
2 x 500 Seagate Barracuda (Raid1)
PSU
Corsair TX750W
Case
In-Win C589
Cooling
Stock Intel Cooling
(note: accessible regions) which brings up another caveat to the HDD realm that a lot of people don't know. When a HDD discovers a bad sector, it marks that sector as unusable. Whatever data was there when marked may get copied to a good sector (if possible). That data remains and is never over-written by any software or other means cause the inner workings of the drive say that sector no long exists. So, when you wipe a drive, those bad sectors never get touched.

I wonder if that could be used by a virus to hide in. Trick the HD into thinking that sector is "bad", until it wants to activate itself. Then it could trick the drive again, this time declaring the sector "good" and emerge from its safe cocoon.
 

My Computer My Computer

Computer Manufacturer/Model Number
me / #1
OS
windows 7 x64 Home Premium
CPU
intel q6600
Motherboard
gigbyte ga ep45 ud3l
Memory
g.skill 8gb ddr2 1066 (pc2 8500)
Graphics Card(s)
evga geforce 9800 gtx 512 mb
Screen Resolution
1680 x 1050
Hard Drives
wd caviar black 500 gb
wd caviar black 1tb
wd elements 1tb external hd x2
PSU
raidmax 500w
Case
smilodon (yes, t'was the pretty blue lites that got me!)
I wonder if that could be used by a virus to hide in. Trick the HD into thinking that block is "bad", until it wants to activate itself. Then it could trick the drive again, this time declaring the sector "good" and emerge from its safe cocoon.

To my knowledge you can not set a bad block as good once it is marked as bad by the drive.

Every HDD is alloted a certain number of bad blocks before the HDD will begin to fail or produce errors of eminate failure.

Every HDD already has bad blocks on the drive and there is no way (that I know of) to know how many Bad Blocks exist on new drives. But it is well under what is allotted. You would need to do more research if you want more info on this. I am going off of old memory here.

The only way to make a Block completely disappear (like bad block marking) is by the drive setting the block bad. Otherwise the sector is visible to any software. I could be wrong, or there is some secret black ops type thing, but if it were known,, I think it would common knowledge an we would see software designed to use such a trick for security reasons other than encryption.

You can hide sections of the drive by partitioning and hiding the partition, yes. But this is not the same thing.

Which is also why you need to use the Drives Built-in Secure Erase feature to wipe bad sectors also.

I keep saying Sectors,,, it should be Blocks.... I am going to fix it,, but if you see sector in my previous posts, then I probably actually mean Block
 

My Computer My Computer

Computer Manufacturer/Model Number
Self Built
OS
Win 7 Ultimate 32bit
CPU
C2D E6600 2.4Ghz
Motherboard
Intel D965WH
Memory
4G Kingston KHX5400D2
Graphics Card(s)
EVGA GTX 570 HD SC (012-P3-1573-KR)
Sound Card
On-Board
Monitor(s) Displays
Samsung 226BW
Screen Resolution
1680 x 1050
Hard Drives
2 x 250 Seagate Barracuda
2 x 500 Seagate Barracuda (Raid1)
PSU
Corsair TX750W
Case
In-Win C589
Cooling
Stock Intel Cooling
Virtual Girl HD appeared two times since the last time I posted, I deleted it every time and rescaned, no malware found, I start to think that there is some sort of downloader inside my MBR(I deleted it and rebuilt it, hope nothing comes back). I am throughly scanning my projects, burn them again to DVD, and than full zeroing.
 

My Computer My Computer

Computer Manufacturer/Model Number
Intel
OS
W7 X64 Ultimate, OSX, Linux
CPU
Intel Core i3 540M
Motherboard
Intel DH55TC
Memory
2GB Kingston DDR3 @ 1333MHz
Graphics Card(s)
nVidia gForce 250GTs, 512MB
Sound Card
OnBoard
Monitor(s) Displays
2xBenq E2200HDA
Screen Resolution
1920x1080
Hard Drives
Linux - 160GB WD 8MB Cache 7200rpm
OSX - 320GB Seagate Barracuda 16MB Cache 7200rpm
W7 - 80GB Seagate Barracude 8MB Cache 7200rpm
PSU
Antec 700W
Case
Cooler Master MidTower
Cooling
Standard
Keyboard
DeLux
Mouse
Logitech Wireless
Internet Speed
LAN/T1
Lol, very true! :D
I would recommend formatting and installing thing step by step, wait and see when VGirl HD comes back
 

My Computer My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 build 7600 64 bit
CPU
Phenom II X4 955 retail 3.2GHz
Motherboard
ASRock M3A790GXH/USB3 ATX AMD AMD3
Memory
4x GeiL 2GB Value PC3-10660 CL9 DC DDR3-1333, CL 9-9-9-28
Graphics Card(s)
PowerColor Radeon HD5850 PCS+ 1024MB, 256-bit GDDR5
Sound Card
Built in
Hard Drives
G.Skill Phoenix Pro 120GB SATA2 SSD Sandforce SF-120
Samsung Spinpoint 500GB SATA2 7200RPM
PSU
Tacens Radix III Smart 520W
Virtual Girl HD appeared two times since the last time I posted, I deleted it every time and rescaned, no malware found, I start to think that there is some sort of downloader inside my MBR(I deleted it and rebuilt it, hope nothing comes back). I am throughly scanning my projects, burn them again to DVD, and than full zeroing.

Do you perhaps have another computer on your network that is infected? Or perhaps running an open access point and a neighbor or other unknown wireless user is infecting you?
 

My Computer My Computer

Computer Manufacturer/Model Number
Self-Built in July 2009
OS
Windows 7 Ultimate x64
CPU
Intel Q9550 2.83Ghz OC'd to 3.40Ghz
Motherboard
Gigabyte GA-EP45-UD3R rev. 1.1, F12 BIOS
Memory
8GB G.Skill PI DDR2-800, 4-4-4-12 timings
Graphics Card(s)
EVGA 1280MB Nvidia GeForce GTX570
Sound Card
Realtek ALC899A 8 channel onboard audio
Monitor(s) Displays
23" Acer x233H
Screen Resolution
1920x1080
Hard Drives
Intel X25-M 80GB Gen 2 SSD
Western Digital 1TB Caviar Black, 32MB cache. WD1001FALS
PSU
Corsair 620HX modular
Case
Antec P182
Cooling
stock
Keyboard
ABS M1 Mechanical
Mouse
Logitech G9 Laser Mouse
Internet Speed
15/2 cable modem
Other Info
Windows and Linux enthusiast. Logitech G35 Headset.
what is the status of the problem?
 

My Computer My Computer

Computer Manufacturer/Model Number
SevenForums
OS
7 Prof
CPU
Q9550
Motherboard
Maximus II Formula
Memory
2x2 Mushkin Ascent 8500
Graphics Card(s)
4870X2
Sound Card
X-Fi Xtreme Gamer
Monitor(s) Displays
LN32A550
Screen Resolution
1920x1080
Hard Drives
Intel G2 80GB
5x1TB
PSU
Corsair 1000
Case
Cosmos
Cooling
Yates^13
Keyboard
G15v1
Mouse
MX518
Internet Speed
6Mbps
Zeroed everything, after a succesfull attempt of VHHD tonight of deleteing all the content on both of my computers .....

Honestly I am sick of this, I am two weeks late on 3-4 projects of mine, my clients are killing me, I am installing MacOSX and continue my work, and when I am done with everything I am going to kill it again and again, btw, how does sound a bios virus?
 

My Computer My Computer

Computer Manufacturer/Model Number
Intel
OS
W7 X64 Ultimate, OSX, Linux
CPU
Intel Core i3 540M
Motherboard
Intel DH55TC
Memory
2GB Kingston DDR3 @ 1333MHz
Graphics Card(s)
nVidia gForce 250GTs, 512MB
Sound Card
OnBoard
Monitor(s) Displays
2xBenq E2200HDA
Screen Resolution
1920x1080
Hard Drives
Linux - 160GB WD 8MB Cache 7200rpm
OSX - 320GB Seagate Barracuda 16MB Cache 7200rpm
W7 - 80GB Seagate Barracude 8MB Cache 7200rpm
PSU
Antec 700W
Case
Cooler Master MidTower
Cooling
Standard
Keyboard
DeLux
Mouse
Logitech Wireless
Internet Speed
LAN/T1
karthurk,

I feel for you. I don't think it's a BIOS virus. I'm still convinced it's in your data files, or some shady cracked application that you think is fine.

While moving to OSX might help, you say it like it's Windows' fault that you are in this predicament. Poor choices as an end user can cause problems in both operating systems.
 

My Computer My Computer

Computer Manufacturer/Model Number
Self-Built in July 2009
OS
Windows 7 Ultimate x64
CPU
Intel Q9550 2.83Ghz OC'd to 3.40Ghz
Motherboard
Gigabyte GA-EP45-UD3R rev. 1.1, F12 BIOS
Memory
8GB G.Skill PI DDR2-800, 4-4-4-12 timings
Graphics Card(s)
EVGA 1280MB Nvidia GeForce GTX570
Sound Card
Realtek ALC899A 8 channel onboard audio
Monitor(s) Displays
23" Acer x233H
Screen Resolution
1920x1080
Hard Drives
Intel X25-M 80GB Gen 2 SSD
Western Digital 1TB Caviar Black, 32MB cache. WD1001FALS
PSU
Corsair 620HX modular
Case
Antec P182
Cooling
stock
Keyboard
ABS M1 Mechanical
Mouse
Logitech G9 Laser Mouse
Internet Speed
15/2 cable modem
Other Info
Windows and Linux enthusiast. Logitech G35 Headset.
Honestly the only apps that I need are Photoshop and Dreamweaver at the moment to finish everything I have to do ... Anyhow, no more Christmas for me ... WORK WORK WORK. Who said Santa Clause doesn't exist?

I'm gonna reinstall win7 after this is done with all of my drives zeroed, I am not gonna copy any of my projects and if VGHD returns .... oh well, I'll see then.
 

My Computer My Computer

Computer Manufacturer/Model Number
Intel
OS
W7 X64 Ultimate, OSX, Linux
CPU
Intel Core i3 540M
Motherboard
Intel DH55TC
Memory
2GB Kingston DDR3 @ 1333MHz
Graphics Card(s)
nVidia gForce 250GTs, 512MB
Sound Card
OnBoard
Monitor(s) Displays
2xBenq E2200HDA
Screen Resolution
1920x1080
Hard Drives
Linux - 160GB WD 8MB Cache 7200rpm
OSX - 320GB Seagate Barracuda 16MB Cache 7200rpm
W7 - 80GB Seagate Barracude 8MB Cache 7200rpm
PSU
Antec 700W
Case
Cooler Master MidTower
Cooling
Standard
Keyboard
DeLux
Mouse
Logitech Wireless
Internet Speed
LAN/T1
Karthurk, do you use a router or a network storage drive?

~Lordbob
 

My Computer My Computer

Computer Manufacturer/Model Number
Hera
OS
Windows 7 Ultimate x64, Mint 9
CPU
Intel i5-2500k
Motherboard
ASUS P8P67 Pro
Memory
2x 4Gb Corsair VENGEANCE DDR3-1600
Graphics Card(s)
NVidia GeForce N260GTX Twin Frozr
Sound Card
Realtek HD OnBoard Audio
Monitor(s) Displays
ASUS 24" Monitor
Screen Resolution
1920x1080
Hard Drives
G.SKILL Phoenix Series 60GB SATA II MLC Internal Solid State Drive (SSD)
SAMSUNG Spinpoint F3R 1TB 7200 RPM 32MB Cache SATA II
PSU
Cooler Master Real Power Pro 750W
Case
Cooler Master Haf 932
Cooling
Fans
Keyboard
Razer Tarantula
Mouse
Razer Lachesis
Internet Speed
not fast enough
writing with wirtual keyboard, gonna be brief, just poured juie. i have a d-link di524 router
 

My Computer My Computer

Computer Manufacturer/Model Number
Intel
OS
W7 X64 Ultimate, OSX, Linux
CPU
Intel Core i3 540M
Motherboard
Intel DH55TC
Memory
2GB Kingston DDR3 @ 1333MHz
Graphics Card(s)
nVidia gForce 250GTs, 512MB
Sound Card
OnBoard
Monitor(s) Displays
2xBenq E2200HDA
Screen Resolution
1920x1080
Hard Drives
Linux - 160GB WD 8MB Cache 7200rpm
OSX - 320GB Seagate Barracuda 16MB Cache 7200rpm
W7 - 80GB Seagate Barracude 8MB Cache 7200rpm
PSU
Antec 700W
Case
Cooler Master MidTower
Cooling
Standard
Keyboard
DeLux
Mouse
Logitech Wireless
Internet Speed
LAN/T1
Back
Top