Virus remains after formatting

windude,
Certainly another approach.
DiskPart writes zeros, one pass to all bytes.
Sufficient for everyone except for the FBI and CIA.
 

My Computer My Computer

Computer Manufacturer/Model Number
Toshiba Satellite S875D-S7239 laptop
OS
MS Windows 7 Ultimate SP1 64-bit
CPU
AMD A10-4600M
Motherboard
AMD Pumori (Socket FT1)
Memory
6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28)
Graphics Card(s)
AMD Radeon HD 7660G
Sound Card
High Definition Audio Device
Monitor(s) Displays
Generic PnP Monitor (1600x900@60Hz)
Screen Resolution
1600x900@60Hz
Hard Drives
SSD 119GB Corsair CSSD-V128GB2 ATA Device
Keyboard
Standard PS/2 Keyboard
Mouse
HP Wireless Optical Mobile Mouse Model FHA-3410
Internet Speed
What the local pub, local coffee shop offers.
Other Info
Optical Drive:MATSHITA BD-CMB UJ160B ATA Device


Also have an Asus ha1002xp netbook with Win 7 Ultimate installed.
Maybe the router is compromised. If the win7 disk is clean or maybe a usb or external hard drive. Also could be something in an email or online storage account. Possibly another infected computer on your network. I would log into the router and change the password. Then see if you can update the router. Could also be a false positive too.
 

My Computer My Computer

Computer Manufacturer/Model Number
Samsung rv520
OS
Windows Seven, Ubuntu
CPU
Intel
Graphics Card(s)
Intel
all good suggestions. however I haven't seen that the victim here has actually secure-wiped yet. if not, then it is entirely possible that a scan would pickup an obfuscated infection ... not that hard to do. whether it is 'live' or not is a different question.
secondly - this is stating the obvious I realize - every cleanup I can imagine involves saving off one's valuables, then restoring those valuables. Obviously you would want to save the valuables, SCAN the valuables, and exterminate any that are compromised before restoring.
 

My Computer My Computer

Computer Manufacturer/Model Number
HP DC7600, HP DC7600[2], HP DC7100, Samsung NC10
OS
Windows XP Pro SP3, Windows 7 Pro 32-bit, Windows 7 Ultimate 64bit, Windows XP Home SP3
CPU
Pentium 4 3.2GHz, Pentium 4 3.4GHz 64bit, Atom,
Motherboard
Dunno
Memory
4GB matched, 1GB, 2.5GB, 4.0 GB
Graphics Card(s)
Geforce 8400 GS and others
Sound Card
RealteK ALC260 and others
Monitor(s) Displays
Asus HD
Screen Resolution
1920x1080
Hard Drives
WD Caviar 640gb SATA
Cooling
We Be Cool
zapp,
a secure wipe is not needed, but what is needed is a wipe, that is, overwriting each and every byte.
 

My Computer My Computer

Computer Manufacturer/Model Number
Toshiba Satellite S875D-S7239 laptop
OS
MS Windows 7 Ultimate SP1 64-bit
CPU
AMD A10-4600M
Motherboard
AMD Pumori (Socket FT1)
Memory
6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28)
Graphics Card(s)
AMD Radeon HD 7660G
Sound Card
High Definition Audio Device
Monitor(s) Displays
Generic PnP Monitor (1600x900@60Hz)
Screen Resolution
1600x900@60Hz
Hard Drives
SSD 119GB Corsair CSSD-V128GB2 ATA Device
Keyboard
Standard PS/2 Keyboard
Mouse
HP Wireless Optical Mobile Mouse Model FHA-3410
Internet Speed
What the local pub, local coffee shop offers.
Other Info
Optical Drive:MATSHITA BD-CMB UJ160B ATA Device


Also have an Asus ha1002xp netbook with Win 7 Ultimate installed.
Hi Guys
I have also get such a kind of a virus
To wipe it out i filled the bootpartition up to the fat with zeros, there are 62 sectors to overwrite,
i used a utility of Acronis disk partion, thyat boots up the computer with a local windows stored
in this utility.
i
then i put a clean windows without any programs or drivers , installed my virusscanner
deleted the infected files and gone was the virus.

I hope this will help

icy00
 

My Computer My Computer

OS
Windows 7 32 & 64 bit , XP
Icy,
the DISKPART Clean command does this for you and also catches the duplicate copy at the end of the disk.

Win 7 requires NTFS and DiskPart works with NTFS perfectly.

Your virus would have been gone.
 

My Computer My Computer

Computer Manufacturer/Model Number
Toshiba Satellite S875D-S7239 laptop
OS
MS Windows 7 Ultimate SP1 64-bit
CPU
AMD A10-4600M
Motherboard
AMD Pumori (Socket FT1)
Memory
6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28)
Graphics Card(s)
AMD Radeon HD 7660G
Sound Card
High Definition Audio Device
Monitor(s) Displays
Generic PnP Monitor (1600x900@60Hz)
Screen Resolution
1600x900@60Hz
Hard Drives
SSD 119GB Corsair CSSD-V128GB2 ATA Device
Keyboard
Standard PS/2 Keyboard
Mouse
HP Wireless Optical Mobile Mouse Model FHA-3410
Internet Speed
What the local pub, local coffee shop offers.
Other Info
Optical Drive:MATSHITA BD-CMB UJ160B ATA Device


Also have an Asus ha1002xp netbook with Win 7 Ultimate installed.
Icy,
the DISKPART Clean command does this for you and also catches the duplicate copy at the end of the disk.

Win 7 requires NTFS and DiskPart works with NTFS perfectly.

Your virus would have been gone.

I don't think the DISKPART Clean command cares whether the disk contains NTFS, FAT, FAT32 or any other type of partition that may exist on the disk. For an MBR disk it simply zeroes out the partitioning information and hidden sector information that follows (when using 'Clean', rather than 'Clean All').

The data for each partition remains, including boot records, MFTs, etc. Including any of their mirrors/backups. The data is simply not recognized by the MBR any longer.
 

My Computer My Computer

OS
Windows 7 Ultimate x64
Hi Guys

DISKPART is an internal command of the opera
 

My Computer My Computer

OS
Windows 7 32 & 64 bit , XP
icy,
Are you having problems of some kind?
You're posts are not making the greatest amount of sense.
 

My Computer My Computer

Computer Manufacturer/Model Number
Toshiba Satellite S875D-S7239 laptop
OS
MS Windows 7 Ultimate SP1 64-bit
CPU
AMD A10-4600M
Motherboard
AMD Pumori (Socket FT1)
Memory
6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28)
Graphics Card(s)
AMD Radeon HD 7660G
Sound Card
High Definition Audio Device
Monitor(s) Displays
Generic PnP Monitor (1600x900@60Hz)
Screen Resolution
1600x900@60Hz
Hard Drives
SSD 119GB Corsair CSSD-V128GB2 ATA Device
Keyboard
Standard PS/2 Keyboard
Mouse
HP Wireless Optical Mobile Mouse Model FHA-3410
Internet Speed
What the local pub, local coffee shop offers.
Other Info
Optical Drive:MATSHITA BD-CMB UJ160B ATA Device


Also have an Asus ha1002xp netbook with Win 7 Ultimate installed.
Hi Guys

DISKPART is an internal command of the operating system , this is not working with bootviruses.
Bootvirusses boot before the opperating system boots and they will intercept all calls &
interupts to the disks.
the only method to clean is to boot before the virus boots, then only will these 61 sectors
be overwritten.

icy
 

My Computer My Computer

OS
Windows 7 32 & 64 bit , XP
icy,
DiskPart run from the System Repair Disc or from the Win 7 installer pgrm does not boot up Win 7.

Both of those have them run a PE (preexecution environment) from ram. There is not boot to be intercepted.
 

My Computer My Computer

Computer Manufacturer/Model Number
Toshiba Satellite S875D-S7239 laptop
OS
MS Windows 7 Ultimate SP1 64-bit
CPU
AMD A10-4600M
Motherboard
AMD Pumori (Socket FT1)
Memory
6.00 GB Dual-Channel DDR3 @ 798MHz (11-11-12-28)
Graphics Card(s)
AMD Radeon HD 7660G
Sound Card
High Definition Audio Device
Monitor(s) Displays
Generic PnP Monitor (1600x900@60Hz)
Screen Resolution
1600x900@60Hz
Hard Drives
SSD 119GB Corsair CSSD-V128GB2 ATA Device
Keyboard
Standard PS/2 Keyboard
Mouse
HP Wireless Optical Mobile Mouse Model FHA-3410
Internet Speed
What the local pub, local coffee shop offers.
Other Info
Optical Drive:MATSHITA BD-CMB UJ160B ATA Device


Also have an Asus ha1002xp netbook with Win 7 Ultimate installed.
DISKPART is an internal command of the operating system , this is not working with bootviruses.

Nonsense - DISKPART and CLEAN/CLEAN ALL can be accessed from any Windows 7 installation ISO and run during bootup from said ISO, prior to the boot manager being loaded.

Regards,
Golden
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
icy,
DiskPart run from the System Repair Disc or from the Win 7 installer pgrm does not boot up Win 7.

Both of those have them run a PE (preexecution environment) from ram. There is not boot to be intercepted.

DISKPART is an internal command of the operating system , this is not working with bootviruses.

Nonsense - DISKPART and CLEAN/CLEAN ALL can be accessed from any Windows 7 installation ISO and run during bootup from said ISO, prior to the boot manager being loaded.

Regards,
Golden

Ditto on both responses above. The only way there can be interference is if the bootable disc itself is corrupt. But that could conceivably be the case with any bootable disc. Always consider the source.
 

My Computer My Computer

OS
Windows 7 Ultimate x64
Back
Top