PDA

View Full Version : Virus survive a format And a new partion X_X


wera
01-31-2006, 10:54 PM
Hey you know how i stated in kwakis thread how evreything got comprimizeeed MIZZED :P anyways i partioned formatted and reinstalled windows... still i can not install my motherboard i get the blue screen evretimeh how can a virus survive a formatt and a re partion XD well i think it may have stored itself on my floppy drive ima go create another boot disk though thats just being parinoid.

wera
01-31-2006, 11:11 PM
Well i am going to try killdisk it writes zeros to it... i have also heard of fdisk/mbr whats that do?

wera
01-31-2006, 11:41 PM
**** i just found my virus



"""""The Nyxem virus on February 3 will begin deleting eleven select file types - including Word, PowerPoint, Excel, and Acrobat files - on infected Windows systems. Security firm Lurhq estimates over 300,000 systems have been infected by the Nyxem-E variant.

On infected machines the virus raids address books to find e-mail addresses to send itself to. The virus also tries to spread by searching for machines on the same local network as any computer it has compromised. Unlike many recent viruses Nyxem is set to overwrite 11 different types of file on infected machines on the third of every month. The list of files to be over-written includes the most widely used sorts of formats."""""

bear
02-01-2006, 06:57 AM
Nyxem virus. On February 3rd, common documents such as MS Word, Excel or Powerpoint will be overwritten on infected machines. Over 300,000 machines have been infected thus far, the main method of infection being the promise of porn in unsolicited emails."
You didn't actually click on "free porn" ads in emails, did you? :crazy:

According to F-Secure's security blog, the counter was showing around 510,000 infections as of Sunday night.Seems you're not alone. ;)

Nyxem infections may be rising because it is taking advantage of computers that have already had their antivirus software disabled by some other virus such as Bagle, Hypponen says.
Maybe why you why you were infected in the first place?
By the way, it doesn't only hit those file types, it also hits PSD, disables several AV programs, spreads to network shares and file sharing programs...

Information on the virus and removal techniques found here:
http://www.f-secure.com/v-descs/nyxem_e.shtml

wera
02-01-2006, 11:40 AM
You didn't actually click on "free porn" ads in emails, did you? :crazy:
l[/url]
No but i got some wiered emails lateley...attachments....friends.... snooping friends then you got to think about the 4 year old who just came ove rbleh...Anyways i just ran killdisk and wrote zeros to the disk reinstalled but i am still haveing ONE ofthe problems that i had earleyer when i tried to install my motherboard about half way through "windows has found a problem in the registry please restart" it sets me back to a date before i installed and when i try to open setup i get "Service not avilable please try agian after closeing all background programs" what now?

wera
02-01-2006, 12:34 PM
The edit button needs to last longer O_O If i use another hard disk drive and clean that one after i have the new hdd in ther will that work ? This happens to me a lot *sigh* All i do with my computer is play games.

bear
02-01-2006, 01:12 PM
If you overwrote the entire HDD with ones and zeros and get a warning that there's a registry problem, something's wrong. The registry is a Windows thing, and if Windows is not installed...there *is* no registry.

If you begin with a clean drive, install should complete. Once you hook the (possibly) infected drive to it, it might infect the new one. Make very sure you have good AV protection on this new HDD before you try adding the old drive to get anything off it. (although if you truly overwrote with ones and zeros, there should be nothing remaining).
Unless I've misunderstood you post?

kwokwai
02-01-2006, 01:25 PM
For virus that can't be killed even Format HDD, you may try this:

Put the XP disc and try to format the infected partition.
When the formating process is near 100%, not 100%, turn off the power immediately!

A friend of mine has tried this experiment, and he's successfully killed it!



Warning: The HDD may be damaged by performing such the 'activity'!

bear
02-01-2006, 01:29 PM
Sounds like the cure may be worse than the disease...

kwokwai
02-01-2006, 02:16 PM
Sounds like the cure may be worse than the disease...

I don't know if he (my friend) was telling the truth; but anyway, I will never try this! :hammer3:

It doesn't hold water, at least I think so! :D

wera
02-01-2006, 03:51 PM
If you overwrote the entire HDD with ones and zeros and get a warning that there's a registry problem, something's wrong. The registry is a Windows thing, and if Windows is not installed...there *is* no registry.

If you begin with a clean drive, install should complete. Once you hook the (possibly) infected drive to it, it might infect the new one. Make very sure you have good AV protection on this new HDD before you try adding the old drive to get anything off it. (although if you truly overwrote with ones and zeros, there should be nothing remaining).
Unless I've misunderstood you post?
Acording to www.killdisk.com thats what killdisk does i did get windows to install butwhile i am trying to install my motherboard it does this EACH TIME ON THIS HDD -_- X_X.

bear
02-01-2006, 03:58 PM
Install motherboard? Now I am confused. to install a mobo, you stick it in a case, attach your devices to it, start the system. What is it you're doing that requires "installation" regarding the Windows registry?

wera
02-01-2006, 07:43 PM
Install motherboard? Now I am confused. to install a mobo, you stick it in a case, attach your devices to it, start the system. What is it you're doing that requires "installation" regarding the Windows registry?
The cd to install the via bridges ethernet the mobo to install it and windows....it is a ecs with via north and south bridge i need to install it to windows as well as just installing it..........EDIT: this is what i am saying ....i built the pc in a case....then i booted up useing a boot floppy fdisked deleted partion created new partion.....formatted....installed...had the pc running for two days with the motherboard installed to windows.... then i got attacked .......used killdisk wrote zeros to the disk so i can start over but somehow now i can not install the mainboard becase halfway tru it says windows registrey needs repaired restarts and now any setup programs will not work can not install the mainboard .....is it possible that my motherboard bios is infected? EDIT: sir bear fdisk /mbr will not work ..... this has to be a virus.. if i clip the little clip on the floppy to open that makes it write protected no?

bear
02-01-2006, 08:04 PM
Yes, opening the small window should write protect the disk.

wera
02-01-2006, 08:06 PM
Yes, opening the small window should write protect the disk.
hmm so then the virus is not on the floppy how..... HOW CAN A VIRUS STOP FDISK ?MBR HOW CAN A VIRUS SURVIVE KILLDISK IT FRIKING WRITES ZEROS TO THE FRIKING DRIVE ****ING COMPUTER WHAT THE **** DO I DO NOW ......

bear
02-01-2006, 08:34 PM
Curious, is the computer hooked to the internet (or LAN) when you start having the troubles?
Was the floppy write protected already the first time it was inserted into the drive?
Was the floppy with killdisk on it write protected before being inserted?
Is there a second hard drive hooked up to this that might be carrying the infection?
Were both floppies created on systems known to be clean?

wera
02-01-2006, 08:37 PM
1. no
2. yes
3.yes
4.no

.....

bear
02-01-2006, 08:39 PM
Were both floppies created on systems known to be clean?
Added this one late...

wera
02-01-2006, 08:40 PM
5. yes.
3 scans with avg
avast pccillin and nortan...*i know nortan sucks -_-*

Anger went away...now im so sad...i just want my computer back....

I hope anyone who even trys to make a virus dies very painfuilly ....

bear
02-01-2006, 08:52 PM
somehow now i can not install the mainboard becase halfway tru it says windows registrey needs repaired restarts and now any setup programs will not work can not install the mainboard
This still has me puzzled. When you install a motherboard, it's already flashed with BIOS information. What is it you're installing for/to it?
You have successfully installed Windows on this drive, or it won't do anything about installing that either?

wera
02-01-2006, 08:53 PM
This still has me puzzled. When you install a motherboard, it's already flashed with BIOS information. What is it you're installing for/to it?
You have successfully installed Windows on this drive, or it won't do anything about installing that either?
I am useing windows 98 i need to install this motherboard TO windows so windows reconises it. Yes i have installed windows at leaset 8 times now same thing.

bear
02-01-2006, 08:57 PM
This makes no sense to me. If you can boot and install Windows (even 98), that means the mobo is fine, compatible and already "installed". You can't install windows to a drive if it isn't attached and working on a motherboard already...

Are you trying to upgrade/flash the BIOS or somethign?

wera
02-01-2006, 09:00 PM
http://www.ecs.com.tw/ECSWeb/Products/Productsdetail.aspx?detailid=343&MenuID=16&LanID=9

Here is a better explanation i need to install the intergrated stuffs . Like the usb ports ethernet intergrated sound and the via chipset.

It does this when i try to install the usb and the chipset and stuff.............

DUH....let me go underclock it to 2.00 ghz becase this all happend when i overclocked it O_O.

wera
02-02-2006, 02:28 AM
OMFG.... well i clocked it back to 1.60 ghz and i was able to install the motherboard...installed sygate avg spybot found 0 viruses...but this is interesting i had TONS of spyware... even after fdisk formatt it all still there even www.kino.com.tw had spyware infectations and i still do not trust that it is all clean what do i do if nothg is detected? Becase im sure there is something else....DAMN BOOT SECTOR VIRUSES triky buggers -_-.

What i find funny is that something as simple as adware can do this..... thats just horrid i could not install zone alarm becase of it i even have a hardware firewall. sygate isnt bad though

just found 10 more spyware.....am i glad i have spybot and adaware. EDIT: BAH why is my router program trying to acsess www.gemtek.com.tw?

Bear...just a sujjestion but i make a lot of edits: could you remove the edit limit / time limit becase i find myself posting like 80 times one thread XD annyways just got done installing updates for 98 se it is now 325 am ....do i sleep? ..... No.

kwokwai
02-02-2006, 03:38 AM
5. yes.
3 scans with avg
avast pccillin and nortan...*i know nortan sucks -_-*

Anger went away...now im so sad...i just want my computer back....

I hope anyone who even trys to make a virus dies very painfuilly ....


Yes, you are right!
It can be painful for everyone to kill an unknown virus!


My suggestion is:

Try to replace the infected HDD, and then copy your favourite data back.
AFAIK, Viruses seldomly exist in Pictures, and Videoes; but of course, you should play safe, try to scan with AV program before you copy them back!
If you have two PCs, this job would be easier to complete.
You may buy a second-hand old PC, and connect the infected HDD to this PC, locate which important data you want, and burn them with CDR or DVDR.

Hope my suggestion can help!
Good Luck, my friend! ;)

Bear...just a sujjestion but i make a lot of edits: could you remove the edit limit / time limit becase i find myself posting like 80 times one thread XD annyways just got done installing updates for 98 se it is now 325 am ....do i sleep? ..... No.


I see that you mention the term 'XD' quite often. Does it mean 'ex dividend' ?

Please correct me if I'm wrong!

bear
02-02-2006, 06:11 AM
Bear...just a sujjestion but i make a lot of edits: could you remove the edit limit / time limit becase i find myself posting like 80 times one thread XD annyways
Most of your new posts occur within the 30 minutes allowed for editing, so maybe it wouldn't help after all? If you recall, we had problems at one point where you kept returning to a post and editing while I was working on the answer. I post, and it's wrong since the OP changed...:wallbash:

I feel that 30 minutes is probably long enough to realize you've posted something that needs correction, so at least for now I'm leaving it alone. Thanks for the suggestion, though. Besides, I can clean up pretty easily afterwards with VB's in line moderation...a few clicks and the mulitple posts are merged into one.

wera
02-02-2006, 02:05 PM
I see that you mention the term 'XD' quite often. Does it mean 'ex dividend' ?

Please correct me if I'm wrong!
Dunno what does ex mean? lol well if you turn the XD around it looks like a emotcon the X are the dead eyes and the D is the toung sticking out almost like :p :). EDIT: Most of your new posts occur within the 30 minutes allowed for editing, so maybe it wouldn't help after all? If you recall, we had problems at one point where you kept returning to a post and editing while I was working on the answer. I post, and it's wrong since the OP changed...:wallbash:

I feel that 30 minutes is probably long enough to realize you've posted something that needs correction, so at least for now I'm leaving it alone. Thanks for the suggestion, though. Besides, I can clean up pretty easily afterwards with VB's in line moderation...a few clicks and the mulitple posts are merged into one.



sure i suppose i can live wit dat .





EDIT:






My suggestion is:

Try to replace the infected HDD, and then copy your favourite data back.
AFAIK, Viruses seldomly exist in Pictures, and Videoes; but of course, you should play safe, try to scan with AV program before you copy them back!
If you have two PCs, this job would be easier to complete.
You may buy a second-hand old PC, and connect the infected HDD to this PC, locate which important data you want, and burn them with CDR or DVDR.

Hope my suggestion can help!
Good Luck, my friend! ;)

Thank you for the suggestion :) but i have no backed up data to worry about had to clean install like 80 friking times.... i guess all i can do now is get on with my life and trust my firewall/antivirus though thanks all you guys pwnzorz :D.