Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

20 years and I have never.....


  • Please log in to reply
3 replies to this topic

#1 corrco

corrco

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:06:52 PM

Posted 04 March 2013 - 07:35 PM

I still remember being infected in DOS by the stoned virus, and getting a McAfee boot disk and scanning, removing the little critter.

 

I was hit last week by something that I have never seen the like of, and hope to never see it again. It started out in a typical fashion by hiding everything and flashing warnings about having surfed porn etc. Booted and scanned with KAV rescue disk after not being able to get control of the system with anything else like safe boot etc.

 

KAVRD 10 found and "disinfected" 5 items identified as Heur.win32.gen. Now the system reboots after the windows xp logo.

 

Cannot launch recovery console from startup menu, from recovery console live CD or from trying an XP install CD - all result in BSOD.

 

Removing the drive for exam is futile in any windows OS as it is not seen as an NTFS files system, though Gparted identifies it as such. Linux can see the file structure and let me backup the data. There are no hidden partitions that I can find.

 

Can no longer access the system setup (bios) key does nothing. I tried installing XP on a new HD, but after it completed it also reboots in a loop - there goes any hope I had of reflashing the BIOS.

 

Has anyone ever seen anything like this?



BC AdBot (Login to Remove)

 


#2 corrco

corrco
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:06:52 PM

Posted 05 March 2013 - 12:03 PM

Managed a slight gain againt whatever this thing is. The desktop model is an HP dx7500, and the BIOS can only be recovered from windows. As I couldn't install windows even on another drive, I managed to boot BartPE and was able to reflash the BIOS this way. Now I can access system setup again and am able to reinstall windows onto another drive. The original drive still is stuck rebooting, and only gives a BSOD any way I try to run recovery console.

 

No sign of anything wrong in the MBR according to Kasp. RD 10 or AswMBR, Roguekiller etc.



#3 corrco

corrco
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:06:52 PM

Posted 06 March 2013 - 05:31 PM

The saga continues.. I have a partition that all tools tried (gparted, Parted Magic etc) show as type 7, and okay. No windows OS or util seems to be able to recognize the volume as having an OS or anything else, and show free space as -1%. Linux will see the partition and files, folders etc. At this point I have recovered the important data, but am very curious how the volume is being stealthed from Windows when it's an NTFS file system. Having -1% explains why the system reboots continually or gives a BSOD when recovery console is attempted. I tried imaging to a 1TB drive and still shows only -1% free.



#4 corrco

corrco
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:06:52 PM

Posted 07 March 2013 - 05:03 PM

I tried imaging the original drive onto another drive using Ghost. Apart from a warning that the checkdisk bit was set all went fine. The newly imaged drive displays exactly the same behaviour as the original drive. Even after removing the partition, MBR, reformat ting it won't allow windows to reinstall, nor can recovery console be accessed without a BSOD. I've tried many of the utils on Hirens 15.2 release - manufacturers diags are okay - utils like MHDD report that the drive does not come ready. Feel free to chime in anytime. Three hard drives down and counting.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users