Dangerous virus --> unbootable PC (even from CD)

Discussion in 'Software' started by woopedazz, Sep 2, 2010.

  1. woopedazz

    woopedazz Private E-2

    >>Running Windows 7 Home Premium 64bit initially booting from SSD<<

    EDIT: I apologise in advance for being unable to complete the "before posting" guidelines, but my computer is currently a large shiny brick, so I wasn't able to run any of the programs. I've included as much info as I can surrounding it's downfall.

    -New PC and the only files installed on my SSD were the OS and drivers.
    -->Random mp3 site.
    -AVG told me the site was pure as the virgin snow and had clearly been paid off.

    The next day i turned it on to find it rebooted every time I started it up. Got her into safe mode and was greeted with "DCOM server process launcher service terminated unexpectedly" --> restart. I was able to mash in a quick "shutdown -a" on my third attempt which bought me a full 50 seconds of uptime interspersed with 5 second intervals of "windows explorer has encountered and error," etc. Then it would reboot anyway.

    This made it impossible to download, transfer or run any form of anti-virus/malware. So my next step was to open up my SSD and find a brand new folder called "obj" filled with a couple of .exe's living happily inside.
    Contents of folder I was able to jot down before computer restarted again included:

    objinstall.exe
    DISWHQL.DLL
    Several activex files.

    I googled them and they took a few hits on malware sites, but not many.

    -I took a breather --> Next day I decided to try to run malwarebytes again, this time I was unable to boot from the SSD at all.
    -Tried to run every repair I could from windows DVD.
    -When that failed I decided to download DBAN and burn the virus alive. :major

    This is when I get a little unhinged... "BOOTMGR image is corrupt. The system cannot boot." This occurs for SSD, Windows CD, DBAN and Bootzilla.

    Will wiping the SSD at a store resolve my problems? Has something more serious happened? I'm confused to how the hell I can't boot from a CD when a few days ago (before this virus) everything was fine. Temps have been steady for weeks (machine is only a couple of weeks old) and the PSU seems fine.

    Thanks for your time,

    Woop.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I have moved your thread to the software forum as you will need to be able to boot up in order for us to help you with malware. However, since it is just a few weeks old, you might want to take it where you purchased it and have them fix it.

    If you want to pursue this here, make sure you tell us exactly what happens and what all you have tried.

    I take it that you can not boot to the Win7 install disc? You cant boot to normal or safe mode? Have you tried getting into the Recovery Environment? If not, you can try creating this disc using a different computer and then see if you can boot to it:

    Vista and Win7 Recovery disc
     
  3. motc7

    motc7 Vice Admiral (Starfleet)

    Frankly, sounds like you got a virus like you surmised and really you wouldn't stand to lose much. I would format and reinstall windows.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    motc7, you didnt read the title.
     
  5. Caliban

    Caliban I don't need no steenkin' title!

    If your SSD is suspect, why not try an IDE drive, see if you can install to it? Most motherboards support multiple interfaces - if you've got anything laying around, even an old 20 gig, you might be able to cut your troubleshooting in half...
     
  6. woopedazz

    woopedazz Private E-2

    Correct, tried all of the above. No working solution. I'll reburn recovery disc after uni today and try one more time. I refuse to believe it can't read the damn recovery disc, and the one I used I hadn't tested beforehand.

    Thanks for all the responses.

    EDIT: I've got an old HDD I can test later aswell.
     
  7. hrlow2

    hrlow2 MajorGeek

    I would love to know what sites had been visited so as to steer a clear course around them.
    Don't need no drive-bys like that sounds like.
    Unless one of the MP3s was the culprit.
     
  8. woopedazz

    woopedazz Private E-2

    I didn't really pay much attention to the site at the time, and as of now I'm not in a position to check my browser history :( I'm fairly sure it was a driveby, because the .mp3 seems clean, and is working fine on mobile, etc...God help me if that was the problem.
     
  9. dlb

    dlb MajorGeek

    It almost sounds like a hardware problem. I don't think I've ever run in to a virus that didn't allow for a drive reformat and reload. Even new hardware can go bad in a short amount of time. On the plus side, if it is a hardware problem, the gear is all new (or sounds like it is anyway) and should be under a warranty.
     
  10. woopedazz

    woopedazz Private E-2

    Another forum indicated that my BOOTMGR problem is likely due to the boot code looking for BOOTMGR being corrupt, as opposed to the BOOTMGR file itself (MBR fault somewhere). This seemed pretty obvious... what I didn't know was that MBR can overide BIOS preferences.

    Unplugged HDDs, and replugged once CD began to boot and presto, booted from CD without error. Still unable to login to computer, but this new development meant I can load DBAN and successfully run it.

    So...Somehow the virus (now suspected to be an XP rootkit that went to shit when exposed to Windows 7) somehow got into MBR and altered BIOS preferences and that was the major problem in trying to run any sort of repair. Now I've got DBAN running and no errors as of yet. Things are looking up and I am ready to start again from a fresh install!

    I'll let you know how it goes.
     
  11. woopedazz

    woopedazz Private E-2

    On it's third pass of 3 in DoD Short of DBAN the SSD decided to error.

    "(failure, code 1) [verify errors: 2811] [58440KB/s]"

    Is this a hardware error? Should I try to use DBAN again with a lower security pass? I am almost certain the problems began with a virus, but now I'm wondering what the hell it's done to my computer...
     
  12. hrlow2

    hrlow2 MajorGeek

    Is your machine capable of running 64bit OSs?
    Did you do a clean install of Win7 or go overtop of XP?(looking at post 10)
    Starting to look like you have 2 operating systems installed and your machine can't decide which to boot.
     
  13. woopedazz

    woopedazz Private E-2

    Machine is very much able to run 64bit and has for the month or so I've had it. CPU=1055T, etc, etc. Clean install of Win7. No problems until I went to turn it on one day and it kept rebooting.

    I've run through diagnostics on ultimate boot CD and at this point all hardware appears fine, and it still looks like the SSD is corrupted. Windows 7 CD will now run, however I am trying one last time to wipe the Drive using UBCD before I try to reinstall.

    EDIT: Sorry I didn't word post 10 very well. What I meant to say is that a rootkit designed for attacks on XP may have gone errored when trying to attack Win7 (a suggestion from a tech guy who saw something similar before, but it never led to as many errors).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds