Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 1st, 2009, 07:31 PM
winterlord winterlord is offline
Regular Poster
 
Join Date: Aug 2009
Posts: 148
Default any idea what type of virus this is or what i can do besides tossing the HDD's

i was wondering , i tried to install windows xp on one of my hard drives seperated not in raid even though they where. i initialy was only using the windows xp disk to do a full format of my hard driver however when trying to install it said for one of the hard drives, it said it coul;d not format for the partition was not in a reconizable fat or ntfc partition.

iv had plenty of things that leads me to believe a virus but this one takes the cake.

western digital tools, seatools... cannot format it ..... those disk work fine, but in fact when i try to boot off either seatools or wd tools while that hard drive is plugged in it wont format anything.

so what do i do? windows 7 installs just fine on either of these disks and raid0 runs fine , but the one disk cannot be formatted? the drives are 2x raptors 10krpm 36gb. does this sound like a familiar strong virus like red or blue pill? or could there be a hidden true crypt linux volume controling my pc? blocking format access through bootup?

thanks
winter
  #2  
Old December 1st, 2009, 10:50 PM
subhrobhandari subhrobhandari is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 241
Default Re: any idea what type of virus this is or what i can do besides tossing the HDD's

Did you try to delete the partition and then create a new one from that space?
__________________
Realtime: Webroot SecureAnywhere Private Beta + Zemana Antilogger + HitmanPro Alert
On-Demand: Hitman Pro
Others: Router + EMET (Custom Conf.) + Fully Updated Windows 7 SP1 64Bit + Other Security Measures
  #3  
Old December 3rd, 2009, 12:22 AM
winterlord winterlord is offline
Regular Poster
 
Join Date: Aug 2009
Posts: 148
Default Re: any idea what type of virus this is or what i can do besides tossing the HDD's

i tried formating the entire drive outside of windows cant format it. or see a partition to delete
  #4  
Old December 4th, 2009, 01:25 AM
chronomatic chronomatic is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,324
Default Re: any idea what type of virus this is or what i can do besides tossing the HDD's

Try downloading a Linux liveCD like GParted. Burn it to disk and boot from it. Once booted, it will take you directly to a formatting tool (that's what this liveCD is used for). It allows you to create NTFS and FAT partitions. It is easy to use with the little slider graphic, etc.. Should be self-explanatory.

If that doesn't work, then boot back into the liveCD again. In the main window, look and see what your disk is named (Linux does not use drive letters. Instead, it will be something like "sda"). Once you get that info, open a terminal and type the following:
Code:
shred -vfz /dev/sda

Where "sda" matches the name of your disk.

This will completely overwrite the disk with zeroes, effectively blanking it and any possible virus on it. After that, try installing Windows again.
  #5  
Old December 4th, 2009, 03:54 AM
Searching_ _ _'s Avatar
Searching_ _ _ Searching_ _ _ is offline
Very Frequent Poster
 
Join Date: Jan 2008
Location: iAnywhere
Posts: 1,988
Default Re: any idea what type of virus this is or what i can do besides tossing the HDD's

If you do try to use Linux, give this command a try:
Code:
sfdisk -LuS
Will show you the partitions and what file systems and size is on them.

If trying Linux; also try hdparm command to wipe, shred is quite slow.
hdparm can access the secure erase function if supported by hardware.

Code:
hdparm -I /dev/(your drive)
Will give drive information available at boot time. Capital I gives more detail.

-g
Displays the drive geometry (cylinders, heads, sectors), the size (in sectors) of the device, and the starting offset (in sectors) of the device from the beginning of the drive.

hdparm also has some crazy reset functions for confused drives.
Research your problem thoroughly before you use such a command!

More info on wiping fast using Linux:
http://ata.wiki.kernel.org/index.php/ATA_Secure_Erase
__________________
Americans are the enemy? Mil. can arrest you?
What the heck is going on?
  #6  
Old December 7th, 2009, 05:14 AM
DasFox DasFox is offline
Very Frequent Poster
 
Join Date: May 2006
Posts: 1,825
Default Re: any idea what type of virus this is or what i can do besides tossing the HDD's

I've seen things like this before, where you have a Dynamic Disk with no boot volume.

Try to load as a secondary drive, storage and see what it is listed as basic or dynamic...

You most likely have a partition table you need to remove and make it bootable...
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:27 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums