Jump to content

Virus issue

qomiter

I'm new here and I expect nothing. So my PC has a nasty virus. I did a factory reset and it is still there so it is in my recovery partition which is really bad. The I made a (with the infected PC) Linux USB bootable drive and boot into Ubuntu and it was there too. I have no clue how to get rid of this virus and I was wondering if you all have any ideas on how to start troubleshooting this problem. Could it be a boot sector virus or a bios virus? 
     I also can not update windows or run a virus scanner. I'm guessing I got a root kit. When I try to scan the computer it disables my network capabilities. 

I am running windows 10

CHKSDK - Windows has scanned the file system and found no problems.
No further action is required.

Ran F-Secure - Scan came back clean
Windows Defender - Scan Came back clean 
Kaspersky TDSSKiller - Scan came back clean

Downloaded Microsoft Windows Malicious Software Removal Tool. - Scanning - Found Nothing

 

I know it is there though I can see its trail. 


"The best and most reliable method is to re-partition, reformat and reload Windows. It's painful, but it's really the best way to go if you really need some closure." - Some website

 

I would rather not. 

 

OS Name    Microsoft Windows 10 Home
Version    10.0.15063 Build 15063
Other OS Description     Not Available
OS Manufacturer    Microsoft Corporation
System Name    LAPTOP-597S028U
System Manufacturer    Razer
System Model    Blade Stealth
System Type    x64-based PC
System SKU    RZ09-01962E52
Processor    Intel(R) Core(TM) i7-7500U CPU @ 2.70GHz, 2901 Mhz, 2 Core(s), 4 Logical Processor(s)
BIOS Version/Date    Razer 6.00, 1/12/2017
SMBIOS Version    3.0
Embedded Controller Version    2.00
BIOS Mode    UEFI
BaseBoard Manufacturer    Razer
BaseBoard Model    Not Available
BaseBoard Name    Base Board
Platform Role    Mobile
Secure Boot State    On
PCR7 Configuration    Elevation Required to View
Windows Directory    C:\WINDOWS
System Directory    C:\WINDOWS\system32
Boot Device    \Device\HarddiskVolume2
Locale    United States
Hardware Abstraction Layer    Version = "10.0.15063.502"
User Name    LAPTOP-597S028U\L4PT0P
Time Zone    Eastern Standard Time
Installed Physical Memory (RAM)    16.0 GB
Total Physical Memory    15.9 GB
Available Physical Memory    11.6 GB
Total Virtual Memory    18.3 GB
Available Virtual Memory    14.0 GB
Page File Space    2.38 GB

Link to comment
Share on other sites

Link to post
Share on other sites

Your best option is to to indeed reinstall Windows. It looks like the virus has corrupted the Windows folder including registry entries and your best option is to wipe it clean. 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

I have a recovery partition that has windows on it and I did a factory reset and that did not work the virus might be in the master boot record or something.  Meaning I don't have an safe windows install disk. I would have to buy a disk and usb cd-rom and reformat. Then get the drivers off of  razorzone.com. Which is pretty much the fix but I am poor right now and have non of the tools need to do this. 

Link to comment
Share on other sites

Link to post
Share on other sites

30 minutes ago, qomiter said:

I have a recovery partition that has windows on it and I did a factory reset and that did not work the virus might be in the master boot record or something.  Meaning I don't have an safe windows install disk. I would have to buy a disk and usb cd-rom and reformat. Then get the drivers off of  razorzone.com. Which is pretty much the fix but I am poor right now and have non of the tools need to do this. 

Then you have to take the L and just wipe it and start over. 

 

if you  have ave your windows key you can download windows ISO from Microsoft and use your key to activate it 

 

Put the ISO on the USB drive and use Microsoft’s bootable usb tool to make your USB bootable so you can install the ISO

Link to comment
Share on other sites

Link to post
Share on other sites

47 minutes ago, qomiter said:

I have no key

If you got this computer new, you most likely had to do an initial first boot. Which would have you register your system with Microsoft. 

 

So if you make a bootable Windows 10 usb, which you can get from Microsoft's website, you can run it to reformat and reinstall windows 10. When prompted to enter your Microsoft ID, its usually your email, it will activate your existing windows key. 

 

You can also skip that as windows does have an automated system which can do an auto activation with the motherboard on your system. 

Current Build

AMD Ryzen 2600

Stock cooler

Asus ROG B450f gaming Mobo

1tb SKHynix m.2

WD 1TB HDD

Asus ROG Strix RX 5700xt

Thermaltake Toughpower 650w DPS RGB 80+Gold

16 Gigs ddr4 3000 gskill ram

Phantek fans

Phanteks P400TG

 

Laptop

Eluktronics Prometheus XVII

Ryzen 7 5800h

32 gigs ddr4 Corsair ram

Nvidia rtx 3080 max-p

17.3 qhd 165 hrz screen

1tb Samsung m.2

1tb WD black m.2

Link to comment
Share on other sites

Link to post
Share on other sites

Thread moved to the Troubleshooting section.

If you need help with your forum account, please use the Forum Support form !

Link to comment
Share on other sites

Link to post
Share on other sites

11 hours ago, Zusafek said:

If you got this computer new, you most likely had to do an initial first boot. Which would have you register your system with Microsoft. 

 

So if you make a bootable Windows 10 usb, which you can get from Microsoft's website, you can run it to reformat and reinstall windows 10. When prompted to enter your Microsoft ID, its usually your email, it will activate your existing windows key. 

 

You can also skip that as windows does have an automated system which can do an auto activation with the motherboard on your system. 

^ this.

 

You are right to suspect that this virus has got into something beyond the OS/System files. I have to agree the only way you're going to get rid of this is to do a complete format and reinstall (and by complete reformat I mean create a bootable windows USB, boot from it, press shift + F10 to open cmd, then use diskpart to delete the partition and format it, then download DBAN, place that on a usb stick, boot from it and do a hardcore multipass format on the offending disk) and only then look to reinstall windows.

 

Instructions for using diskpart below

Spoiler

open CMD

type diskpart [return]

[wait for it to open]

list disk [return]

select disk # (probably zero) [return]

clean [return] <- this removes the partitions

create partition primary [return]

format fs=ntfs [return]

exit

 

Link to comment
Share on other sites

Link to post
Share on other sites

14 hours ago, qomiter said:

I'm new here and I expect nothing. So my PC has a nasty virus. I did a factory reset and it is still there so it is in my recovery partition which is really bad. The I made a (with the infected PC) Linux USB bootable drive and boot into Ubuntu and it was there too. I have no clue how to get rid of this virus and I was wondering if you all have any ideas on how to start troubleshooting this problem. Could it be a boot sector virus or a bios virus? 
     I also can not update windows or run a virus scanner. I'm guessing I got a root kit. When I try to scan the computer it disables my network capabilities. 

I am running windows 10

CHKSDK - Windows has scanned the file system and found no problems.
No further action is required.

Ran F-Secure - Scan came back clean
Windows Defender - Scan Came back clean 
Kaspersky TDSSKiller - Scan came back clean

Downloaded Microsoft Windows Malicious Software Removal Tool. - Scanning - Found Nothing

 

I know it is there though I can see its trail. 


"The best and most reliable method is to re-partition, reformat and reload Windows. It's painful, but it's really the best way to go if you really need some closure." - Some website

 

I would rather not. 

 

OS Name    Microsoft Windows 10 Home
Version    10.0.15063 Build 15063
Other OS Description     Not Available
OS Manufacturer    Microsoft Corporation
System Name    LAPTOP-597S028U
System Manufacturer    Razer
System Model    Blade Stealth
System Type    x64-based PC
System SKU    RZ09-01962E52
Processor    Intel(R) Core(TM) i7-7500U CPU @ 2.70GHz, 2901 Mhz, 2 Core(s), 4 Logical Processor(s)
BIOS Version/Date    Razer 6.00, 1/12/2017
SMBIOS Version    3.0
Embedded Controller Version    2.00
BIOS Mode    UEFI
BaseBoard Manufacturer    Razer
BaseBoard Model    Not Available
BaseBoard Name    Base Board
Platform Role    Mobile
Secure Boot State    On
PCR7 Configuration    Elevation Required to View
Windows Directory    C:\WINDOWS
System Directory    C:\WINDOWS\system32
Boot Device    \Device\HarddiskVolume2
Locale    United States
Hardware Abstraction Layer    Version = "10.0.15063.502"
User Name    LAPTOP-597S028U\L4PT0P
Time Zone    Eastern Standard Time
Installed Physical Memory (RAM)    16.0 GB
Total Physical Memory    15.9 GB
Available Physical Memory    11.6 GB
Total Virtual Memory    18.3 GB
Available Virtual Memory    14.0 GB
Page File Space    2.38 GB

Yea, reinstall windows but when you get to the screen where you can format the drives, delete all of the partitions for it including the recovery one and then create a new one with the unallocated space. That should fix it.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×