Question:
Is it possible for a virus to stay on your pc even after reinstalling your os and reformatting your HDD?
skitzo107
2007-05-02 19:59:00 UTC
I recently had a virus on my pc, so I decided to reinstall my os however my HDD is partition into 2 drives (C & D) I only formatted the C drive and also reinstalled on the C drive. I was wondering was it possible for the virus to stay on the D drive or somewhere hidden? If so then whats the best way to completely elimate the virus from your PC.
Five answers:
2007-05-02 20:31:48 UTC
Yes, but it is not common. Often people infect their computer when they reinstall their files; reinstall rogue programs containing malware; and by accessing other drives and memory storage devices that have not been cleaned of the virus.



I recommend you eliminate the malware and scan all backup disks, drives, memory storage devices before you reinstall windows to avoid the possibility of reinstalling the virus.



To eliminate all malware off the drive wipe the drive first.



Use one of the following methods. These will overwrite all data on the hard drive.



http://forums.cnet.com/5208-6142_102-0.html?forumID=5&threadID=194873&messageID=2115918

"You can find out the manufacturer of your HD and then attempt to download the formatting tool created by that manufacturer for their HD's. Most HD Manufacturers have a Zero Fill Low level formatting tool available to erase their HD products. This will clean any existing OS files from your system as well as any viruses other files etc.."



Darik's Boot and Nuke (DBAN) free

http://www.download.com/Darik-s-Boot-and-Nuke/3000-2092_4-10165154.html

http://dban.sourceforge.net/

DBAN will automatically and completely delete the contents of any hard disk that it can detect, which makes it an appropriate utility for bulk or emergency data destruction.



Active@ Kill Disk - Hard Drive Eraser (Free version/ $29.95 enhanced version)

http://www.killdisk.com/

Free version limited to 1 erasure pass and first hard drive.

Active@ KillDisk - Hard Drive Eraser is powerful and compact DOS software that allows you to destroy all data on hard and floppy drives completely, excluding any possibility of future recovery of deleted files and folders. It's a hard drive and partition eraser utility.



WipeDrive by White Canyon $39.95 (no free version)

http://www.whitecanyon.com/

Completely wipe and erase all the information from a computer before selling or discarding it. WipeDrive makes it easy.

--------------------------------------------------------------------

When you format enter "fdisk /mbr" to format the master boot record.

http://forums.cnet.com/5208-6132_102-0.html?forumID=32&threadID=49909&messageID=593967



Then Reformat and install. (Cleans drive loses all data)

http://support.microsoft.com/kb/313348

http://www.microsoft.com/windowsxp/using/setup/winxp/install.mspx

http://www.whitecanyon.com/reformat-the-hard-drive-in-windows-xp.php

http://www.smartcomputing.com/editorial/article.asp?article=articles/archive/l0910/32l10/32l10.asp





---------------------------------------------------------

To get rid of your virus follow the following procedure.

All programs listed are free. If after following this procedure you are still infected you will need to post a hijackthis log (see references at bottom).



---------------------------------------------------------

Update your antivirus and run a full scan



If you do not have virus protection install:

AVG Antivirus 7.5 Free Edition

http://free.grisoft.com/freeweb.php/doc/avg-anti-virus-free/lng/us/tpl/v5

http://www.download.com/AVG-Anti-Virus-Free-Edition/3000-2239_4-10669237.html?tag=lst-0-1

or

Free antivirus - avast! 4 Home Edition

http://www.avast.com/eng/avast_4_home.html

or

AOL Active Virus Shield

http://www.activevirusshield.com/antivirus/freeav/index.adp

---------------------------------------------------------

Install Windows Defender (full time spyware protection)

Perform a full scan.

http://www.microsoft.com/athome/security/spyware/software/default.mspx

---------------------------------------------------------

Install the following five programs and run weekly or at least monthly. You need all five. They are not a substitute for full time spyware and virus protection.



Ad-Aware SE Personal (update + full scan)

http://www.lavasoftusa.com/products/ad-aware_se_personal.php



Spybot Search & Destroy (update + immunize + scan)

Do not enable Tea Timer and SDHelper

After installation: update + scan + immunize

http://www.safer-networking.org/en/mirrors/index.html



SpywareBlaster: Update then open and click “enable all protection”.

http://www.javacoolsoftware.com/spywareblaster.html



SUPERAntiSpyware free version: (update + scan)

http://www.superantispyware.com/



CCleaner: Do not install toolbar and recycle bin options

Removes tracking cookies, unneeded files, history

In options.

Set to run when computer starts.

Place cookies you want to keep in save list

http://www.ccleaner.com/



Note if a scan detects a problem but is unable to remove, start the computer in safe mode with the internet line disconnected and run a full scan.



In severe cases your system restore files will also be infected. In these cases you will need to turn off system restore to prevent malware hiding in the system restore files and reinfecting the computer during removal or during a future system restore. Turning off system restore deletes the system restore files.



Right click on "my computer"> Properties > System Restore Tab > Check box turn of system restore



After the malware is removed turn on system restore.

-------------------------------------------------------------

Run this time



Shoot The Messenger

http://www.grc.com/stm/shootthemessenger.htm



Install VX2 tool for Ad-Aware and run tool

http://www.lavasoftusa.com/support/securitycenter/vx2_cleaner.php



CWShredder: run

http://www.trendmicro.com/cwshredder/



SmitFraudFix

http://www.geekstogo.com/forum/How_to_use_SmitFraudFix-t109268.html

----------------------------------------------------------------------

Run this time and as needed.



Microsoft OneCare Live, run “full service scan”

Updates windows, virus and spyware scan, disk cleanup, disk fragmentation (if needed), backs up registry and then cleans registry, and checks for open firewall ports

http://onecare.live.com/site/en-us/default.htm



Malicious Software Removal Tool (run “full scan”)

http://www.microsoft.com/security/malwareremove/default.mspx

-------------------------------------------------------

Rootkit Removal Guide

http://safecomputing.umn.edu/guides/scan_unhackme.html



Rootkits Removers (Pick any 2 install and run monthly)



AVG Anti-Rootkit

http://www.grisoft.com/doc/products-avg-anti-rootkit-update-app-art/?ver=1.1.0.29



F-Secure BlackLight

http://www.f-secure.com/blacklight/



Sophos Anti-Rootkit

http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html

----------------------------------------------------------

Online Free Scanners:

Run Trend Micro, Kaspersky, and Panda Scan now.

Run a different one each month.



Trend Micro: HouseCall Free Scan (removes what it finds)

http://housecall.trendmicro.com/

BitDefender Online Scanner http://www.bitdefender.com/scan8/ie.html

Kaspersky Labs Online Scanner http://www.kaspersky.com/virusscanner

McAfee http://us.mcafee.com/root/mfs/default.asp?affid=294

Panda ActiveScan Free Online Scanner http://www.pandasoftware.com/products/activescan?

Symantic Online Scanner http://security.symantec.com/sscv6/ssc_eula.asp?langid=ie&venid=sym&plfid=23&pkj=ALUFRHYTINMHDKDCWLL&vc_scanstate=2

-------------------------------------------------------

Additional Information read:

http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Overview

http://wiki.castlecops.com/Malware_Prevention:_Prevent_Re-infection

http://www.castlecops.com/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html

http://aumha.org/a/quickfix.htm

http://aumha.org/secure.htm

http://aumha.org/a/parasite.php

http://www.castlecops.com/t102301-Hijackthis_Guidelines_Read_Before_Posting.html

http://www.techsupportforum.com/security-center/hijackthis-log-help/15968-please-read-before-posting-

http://forum.aumha.org/viewtopic.php?t=4075&sid=901703d08c2ace31389ffef2d84b6607
Albert D
2007-05-02 20:17:55 UTC
Yes it is very possible. You have to understand that virus are multiplyers and there are designed to ensure survivability in all manners. They are geared to infect all removeable drives (Drive A, C, Flash Drives, Memory Cards and hard disk partitions). In your case it has infected not only your Drive C before but also its partion (D).



If you have reformatted your hard drive and reinstalled the OS, the next step would be to immediately you antivirus and update it, then install your antispyware and update it too.



Then do a full system scan of your Drive C: and Drive D:, with your antivirus first, then with your antispyware. This should detect and remove any traces of a virus or spywares which could have copied itself in your Drive D:



Viruses are more virulent if it is residing in your C: drive, so doing the above mentioned steps could preserve your date on D:



Hope this helps!
JP
2007-05-02 20:15:51 UTC
Which partition do you use regularly? If you only use the C then maybe the virus was already eliminated. But there is still a slim chance that there is still a virus.



Try installing an anti-virus (AVG recommended) in your partition C and scan your whole hard drive. This could be a cost less solution to your problem. You could download AVG for free. Try www.ewido.net.
RElliot
2007-05-03 08:20:01 UTC
Many viruses would be able to stay on your pc after reformatting your HD.



First of all, find out what kind of virus you have. Your problem may be bigger than you think.



I recommend the latest Panda tools (Panda Total Scan and Panda Nano Scan). They have more virus definitions than anybody else and you can try them for free at http://www.infectedornot.com



The site is safe and it is owned by Panda. It is part of a new awareness campaign they have recently launched.
verdastel
2007-05-02 20:10:01 UTC
It's very highly possible that the virus still stay in D. Try to find any file with .exe or .scr extension. Most virus use that extension.

You should install antivirus and update it regularly.

Try AVG, it provides free version and it's quite reliable.


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...