This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Still seeking assistance

1 min read

This thread's last reply is from August 1, 2009, 1:53 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Per the 3-day mod's instructions, I am posting to reaffirm my desperate need of your help in disinfecting my computer. My original post is located here: viewtopic.php?f=11&t=44676&view=unread#unread

I've been browsing some hidden files and now have a somewhat better understanding of this malware's nature. It has surreptitiously turned my system into a virtual machine running some other OS in the background, presumably Linux. It has created a hidden boot sector inaccessible to the Windows OS labeled "\\?\PhysicalDrive." The hidden partition is formatted in something called Novell Netware 286. There is also a second hidden partition, "\\.\PartmgrControl" formatted in FAT16. All Windows reboots and even system restore are directed to a hidden copy of the bootable Vista disc image "\bcd\hives\bin\efi_cdboot\bcd." Thus the "virtual machine based rootkit" survives the phony factory disc image restore.

Ingenious, really. I will patiently await your help while continuing to uncover as much information as I can.

VP
Gary has replied

http://www.malwareremoval.com/forum/vie ... 35#p458735