This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Still seeking assistance

1 min read

✨ The volunteers who helped with this thread aren't active anymore, but you can still get a personalized answer — click Ask AI below.

This thread's last reply is from August 1, 2009, 1:53 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Vistaphobic
Per the 3-day mod's instructions, I am posting to reaffirm my desperate need of your help in disinfecting my computer. My original post is located here: viewtopic.php?f=11&t=44676&view=unread#unread

I've been browsing some hidden files and now have a somewhat better understanding of this malware's nature. It has surreptitiously turned my system into a virtual machine running some other OS in the background, presumably Linux. It has created a hidden boot sector inaccessible to the Windows OS labeled "\\?\PhysicalDrive." The hidden partition is formatted in something called Novell Netware 286. There is also a second hidden partition, "\\.\PartmgrControl" formatted in FAT16. All Windows reboots and even system restore are directed to a hidden copy of the bootable Vista disc image "\bcd\hives\bin\efi_cdboot\bcd." Thus the "virtual machine based rootkit" survives the phony factory disc image restore.

Ingenious, really. I will patiently await your help while continuing to uncover as much information as I can.

VP
Katana MRU Teacher Emeritus
Gary has replied

http://www.malwareremoval.com/forum/vie ... 35#p458735

✨ Ask AI about this thread

No ads, no affiliate links — generated on request from this thread's own archived content, not written by forum staff. Never run a scan/removal tool as a self-service step if the original thread describes it being done under a helper's direct supervision, and don't include your name, email, or other personal details in a follow-up question. See our privacy page for details on how this works.