Hi guys, got this e-mail from a friend today asking for help. He lives a long way away from me so I'm not able to physically get to the machine itself.
I've e-mailed him back asking for details of how exactly he caught it and told him to install some free anti-virus software. I've known of certain viruses that would corrupt or clear the BIOS but I don't know of any that would actually reside in the BIOS so to speak. Could it be living in the MBR? Would that be wiped after a format?
Hi
I have contracted a Virus of the PC variety.
I won't go into how I got it, but to suffice to say, it was a tad flukey!
Anyway, I decided to get rid of it by wiping my HD, so I used WDclear which writes zero's to the HD and makes it like it was fresh from the factory. However, when I reinstalled XP Pro, there it still is! I ran Spy-Doctor, which found 422 infections , so I purchased it and then proceded to use it to get rid. When I ran it a second time it came up with 50, and the third time it came up with 8 which were all Worm.WGAVN. It said they would be destroyed when I rebooted, so I did but nay, the buggers where still there, and when I went on line to see if I could do some research, I was infested by windows opening telling me I had s**t on my PC and to go 'Here there and everywhere' to get it fixed. And when I ran Spy-Doctor again, it came up with 283 infections.
Is it possible for a virus to be in the BIOS? Because if the WDclear writes zero's, how can the virus remain on the HD?
Any help would be greatfully excepted (Before I pull out all my hair!!! )
Here are some of the sites that the PC is trying to connect to:
promo.dollarrevenue.com
linuxcard.com
numb-soft.com
apps.deskwizz.com
and my personal favourite..........
symantec.loves.the.****.pheer.biz.
I've e-mailed him back asking for details of how exactly he caught it and told him to install some free anti-virus software. I've known of certain viruses that would corrupt or clear the BIOS but I don't know of any that would actually reside in the BIOS so to speak. Could it be living in the MBR? Would that be wiped after a format?