Click to See Complete Forum and Search --> : Possible Virus Warning! Hard Drive Killer, ,maybe?
Richard_Cranium72
08-22-2000, 03:53 PM
Some of you have followed my woes of late regarding my HD failures.
the known facts;
1.Two dead HD's possibly 3.
2.They all had the same symptoms after being connected to a machine with a questionable e-mail and subsequent fail to boot to Win98 o/s.
3.The HD's failed to fdisk.
4.Format OK, sys c OK, CHKDISK OK,
5.Refusal to accept dos command "setup"
6.Register in second machine as OK, post ok as 2nd slave
7.Format in Win OK, Scandisk in Win OK.
8.BC Wipe fails at midway point.
9.Format in Win OK.
10.Failure to copy system files
11.Failure to start Wipe
12.Shows in Win OK, percentage free space 0.0%
13.Failure to format.
14.Fail to scandisk.
15.Fail to be seen in Win98 "My Computer" message "cannot identify drive type"
16.Clicking on ICON gives BSOD!!
So these two steadily went downhill from refusal to setup all the way to BSOD just by click on icon..
Disc history,
Q.B'foot 8.4 is 1998 July, thousands of hours. Original failure from removal of audio codecs.
Maxtor 1.6, scrap heap special. Unknown hours or yr of mfg. Ran win95 for a year or so giving windows protection errors every now and then. Connected to failed machine in attempt to boot, transferred problem to HP from NEC.
I've mistakenly id'd the other one, it is a Maxtor 27.2 @ 7200. sniff. It has a 4 month time of usage. Original fail a couple of days ago due to E-mail as best as I can tell.
Obviously the BIOS is unaffected in one of the two machines cause I've got it running with a secondary HD.
Am I missing something obvious here.. thoughts appreciated.
DrVette
Richard_Cranium72
08-22-2000, 03:58 PM
I forgot to let ya see the e-mail that I THINK started all this.
" INVALID_ADDR... =?UNKNOWN?Q?=D5=D0=C6=B8=D0=C5 "
message->>" 你是不是为找工作花费了大量的时间和金钱,而且未能如 愿;没关系,现在有“招聘信息网 "
Thread here->> http://sysopt.earthweb.com/forum/Forum17/HTML/000796.html
OuTpaTienT
08-22-2000, 04:58 PM
Is there a drive overlay issue with these drives. That's what it sounds like.
lec169
08-22-2000, 06:51 PM
Try :
fdisk /mbr a couple of times.
then fdisk create a partition, format it,
delete it, do a fdisk /mbr again.
You might have a overlay issue.
Also you need to get a copy of partition magic or some other partitioning software.
I think those drive are good.
Lec
Dave_H
08-22-2000, 07:27 PM
Another possible reason would be that the drives became inactive. If you remove a primary drive from one system and add it to a second system, Windows will make the second drive non-active because it only allows one active partition at a time.
To make the partition active again, you need to run fdisk on it and select option 2
"Select active partition". If done properly, with no changes to the partitions, you will not loose any data on the drive.
On your thread "I just killed my computer"
I noticed that your system was stopping at a C prompt. If that is the one you were trying to fdisk, format, sys, or give DOS commands, I don't think any would work at a C prompt.
You would have to change to either an A prompt and run them off a boot disk, or change directories to C:\Windows\command
Some of your symptoms are indeed bizzare, If you still have a copy of the E-mail perhaps you should save a copy to a floppy as a back up and submit one to Symantec.
Best of luck Doc. http://sysopt.earthweb.com/forum/smile.gif
Dave
Jeff7
08-22-2000, 08:34 PM
Give these utilities a try:
WIPE (http://www.myfreeoffice.com/jeffelec/auction/wipe.exe)
ZAP (http://www.myfreeoffice.com/jeffelec/auction/zap.exe)
ZAP just deletes any partition data from the drive. WIPE deletes ANY data from the hard drive.
Just run the 2 files - they will extract 2 files each - a .COM file, and a TXT file. Put those files onto a bootable floppy drive. They use the drive's numbers - primary master is 0, primary slave 1, sec master 2, sec slave 3...
You should then be able to Fdisk and format, hopefully.
[This message has been edited by Jeff7 (edited 08-24-2000).]
Richard_Cranium72
08-23-2000, 02:23 PM
Refer to this thread->>
http://sysopt.earthweb.com/forum/Forum2/HTML/009141.html
The units I was working on were a HP, NEC and a bb amd 433 unit.
The issues seemed different then lead to the same problem, it seems.
Hopefully I can work through this without too much expense or time involved from the good folks at sysopt.
Most Sincerely, DrVette
[This message has been edited by Richard_Cranium72 (edited 09-10-2000).]
Richard_Cranium72
09-10-2000, 08:30 AM
I don't know whether to start a NEW thread or not.
My machine DID get a virus !!
Finally I opened up the HD of the dead machine by putting the HD of an identical NEC into it.
The contents of my "C" drive were ALL messed up. Even the HD was re-named something in Chinese, or Whatever.
There were EXTRA folders there with strange names, Stupidly , I tried to open one, BSOD !!!
I used Printkey to grab pics of the folders and the header on the c drive. I don't have a account at geocities to post them here.
Monday, I'll contact Disney Studios and let them see the pics of the HD contents. They alleged that when I forwarded the suspect E-mail that they could NOT duplicate my results.
So, the HD has had a BC WIPE and a fdisk, format, soooo,, maybe it's clean, hope it didn't migrate into the BIOS... http://sysopt.earthweb.com/forum/frown.gif
socalgal
09-10-2000, 08:47 AM
Re your question on starting a new thread: it's best not to. Keep any and all info regarding this problem in the same thread.
More than one thread on the same problem will only make it more difficult to follow and troubleshoot - it's difficult to follow what's happening when one has to jump from thread/link to thread/link.
I hope you get this problem resolved soon, Doc.
[This message has been edited by socalgal (edited 09-10-2000).]
Richard_Cranium72
09-10-2000, 09:48 AM
I thought as much, sometimes when I panic, the urge gets the best of me.
In an effort it resolve/warn , whatever, we/I get a bit hasty in remarks or multiple posting. This I try to do little of, TRY.
This virus thing has me a bit worried, I AM SURE it came from the e-mail. The good folks at go.com / Disney Studios were unable to track it. Possibly a "run-once" per 'situation' virus. I know NOTHING about viruses so ......
Thanks folks for your continued patience.
DrVette
I've dealt with virus's like this many times.
Unfortunately, most imunize themselves to your virus scanner teh first time around, so if you get a warining your safe removing it, but if it slips in from a floppy boot, too late.
Warning: The drive data is usually unrecoverable if it infects a NTFS drive, as it wipes the first 128 bits of boot sector, which totally kills NT.
The only way I could get rid of them after that point was to remove power from the infected drives, then boot the machine to a clean dos floppy. With the zap program on the floppy, I reconnect the power connector to the drive ( while the machine is running ) and then zap the drive.
Wouldn't that kill the drive if you connect the power while the PC is running???
I did that a few years back with a Fujitsu drive by accident, and that HDD just died and had to get it serviced by the manufacturer.
Richard_Cranium72
09-10-2000, 11:32 AM
NDC, the quick swap removable HD carraiges are reported to be 'Hot Swappable'
"Product Features:
Removable ATA/66 Drive Tray
Fits any standard 3.5'' ATA/66 Drive
Entire enclosure fits into 5.25'' Drive Bay
Includes Keylock and LED Lights
Has Cooling Fan / Hot Swappable"
http://www.compgeeks.com/cgi-bin/details.asp?cat=Drives&sku=205-7036
I've seen this very simular problem once before, not sure if this will help, but ya never know. Anyways someone brought there computer in to me because for some reason the harddrive had funny named directories and such as you described it was an older pentium version with a 133 in it, what I found was that the bios setting for the harddrive had somehow been changed to what it actually was CHS.
Good luck
Deke
[This message has been edited by Deke (edited 09-10-2000).]
NDC...
There is a dilemma here. I have done this when necesary, and have never damaged a single drive ( I've personally done it about 5 times in about a years time ).
The reason is that the virus goes resident on initial PC power up, in a bios cached memory area... even before the drive is detected on startup.
The only way to get rid of it is zapping the MBR/Boot area of the drive while a virus is NOT resident in any memory space. The only way to do that, is by a "Hot swap" style or method where the drive powers up after the PC is booted. Plugging the energized drive power connector in is safer than plugging in a live IDE ribbon. ( this way you are limiting damage to a drive or power supply, IF... and that is, IF, something goes wrong )
Gutter Ball
09-10-2000, 05:20 PM
Argh, that's what happened to me :/ Exact same thing and I don't know how I got it. I did get a few of those strang emails too, but I NEVER opened it! All of a sudden, I had all these weird directories and stuff...then my HD went click of death and died. Got a new IBM 16gig, reghosted my old image(very bad idea) and then the IBM one died too :/ And no warranty cause the drive was sitting on the shelf for more than a year I guess...****!!! Wonder what kind of virus does this??
TechJumper
09-10-2000, 05:49 PM
Is it possible to corrupt an entire hard drive with one email, geez
TJ
Richard_Cranium72
09-10-2000, 06:26 PM
Gutter Ball, did your HD's do like Mine?
They power up, you hear the whine, then CLICK,,,, CLICK,,,, CLICK
I've not only killed maybe three of mine,
My used one from compgeeks, a Quantum 2.5 is doing it too http://sysopt.earthweb.com/forum/frown.gif
Gutter Ball
09-10-2000, 09:49 PM
Richard: Man, EXACTLY!!! It sounded like it was spinning up(the whine sound) and then it sounded like something would slam down on it(loud click) stopping it temporarily, then it would spin up and then click again..it would keep doing it not matter what!!! If the comp was idle, the clicks weren't as often, but if I was using it..holy click/slam!!! I thought _I_ messed them up somehow, like I shocked it or something!!! I started to lose partitions too :/ It was totally disappear, but there would be disk space. Norton fixed it, reghost...disapper again later!! ARGH!!!
-
WAIT!!! I killed a THIRD hard drive!! I totally forgot! After my IBM died, I put in my old 1.2G Quantum(this sucker was rock solid) and an old 1.2 WD. My old drive had 5 partitions, so I just ghosted the C and D images. Loaded C: on the WD and D: on the Quantum. Used for about 2 weeks until I got my current Fujitsu. Had to format the old drives, so put them back in to format...WD works fine and is now my removable HD...Quantum drive made a very quiet "click"..so I thought nothing of it, booted from floppy...went to "format c:" got a disk error?!?! Tried "format d:" invalid drive specification or something like that. So I put my Fujitsu back in and set the Quantum to primary slave...Windows couldn't identify drive and Norton Disk Doctor couldn't read it...then it happened...CLICK!!!! Dead drive :/
=
This is soooooo weird :/ Anyway, I junked all my CD-RW's with the ghosted images and before I did a clean install, I flashed the BIOS. Haven't heard a thing since and have new ghost images. I still wanna know what kind of Virus it was and HOW I got it :/
Ok, thanks for the reply. I guess I just had bad luck when I plugging the power while the the system was power on with my Fujitsu hard Drive. LOL http://sysopt.earthweb.com/forum/smile.gif And yes, Richard I know what "hotswap" hard drive racks are, Thank you. I use them on my system at work and home. But BBA was not talking about a HOT-SWAP Rack, he was talking about just plugging it it while the system was running without hot-swap rack. http://sysopt.earthweb.com/forum/smile.gif
I wish you luck on getting your system back to working condition. I know what a heart-pain it is to get all your hard drive data wiped out! http://sysopt.earthweb.com/forum/frown.gif
[This message has been edited by NDC (edited 09-10-2000).]
SysOpt.com
Copyright Internet.com Inc. All Rights Reserved.