[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

hey /g/uys I have a question: Is it possible for malicious

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 33
Thread images: 2

File: pontiac_ghost_car.jpg (178KB, 1280x844px) Image search: [Google]
pontiac_ghost_car.jpg
178KB, 1280x844px
hey /g/uys I have a question:

Is it possible for malicious data to survive a drive being formatted?
>>
>>57418490
yes
>>
>>57418490
If you only format it without making a new partition table, maybe. A drive might also have some hidden sectors you can't usually access.
>>
Is it possible?
No, how can something run in a specific userspace, if the userspace is not installed yet?
>>
>>57418490
You need to zero the drive. Formatting the drive will only overwrite a few megabytes of the partition table and superblocks.
>>
>>57418638
Whoops, ignore this. I didn't read your post correctly.
>>
>>57418591
hmm

I'm asking because something is fucking my (Win7) computer up, it can only boot in safe mode now and something is stopping my usual antivirus' system service every time I start it. Malwarebytes has found nothing.

I don't even go to skeevy questionable sites, no idea what the fuck happened.
>>
>>57418490
if it lives in the bios.
>>
>>57418658
>Windows & security
>>
if your hard drive firmware gets infected you are cucked
>>
>>57418689
So would that sort of thing be rare? I'm curious as to how these things propigate since I seem to have contracted something from fucking nowhere I can think of.

Is it possible for something to highjack the disk check function? After it shut down unexpectedly, I rebooted and got a normal looking disk check prompt which apparently recovered some files or something. Since then it's been fucked.

Yeah I know, /g/ is not tech support. I just wanna know what this might be so I can figure out how to deal with it.

>>57418700
Well, what do you suggest?

>>57418716
that doesn't seem to be the case, so I might as well try a format

Everything works or seems to work, except booting normally gives me a blue screen after a minute everytime.

Gotta install all those fucking updates again...
>>
>>57418845
>computer gives me an error

See, this is a problem with most of you windows users. What error? Why do ypu ALWAYS say "this doesn't work", "there's a window and it says something", "computer shows a blue screen and turns off", "a message tells me to reboot, what do I do"
>>
>>57418845
I have to side with
>>57418893

Specify your error. Expecting it to work and someone to have a solution to a vague description is impractical.

Spend a hour or two looking up some info and you'll be better at diagnosing the issue.
>>
>>57418845
>what do you suggest?

Install gentoo
>>
>>57418893
>>57418924
Fair enough, considering that I had to do some tinkering to get it to start downloading updates after installation in the first place (microsoft: "it just works automatically"), and that the USB controller driver that came with the motherboard was the source of massive DPC latency, I shouldn't be surprised.

Should have been more attentive. I was hoping what I knew so far would be able to help me find a classification of what it might be but yeah, still too vague.

Still better than my mother's laptop. Windows 10 had an update that rewrote her pin-based password to a seven digit number. She was blocked from logging in until she went to the microsoft store and paid $75 to un-fuck the computer. Fucking company should have paid her for their dumbass mistake.

>>57419010
oooh look at me and the five whole programs I can run
>>
>>57419080
To be honest you could have just booted her laptop from a Liveusb Linux system and reset the password using the chntpw program.
>>
>>57418490
depends on how malicious we're talking about, there's proof of concept malware that hides itself in the hard drive firmware
>>
>>57419122
really? huh

Is linux hard to get into? As you've seen I know next to nothing. I've fiddled with Ubuntu a bit before, seemed ok but I don't like having limited compatability. If anything I doubt I'd be using it as a main OS.
>>
>>57419133
I honestly don't know yet, but this problem my PC is having makes me curious about what's out there.
>>
>>57419080
Despite >>57418893 we still have no idea what that "blue screen" error message was.
>>
>>57419181
See >>>/g/fglt
>>
File: 20161106_191025-2.jpg (2MB, 2495x1326px) Image search: [Google]
20161106_191025-2.jpg
2MB, 2495x1326px
>>57419215
yeah, something impersonated disk check and fucked me over. I have the .dmp and other data on the crashes on it in safe mode, dumbass that I am, I haven't looked at them.

>>57419269
ok
>>
>>57419482
>REGISTRY_ERROR

Check if the registry isn't simply corrupted
>>
>>57418490
boot. sector. virus.
>things deleted are really still there.
>boot sector memory addresses remain the same after formatting and reinstalling.
>>
>>57418490
>>57419545
>MBR
kek
>>
>>57419545
that's some scary shit
>>
>>57419545
>>57419579
Somebody actually did a proof of concept and got a virus into the BIOS memory. Impossible to get rid of without flashing new firmware in. Not sure if anybody has done anything with it yet but the concept is scary enough.
>>
>>57418490
what is malicious data?
are you worried about the virus you got from looking at the kiddie porn, or are you worried about the porn being found?
More context is needed to answer the question in the way youre wanting.

formatting the drive doesnt erase the data.
The new OS wont just refind the old data and run the virus and get infected again, but the data is still there. You could recover data at some point, forget its there, and then rerun the virus and reinfect yourself like a retard..
or law enforcment could scan your drive and see the cp you tried to delete.
>>
>>57418490
MBR
bootkit
Disk firmware
>>
>>57419545
fuck off jerry.
>>57419692
>>57419579
A bios virus is so super fucking niche that nobody does it without targeting specific individuals.
>>
>>57419524
doing this...

sfc/scannow
"Verification 100% complete.
Windows Resource Protection did not find any integrity violations."
??? that can't be right

>>57419695
well I meant viruses, spyware, backdoors and shit like that I guess, a recent fuckup has had me wondering what's possible because I was considering formatting and re-installing

thanks for the info though, and nah I'm not the kind of guy who meets Chris Hansen in a stranger's kitchen
>>
well I'll stop wasting your time with this and fuck off to figure out what it is. I have the minidump and other stuff, so I should be able to figure something out with some prior research. Thanks for the info.
>>
>>57419822
Do not back up any executable, and any operating system iso. Only reinstall from non rewritable media. Dont save pdfs either. Theres probably more file extensions to not save by now and Im not rewriging this fucking thing for the third time this month.. I really need to copypasta it.

so youre they type that meets the pd in your living room on the floor?
Thread posts: 33
Thread images: 2


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.