impossible to remove virus

Hi everybody I have a big problem on my hands, my sons computer caught a virus and i can’t get rid of it, I have wipe the hard drive clean installed w7 from scratch, put avast in it did boot scan three times and came out clean. what the computer does is it disables windows update, computer restore and when I try to do a virus scan it loads the hard drive to 100% and stalls everything. Long story short I decided to wipe the drive clean again and install linux mint, I thought that would solve my problem right? wrong it does the same thing, by the way when I wipe the computer the first time and installed windows 7 it worked very good when i wasn’t scanning it. anybody has any idea how to fix it?

welcome to the forum.

i suggest you try malwarebytes antimalware as a first step.

http://filehippo.com/download_malwarebytes_anti_malware/

download install update and do a scan, don’t forget to remove what it finds. a system reboot might be needed.

second do a scan with OTL and post the result here

http://oldtimer.geekstogo.com/OTL.exe

Download OTL to your desktop.
Double click on the icon to run it. Make sure all other windows are closed to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Under the Standard Registry box change it to All.
Check the boxes beside LOP Check and Purity Check.
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. 

good luck.

. Long story short I decided to wipe the drive clean again and install linux mint...
@mikaelrask.....will these tools work on Linux ?

no they won’t I am afraid

This sounds like a MBR problem or an infected file being reloaded

Thanks for answering guys, but doesn’t the mbr gets erased when you wipe and reformat the entire drive?
By the way the computer is a acer aspire 6530 notebook

It depends how you did the re-install, was it a full reformat first ?

Also are the backup files being restored clean

But you could check out for the lates MBR threat

[*]Download AntiZeroAccess to Desktop
[*]Double click on it to run it (If running Vista or Windows 7, right click on it and select “Run as an Administrator”)
[*]Type y and press enter to run the scan
[*]Please post AntiZeroAccess_Log.txt contents in your next post. This file is saved in the same location as AntiZeroAccess program.

I used the windows 7 installer dvd to reformat the drive. when I saw that the first time i couldn’t get rid of the virus I tried to reinstall windows 7 a second time but it failed. when I check the reason for the failure I saw that the entire drive had been filled that wasn’t any room left even though i had just wipe it clean

Hmm that does sound weird, I will see what I can find out

yhea good point there pondus. I missed that part that he installed linux.

Hi guys I’m back, well i can report that the monster is still alive. Over the long weekend ( i’m in the usa) I wiped the hard drive again installed windows 7 once more installed all the updates left everything nice and clean shut the machine down after working on it for like 10 hrs , and next day nothing, no boot up. check disk with partition manager and it seems to be ok.

Now that could well be a hardware problem - what hard drive do you have as we may need to run a diagnostics on it

Hi guys it’s me again to happily report that I think I found the problem. I think i had an mbr rootkit, that wouldn’t let me delete it or open it because it was encrypted. So what i did is I wiped the hard drive one more time, rebuilt the mbr using a bootable partitioning disk, reinstalled windows 7, installed all the updates, did a malwarebytes scan, an aswMBR scan, an AntiZeroAccess scan and everything came out clean and the computer is running faster than its ever been, thanks everybody for your help.

In that case I would suspect the zero access variant, I have only had limited exposure to that to date and I have been unable to get a decent handle on the symptoms. So the info came in handy Ta ;D