• ×
    Information
    Windows update impacting certain printer icons and names. Microsoft is working on a solution.
    Click here to learn more
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
  • ×
    Information
    Windows update impacting certain printer icons and names. Microsoft is working on a solution.
    Click here to learn more
    Information
    Need Windows 11 help?
    Check documents on compatibility, FAQs, upgrade information and available fixes.
    Windows 11 Support Center.
  • post a message
Guidelines
We have new content about Hotkey issue, Click here to check it out!
Check out our WINDOWS 11 Support Center info about: OPTIMIZATION, KNOWN ISSUES, FAQs, VIDEOS AND MORE.
HP Recommended
Pavilion dv6 notebook pc
Microsoft Windows 7 (64-bit)
So i got virused and aim to restore all to point zero where i only have the os back
I will back up all media to an external for later check on updated antivirus after recovery...
How can i make factory or recover system files to point zero...
All i want is a sure os empty of viruses.
May the recovery partition include virsus?
What is the best method please help.
1 ACCEPTED SOLUTION

Accepted Solutions
HP Recommended

I don't know what "massively virused" means but there is no reason in principle the infection could not spread to the recovery partition, not to mention you could have a rootkit that would survive a factory recovery. The only sure safe way to restore after such an attack is to run a rootkit killer which clears everything out of the boot sector

 

https://www.sophos.com/en-us/products/free-tools/sophos-anti-rootkit.aspx

 

and then run a full low level format (zero fill) on the drive

 

https://dban.org/

 

and then a clean install of Windows or recovery from an HP recovery disk that was made before the computer was infected or is an HP factory branded recovery disk. This should provide near military-grade security from propogation of the infection to a new installation. 

 

And I would run multiple antivirus and malware scans on that backed up data before putting it back on my new clean system. 

 

If this is "the Answer" please click "Accept as Solution" to help others find it. 

View solution in original post

8 REPLIES 8
HP Recommended
I saw the pinned how to restore to factory already....but my question is can i only restore system to point zero and may it contain virsus or sure won't?
HP Recommended

I don't know what "massively virused" means but there is no reason in principle the infection could not spread to the recovery partition, not to mention you could have a rootkit that would survive a factory recovery. The only sure safe way to restore after such an attack is to run a rootkit killer which clears everything out of the boot sector

 

https://www.sophos.com/en-us/products/free-tools/sophos-anti-rootkit.aspx

 

and then run a full low level format (zero fill) on the drive

 

https://dban.org/

 

and then a clean install of Windows or recovery from an HP recovery disk that was made before the computer was infected or is an HP factory branded recovery disk. This should provide near military-grade security from propogation of the infection to a new installation. 

 

And I would run multiple antivirus and malware scans on that backed up data before putting it back on my new clean system. 

 

If this is "the Answer" please click "Accept as Solution" to help others find it. 

HP Recommended
Ouch...
What if I don't have an HP recovery disk from before the infection?
The only recovery i have is that placed by HP on my recovery partition 😕
HP Recommended

Then you takes your chances. The computer nags you to make those backup and recovery DVDs for quite a while after the laptop is new. Most people don't or make them then lose them. This is one of those cases when you really need them. HP no longer has Windows 7 recovery disks available. 

HP Recommended
True
You never learn by the easy way...
If i remove the hdd after emptying the c drive...
Connect it external to another laptop with updated antivirus and run the toolkit also on it...
Do you think that will work?
Or dnt knw maybe install linux to a flash and boot from it and thus running those from it tho i think this method is useless since the antivirus will be downloaded on that drive which may be infected too...
HP Recommended
Btw
I didn't mention earlier
But thank you so much for your help...
Its good to know that exist people who share knowledge...
Thanks
HP Recommended

Your ideas are actually pretty good but I think the rootkit scanner has to be run from the drive it is scanning. There are Linux tools which will do a complete zero fill on an external hard drive. In fact dban is itself a Linux program I think. 

A complete zero fill will get rid of a rootkit so yes you can do it on the drive when connected externally to a different computer. 

HP Recommended
I think i will do that tomorrow and will post my feedback at then...
Thank you so much again...
Its highly appreciated how support you are and fast reply...
Thanks
† The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the <a href="https://www8.hp.com/us/en/terms-of-use.html" class="udrlinesmall">Terms of Use</a> and <a href="/t5/custom/page/page-id/hp.rulespage" class="udrlinesmall"> Rules of Participation</a>.