Shoutbox

Removal of Boot Sector Virus - Printable Version

-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: Skype & Technology (/forumdisplay.php?fid=9)
+---- Forum: Tech Talk (/forumdisplay.php?fid=17)
+----- Thread: Removal of Boot Sector Virus (/showthread.php?tid=50684)

Removal of Boot Sector Virus by Vazza on 09-19-2005 at 07:21 PM

Hey Guys

I've got a question for you all. I'm currently running Windows 98 SE on the family computer but as of today, we have discovered that there is a virus in the boot sector. While its there, we cannot copy the necessary files to restore the OS without doing a full format (we need the documents etc.) Is there anyway of removing the virus without format OR how to remove/overwrite the Winboot file in DOS (we discovered thats the source of it)

Thanks in advance


RE: Removal of Boot Sector Virus by DJeX on 09-19-2005 at 09:22 PM

Ok well you say it’s being run from the Winboot file. Which is win.ini in the Windows folder.

Boot into dos and at the C:\ type:

edit C:\Windows\win.ini

you should be brought into a dos editor kind of like notepad but more UNuserfriendly and its blue. 

You will see a bunch of typing. Look for a line with the word run in it. Followed by the word run you should see your virus's run path. One you have found and deleted (erased) the virus from the editor press ALT DOWNARROW then the file menu should open up. Navigate to the save option in the menu with the arrow keys and press enter. Once saved press ALT DOWNARROW and go to exit and press enter. That should work if like you said and it is in the win.ini file.


RE: Removal of Boot Sector Virus by Vazza on 09-19-2005 at 09:29 PM

well, we given it a try and we keep getting "bad command or file name". Would this suggest that the Command files for windows is corrupted as well?


RE: Removal of Boot Sector Virus by ShawnZ on 09-19-2005 at 09:45 PM

quote:
Originally posted by DJeX
You will see a bunch of typing. Look for a line with the word run in it. Followed by the word run you should see your virus's run path. One you have found and deleted (erased) the virus from the editor press ALT DOWNARROW then the file menu should open up. Navigate to the save option in the menu with the arrow keys and press enter. Once saved press ALT DOWNARROW and go to exit and press enter. That should work if like you said and it is in the win.ini file.

Thats all nice and dandy, but 1) winboot isnt win.ini, and 2) its a bootsector virus, not an operating system virus.

quote:
Originally posted by Vazza
well, we given it a try and we keep getting "bad command or file name". Would this suggest that the Command files for windows is corrupted as well?

Do a ' dir /s/b c: | find /i "edit.com" '. If anything comes up, try entering the full path to edit.com. If it still doesn't work then edit.com must be corrupted or something, but thats unlikely.
RE: Removal of Boot Sector Virus by DJeX on 09-19-2005 at 09:50 PM

Ahh yea I would say so, that should have worked. I even tested it on XP and it works fine. I used to use 98 SE for years. You’re sure you typed in

edit C:\Windows\win.ini

Well if that don't work I'd try navigating your computer in DOS and copying what ever you want saved to a floppy disk. But it can only be small files, music and such is too big.

Here is some DOS commands used for navigation and file copying.

dir - Displays all folders in your computer

cd - (Change directory) Changes the folder to a specified folder. Example: cd C:\Windows\Desktop  that will open the folder Desktop in the folder Windows.

copy - copies a file to a specific source. Example: copy C:\Windows\My Documents\MyFile.doc A:\     this will copy MyFile.doc to the A:\ drive (floppy drive)

This info you should be able to navigate your computer in dos and copy and save the information you want on floppy disk providing the files are not any bigger than 1.44 mb.


RE: Removal of Boot Sector Virus by Vazza on 09-19-2005 at 09:53 PM

The problem is that we don't all the file names DJex so that would be inmpossible....wouldn't it?

Shawnz: We'll give it a go tomorrow night but dad is talking about getting the professionals in (even though I could tell them how to do their job....well, parts of it :p)


RE: Removal of Boot Sector Virus by ShawnZ on 09-19-2005 at 09:55 PM

You know, this could be so much simpler if you just got a linux livecd.

http://stuwww.uvt.nl/ubuntu/hoary/ubuntu-5.04-live-i386.iso


RE: Removal of Boot Sector Virus by Vazza on 09-19-2005 at 09:57 PM

ShawnZ: I can't use that.  Already tried the one that I was given as part of someone research project and it refused to load to the computer.


RE: Removal of Boot Sector Virus by Concord Dawn on 09-19-2005 at 11:10 PM

quote:
Originally posted by Vazza
ShawnZ: I can't use that.  Already tried the one that I was given as part of someone research project and it refused to load to the computer.

Ubuntu live works on my 9 year old computer. Linux runs on anything, like gorgeous fembots with a penchant for evil :cheesy:

Seriously though, give the Ubuntu live disc a shot, it's better than paying some dude to dink around with your computer isn't it?
RE: Removal of Boot Sector Virus by lizard.boy on 09-20-2005 at 12:14 AM

take the drive out and install it in another computer? thats what i do when worse comes to even worse. that way you can copy docuemnts off the computer's disc, and then you can reinstall windows or just pitch the machine or its drive if its old enough and your willing to replace it.


RE: Removal of Boot Sector Virus by DJeX on 09-20-2005 at 12:57 AM

if you use the dir it lists the files and the names


RE: Removal of Boot Sector Virus by Vazza on 09-21-2005 at 12:48 PM

well thanks for the suggestions guys. I'll keep a note of them in case what we are going to do tonight doesn't work (Going to see a friend who can make our harddrive a second harddrive for his computer to allow us to run antiviral software on it.)

It went to the friend and turns out that it where we should have only had 5 directories, there were 97, probably meaning that everytime we booted it up, that it was duplicating. Friend copied the entite hd contents to a USB hd, partioned the drive so that the files we couldn't remove will just sit there and installed Windows XP profesional for us. Now its the long process of sitting going through the USB drive to find what files we want to keep :(.

Appears that it not just who have the problem though. Someone else my dad know seems to have got the same problem as well.

Anyways, thanks you all your help :)