Removal of Boot Sector Virus |
Author: |
Message: |
Vazza
Senior Member
![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif)
Posts: 855 Reputation: 28
– / / –
Joined: May 2003
|
O.P. Removal of Boot Sector Virus
Hey Guys
I've got a question for you all. I'm currently running Windows 98 SE on the family computer but as of today, we have discovered that there is a virus in the boot sector. While its there, we cannot copy the necessary files to restore the OS without doing a full format (we need the documents etc.) Is there anyway of removing the virus without format OR how to remove/overwrite the Winboot file in DOS (we discovered thats the source of it)
Thanks in advance
I'll never forget how lucky I was 7554 days, 12 hours, 24 minutes, 42 seconds ago
![[Image: 2tde3m]](http://tinyurl.com/2tde3m) ![[Image: 2y6ojm]](http://tinyurl.com/2y6ojm)
|
|
09-19-2005 07:21 PM |
|
![](images/pixel.gif) |
DJeX
Veteran Member
![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif)
![Avatar](avatar.php?uid=24324-2186)
Posts: 1138 Reputation: 11
– / / –
Joined: Jul 2003
|
RE: Removal of Boot Sector Virus
Ok well you say it’s being run from the Winboot file. Which is win.ini in the Windows folder.
Boot into dos and at the C:\ type:
edit C:\Windows\win.ini
you should be brought into a dos editor kind of like notepad but more UNuserfriendly and its blue.
You will see a bunch of typing. Look for a line with the word run in it. Followed by the word run you should see your virus's run path. One you have found and deleted (erased) the virus from the editor press ALT DOWNARROW then the file menu should open up. Navigate to the save option in the menu with the arrow keys and press enter. Once saved press ALT DOWNARROW and go to exit and press enter. That should work if like you said and it is in the win.ini file.
This post was edited on 09-19-2005 at 09:24 PM by DJeX.
|
|
09-19-2005 09:22 PM |
|
![](images/pixel.gif) |
Vazza
Senior Member
![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif)
Posts: 855 Reputation: 28
– / / –
Joined: May 2003
|
O.P. RE: Removal of Boot Sector Virus
well, we given it a try and we keep getting "bad command or file name". Would this suggest that the Command files for windows is corrupted as well?
I'll never forget how lucky I was 7554 days, 12 hours, 24 minutes, 42 seconds ago
![[Image: 2tde3m]](http://tinyurl.com/2tde3m) ![[Image: 2y6ojm]](http://tinyurl.com/2y6ojm)
|
|
09-19-2005 09:29 PM |
|
![](images/pixel.gif) |
ShawnZ
Veteran Member
![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif)
![Avatar](avatar.php?uid=4387-14065)
Posts: 3141 Reputation: 43
32 / / ![Canada Flag](images/flags/ca.png)
Joined: Jan 2003
|
RE: Removal of Boot Sector Virus
quote: Originally posted by DJeX
You will see a bunch of typing. Look for a line with the word run in it. Followed by the word run you should see your virus's run path. One you have found and deleted (erased) the virus from the editor press ALT DOWNARROW then the file menu should open up. Navigate to the save option in the menu with the arrow keys and press enter. Once saved press ALT DOWNARROW and go to exit and press enter. That should work if like you said and it is in the win.ini file.
Thats all nice and dandy, but 1) winboot isnt win.ini, and 2) its a bootsector virus, not an operating system virus.
quote: Originally posted by Vazza
well, we given it a try and we keep getting "bad command or file name". Would this suggest that the Command files for windows is corrupted as well?
Do a ' dir /s/b c: | find /i "edit.com" '. If anything comes up, try entering the full path to edit.com. If it still doesn't work then edit.com must be corrupted or something, but thats unlikely.
Spoiler: the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
|
|
09-19-2005 09:45 PM |
|
![](images/pixel.gif) |
DJeX
Veteran Member
![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif)
![Avatar](avatar.php?uid=24324-2186)
Posts: 1138 Reputation: 11
– / / –
Joined: Jul 2003
|
RE: Removal of Boot Sector Virus
Ahh yea I would say so, that should have worked. I even tested it on XP and it works fine. I used to use 98 SE for years. You’re sure you typed in
edit C:\Windows\win.ini
Well if that don't work I'd try navigating your computer in DOS and copying what ever you want saved to a floppy disk. But it can only be small files, music and such is too big.
Here is some DOS commands used for navigation and file copying.
dir - Displays all folders in your computer
cd - (Change directory) Changes the folder to a specified folder. Example: cd C:\Windows\Desktop that will open the folder Desktop in the folder Windows.
copy - copies a file to a specific source. Example: copy C:\Windows\My Documents\MyFile.doc A:\ this will copy MyFile.doc to the A:\ drive (floppy drive)
This info you should be able to navigate your computer in dos and copy and save the information you want on floppy disk providing the files are not any bigger than 1.44 mb.
|
|
09-19-2005 09:50 PM |
|
![](images/pixel.gif) |
Vazza
Senior Member
![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif)
Posts: 855 Reputation: 28
– / / –
Joined: May 2003
|
O.P. RE: Removal of Boot Sector Virus
The problem is that we don't all the file names DJex so that would be inmpossible....wouldn't it?
Shawnz: We'll give it a go tomorrow night but dad is talking about getting the professionals in (even though I could tell them how to do their job....well, parts of it ![:p](images/smilies/msn_tongue.gif) )
I'll never forget how lucky I was 7554 days, 12 hours, 24 minutes, 42 seconds ago
![[Image: 2tde3m]](http://tinyurl.com/2tde3m) ![[Image: 2y6ojm]](http://tinyurl.com/2y6ojm)
|
|
09-19-2005 09:53 PM |
|
![](images/pixel.gif) |
ShawnZ
Veteran Member
![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif)
![Avatar](avatar.php?uid=4387-14065)
Posts: 3141 Reputation: 43
32 / / ![Canada Flag](images/flags/ca.png)
Joined: Jan 2003
|
RE: Removal of Boot Sector Virus
You know, this could be so much simpler if you just got a linux livecd.
http://stuwww.uvt.nl/ubuntu/hoary/ubuntu-5.04-live-i386.iso
Spoiler: the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
the game.
|
|
09-19-2005 09:55 PM |
|
![](images/pixel.gif) |
Vazza
Senior Member
![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif)
Posts: 855 Reputation: 28
– / / –
Joined: May 2003
|
O.P. RE: Removal of Boot Sector Virus
ShawnZ: I can't use that. Already tried the one that I was given as part of someone research project and it refused to load to the computer.
I'll never forget how lucky I was 7554 days, 12 hours, 24 minutes, 42 seconds ago
![[Image: 2tde3m]](http://tinyurl.com/2tde3m) ![[Image: 2y6ojm]](http://tinyurl.com/2y6ojm)
|
|
09-19-2005 09:57 PM |
|
![](images/pixel.gif) |
Concord Dawn
Veteran Member
![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif)
![Avatar](avatar.php?uid=29319-4682)
This is a loopy fruit.
Posts: 1203 Reputation: 16
34 / / –
Joined: Feb 2004
|
RE: Removal of Boot Sector Virus
quote: Originally posted by Vazza
ShawnZ: I can't use that. Already tried the one that I was given as part of someone research project and it refused to load to the computer.
Ubuntu live works on my 9 year old computer. Linux runs on anything, like gorgeous fembots with a penchant for evil
Seriously though, give the Ubuntu live disc a shot, it's better than paying some dude to dink around with your computer isn't it?
|
|
09-19-2005 11:10 PM |
|
![](images/pixel.gif) |
lizard.boy
Veteran Member
![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif) ![*](images/star.gif)
![Avatar](avatar.php?uid=8700-3903)
Posts: 1708 Reputation: 24
34 / / ![Canada Flag](images/flags/ca.png)
Joined: Mar 2003
|
RE: Removal of Boot Sector Virus
take the drive out and install it in another computer? thats what i do when worse comes to even worse. that way you can copy docuemnts off the computer's disc, and then you can reinstall windows or just pitch the machine or its drive if its old enough and your willing to replace it.
|
|
09-20-2005 12:14 AM |
|
![](images/pixel.gif) |
Pages: (2):
« First
[ 1 ]
2
»
Last »
|
|