| |||||||
| Anything Goes Just like it says... anything goes. |
![]() |
| | LinkBack | Thread Tools | Display Modes |
| | #1 (permalink) | |
| Hey guys. I got a problem and I went straight to the geniuses of the field. A friend of mine caught a very interesting virus. It displays the text "ImIm" and "DuDu" during the initial boot up screen in red text. Once the next boot screen comes up, every line on the screen is covered with a - or a = making it hard to read the text behind it. I have initially thought it was a main board problem. I switched the board on the same hdd and a second later it hit it as well. I believe it is a virus. Now, it hides in the MBR of the hard drive and blocks off all visibility on screen to deleting it. I have tried to do fdisk /mbr but it does not go in with the windows 98 boot disk. The virus also copies itself onto a part of the bios. I figured I need to delete the MBR and format the drive completely. Once that is complete, turn off the computer and run a flash bios program and install new bios on it. Now, does anyone know how I can delete the Master Boot Record? Please do not tell me how to do it in windows! Thanks, any suggestions will be greatly appreciated! | ||
| | | |
| | #3 (permalink) | |
| Well, if it's a very well programmed virus, formatting the HD and then flashing wont help. You can format, but if its infected the BIOS, it will just put a fresh copy onto the HD. Get a mobo that lets you lock the ability to write on the BIOS via jumpers, then put that HD on it and try formatting. But because you tried a different mobo, try putting a old HD on either of the mobos and see if the viruse infects that HD too (If you have an old ~2gb hd.) Edit: typos x.x ![]() | ||
| | | |
| | #4 (permalink) | ||||||||||||||||||||
I tried that before. All that occurs is that it will skip a line and go back to C prompt | |||||||||||||||||||||
| | | ||||||||||||||||||||
| | #5 (permalink) | |
| Gladiator, If you have done that...then you have FDisk'd your MBR...DOS does not come back and say finished, the only thing message you will recieve is if you type a wrong commang. Did you also Fdisk the hard Drive and Format it? Were you able to flash the Bios? | ||
| | | |
| | #6 (permalink) | ||||||||||||||||||||
I thought fdisk mbr had a menu where you can choose to restore the boot record or delete it. I think the bios is not infected anymore. I dont the cmos clear as well as bios reset program built into the a-bit board and have had clean boots without the hard drive. Once the hard drive is connected, it all appears again. I think that the fdisk mbr is not deleting the master boot record. The hard drive is an IBM deskstar. I thought trying to use MaxBlast which comes with maxtor hdd but it autodetects the non-maxtor drive and quits the program early. What can be done to save this hard drive? | |||||||||||||||||||||
| | | ||||||||||||||||||||
| | #9 (permalink) | |
| I have a program that we call "GOD DISK", it does a governement wipe. Recently there was a thread regarding wiping the HD. There were some suggestions there. If you FDisk'd the MBR, FDisk'd the Hard Drive (delete the old partition and created a new one) and formatted it, the virus should be gone unless it resides inside the Bios. What is the name of the virus that you picked up? | ||
| | | |
| | #10 (permalink) | |
| no clue of the name. I think it was inserted by hand by someone. The computer is not mine but of my friend. He makes professional type of movies like party videos and etc. One of his business friends was jealous and did it (what we believe although we are not 100% sure. I have gotten the computer to boot into windows xp before and it recognized a virus and would not completly boot. It would stop 1/2 way in/ Where can i find this god disk? | ||
| | | |
| | #12 (permalink) | |
| if you have an original Norton CD, you can boot off that and it should run a quick scan, though if it's a new virus it might not be detected. You could have a buddy create a rescue disk set from their Norton Antivirus, but these are supposedly machine specific, probably worth a shot though... | ||
| | | |
| | #13 (permalink) | ||||||||||||||||||||
Thanks will try that. Btw Fantazmic2. why not make an image? winimage is perfect for that | |||||||||||||||||||||
| | | ||||||||||||||||||||
| | #14 (permalink) | |
| Ive got something similar to that Fantazmic, 2 different progs one called wipeit and the other is destroy it... cant remember where they came from but they sound like the same sort of thing and both run of floppy disk. you may be able to find them online Gladiator | ||
| | | |
| | #16 (permalink) | |
| I'm not familiar with your board, can you lock the bios? If need be, I gather for about 20 clams you can order a new bios chip, or send yours in for reprogramming. Google should help you on that one. This program from Symantec claims to terminate CIH (Chernobyl virus) from your memory, should at least confirm what the virus is. I *think* it'll run in DOS, if you boot from a win98 disk. Info on that prog, and Chernobyl in general, is here. They claim a 2001 or later Norton CDshould do it. | ||
| | | |
| | #17 (permalink) | |
| Well, might as well put in my .02 cents Run a Norton Anti-Virus scan/clean disk after booting to dos with a boot disk. If it finds it, it should clear it from the boot record and the hard drive. Flash the bios with an older version of the bios, or whatever the ABIT board will let you do. Doing a super duper wipe of the hard drive probably won't cure your problem. We use BC Wipe at work, which does a 7 pass wipe of the hard drive...and the only reason we do that is for classified systems to ensure no data is left to recover...I doubt the virus is written so well it can recover itself from a formatted disk and go back to work causing havoc. | ||
| | | |
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| warm boot performs cold boot..... | PCApexUser01 | Intel CPU/Motherboard OC | 9 | 11-June-06 08:09 PM |
| This is a record for me! | Fred_G | Anything Goes | 9 | 31-May-06 10:58 PM |
| 9600PRO AIW won't record from VCR. says "can't record broadcast video" | AMD Daddy | Video Cards | 14 | 03-April-05 01:56 AM |
| Affiliate Review: Cooler Master Wave Master @ 3D Velocity | Lokie | PC Apex Web News | 0 | 18-February-04 09:27 PM |
| Cooler Master Wave Master TAC-T01-BK Aluminum Case | Red02 | PC Apex Web News | 0 | 28-January-04 08:06 PM |