Computing.Net > Forums > Security and Virus > Boot Sector Virus Kills FAT & MBR

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Boot Sector Virus Kills FAT & MBR

Reply to Message Icon

Original Message
Name: ScorpioSting
Date: June 2, 2002 at 01:29:55 Pacific
Subject: Boot Sector Virus Kills FAT & MBR
Comment:

yup, this has been a nasty nightmare.

running WinME on my Grrrlfriends computer she kept having 'slow downs', BSofD, unexplained shut downs & reboots and the 'freezes'.

She ran ME Second Chance, like, 100 times in a fornight, reformatted, re installed but after a couple of reboots the same thing happened.

all the Anti V software (Norton, PC-Chillin, Mcafe) failed to detect anything, Norton at dos-prompt and Windows.

The problem reached it's peak this weekend when the FAT info dissappeared after every second reboot and I had to restore with fdisk and reinstall ME second chance as microsoft will no longer let you format /s or SYS C: (b---tards) you can only do that under windows or from instillation CD grrrr. and I didn't have my win95 or dos622 disks here.

now the problem got worse, Norton found it had a boot sector virus but claimed that the FAT was completely filled and could not restore or rewrite another (boot sector holds 3 copies I believe~ so fdisk /mbr should be done 3 time to REALLY kill any bad stuff in it!) so....
rebooted from my own EBD with lowlevel progs on it but now the entire FAT has vanished and the drive is completely unreachable. The BIOS detects it okay, as both a master and as secondary slave with all the right geometry but none of the microsoft OS will acknowledge it's existence at all, (I have yet to try it on my Linux system though...)

I have had to buy a new drive and reinstall ME on that but there are some things on the other disk I'd like to preserve if poss but might just have to loose them with a low level format & zero the bugger out.

anyway...long message but does anyone know of a virus that wipes both the FAT and MBR rendering the disk unreachable to anything except Bios & screwdrivers???
I have just had the thought it might be a BIOS virus and I should have cleared the CMOS before putting the new drive in but I can work backwards on that later....

any ideas would be appreciated
Thanx


Report Offensive Message For Removal


Response Number 1
Name: Charger
Date: June 2, 2002 at 09:38:11 Pacific
Reply: (edit)

There is CIH which will FlashBIOS.
But I don't think you have CIH.
If you can, which I don't think you can, go to my site and do a low level format.
This will erase everything and start it from scratch...FATs MBR's etc.
Once that's done, I highly reccomend going and buying a GOOD antivirus. Like PC-Cillin.

After that, you might wanto to read my Antivirus tips write up. It will help you alot.

http://boomspeed.com/dodgecharger

Good Luck
Charger


Report Offensive Follow Up For Removal

Response Number 2
Name: wawadave
Date: June 2, 2002 at 16:09:44 Pacific
Reply: (edit)

hello
you can do format from boot disk format c:
should do it. and at the a:\sys c: works with boot disk allso
ether a 98 boot disk or m.e will work


Report Offensive Follow Up For Removal

Response Number 3
Name: Scorpio Sting
Date: June 3, 2002 at 15:37:31 Pacific
Reply: (edit)

Thanks guys, as it stands I've flashed the Bios just in case and put in a new hdd AND RE INSTALLED me.
We have PC-Chillin and Norton but either seem to crash way too often, I have suspicions about registry stuff being an ass but reckon its just Microsoft's dammed buggy programming and a preinstalled "Tiny" package.
I'm gonna low level the other hdd later in the week on one of my machines at my place after trying some disk rescue programs, got from site mentioned in another thread.
I will have a looksee at your site too Charger :)

Wavadave, still not been able to get ME or XP to cooperate with manual format /s or sys /C: ... just says this version of windows no longer supports blahblahblah.
nevermind eh?

l8ts dudes.


Report Offensive Follow Up For Removal

Response Number 4
Name: Charger
Date: June 3, 2002 at 18:13:28 Pacific
Reply: (edit)

Get rid of one of the AV's.
You can't have 2 av's at a time. That is why your computer has been crashing.

P.s. Just about all of the instructions you will need are on my site. Formatting, low level formatting, etc.

GooD Luck

Charger


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you own an iPhone?

Yes
No, but soon
No


View Results

Poll Finishes In 7 Days.
Discuss in The Lounge
Poll History




Data Recovery Software