Computing.Net > Forums > Windows 95/98 > nyb virus

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

nyb virus

Reply to Message Icon

Name: mandy
Date: August 5, 2002 at 16:51:10 Pacific
Comment:

Ok - I've read everything i can on NYB virus and on your site and others. I know that the virus originally existed because when i started troubleshooting it found the virus. I think it is still in the boot sector. I have rebooted the system with an emergency boot disk with the latest .dat files.
I tried doing bootscan /clean / nomem. I tried fdisk /mbr. I was told by a techy to do a low level format. Won't this erase everything?

I am befuddled on what to do to fix this mess.

any more advise would only help.

thanks




Sponsored Link
Ads by Google

Response Number 1
Name: Andi
Date: August 5, 2002 at 16:56:21 Pacific
Reply:

www.orangeforest.com
www.antivirus.com
www.pandaosftware.co.uk

All these sites have free online anti virus scanner for you to pc your pc with. I would suggest giving one of them and go and see what it can pick up.


0

Response Number 2
Name: mandy
Date: August 5, 2002 at 17:00:26 Pacific
Reply:


well the problem is i can't log on to the internet with that system.

I am stuck in a safe mode boot win 98.

i have to have something that will fit on a floppy.

thanks tho i'll check it out.


0

Response Number 3
Name: John
Date: August 5, 2002 at 17:10:39 Pacific
Reply:

Fisrt off did you origanly find the virus in a file or in the boot record?

If it was in a file there is always that chance that the file was never executed and the virus never released on your PC.


The virus also loads into hi memory. Afetr cleaning the virus dont just reboot. The copy in RAM will just infect the PC again. Shut the PC all the way down.

Have you scanned all of your floppy disks for the virus? Including the one you keep booting the PC with when running Fdisk.


0

Response Number 4
Name: John
Date: August 5, 2002 at 17:13:17 Pacific
Reply:

I see nothing that says that the virus will stop your PC from booting in to windows normally.

What happens when you try to boot normal?


0

Response Number 5
Name: mandy
Date: August 5, 2002 at 17:22:13 Pacific
Reply:

When i try to boot normally it just goes diretly to the menu and gives me the option to go into dos prompt/safe mode etc.


0

Related Posts

See More



Response Number 6
Name: mandy
Date: August 5, 2002 at 17:22:55 Pacific
Reply:

anyone on AIM (mb61559 is my screen name!) help!


0

Response Number 7
Name: Mandy
Date: August 5, 2002 at 17:28:51 Pacific
Reply:

boot to the DOS promt
follow these commands at the c:

attrib msdos.sys -h -r -a -s
edit msdos.sys

you should get a blue edit screen with some text in it.

look for aline that says bootmenu=1

change it to bootmenu=0

save the file (Atl+f scroll down to save)
exit the file (Atl+f scroll down to exit)

At the c: type

attrib msdos.sys +a +s +r +h

reboot


0

Response Number 8
Name: John
Date: August 5, 2002 at 17:31:34 Pacific
Reply:

Opps i put your name in there....loIf you get a error when you type the attrib command then type this and try it again.

path=c:\windows\command


0

Response Number 9
Name: mandy
Date: August 5, 2002 at 17:41:16 Pacific
Reply:

Ok John, did that.

no bootmenu listed.

Options
bootMulti=1
bootGUI=1
doublebuffer=1
autoscan=1
winver=4.10.1998


0

Response Number 10
Name: John
Date: August 5, 2002 at 17:48:25 Pacific
Reply:

Under the boot menu that you are getting does it say something about windows not being shut down proprly or does it say something else?


0

Response Number 11
Name: mandy
Date: August 5, 2002 at 17:53:14 Pacific
Reply:

it says

windows did not finishing loading on the previous attempt.

choose safe mode to start Windows 98... then it tests the memory, then goes into safe mode automatially.


0

Response Number 12
Name: John
Date: August 5, 2002 at 18:10:33 Pacific
Reply:

Hmmm I am guessing that the Autoscan and win ver line are all the way at the bottom of the msdos.sys file. That is where they ussually are.

Does the PC run scan disk?

It is odd that it keepsloading that way and doesnt give you a chance to change how you want to boot up.


0

Response Number 13
Name: mandy
Date: August 5, 2002 at 18:14:36 Pacific
Reply:

also while doing mcafee virus scan
cannot scan boot record.


0

Response Number 14
Name: AA
Date: August 5, 2002 at 18:16:08 Pacific
Reply:

Mandy;

Let's start from the beginning:

Here, from Symantec...

"Discovered on: February 17, 1995"

"NYB is a simple virus that infects master boot records (MBR) and DOS boot sectors (DBS). NYB spreads to a system only when there is an attempt to boot the system from an infected floppy disk.

Target of infection: DOS

TECHNICAL DETAILS

During the boot process, NYB loads the MBR into memory and checks for infection. After determining that the MBR is not infected, the NYB stores the uninfected MBR at cylinder 0, side 0, sector 17 on the hard disk. NYB then places its virus code into the MBR and writes the infected MBR back to the
hard disk at cylinder 0, side 0, sector 1.

Once the boot process is complete and the NYB virus is active in memory, the virus displays its stealthing capabilities by redirecting any disk reads of the infected MBR or DBS to its clean counterpart. (On floppy disks, the original DBS is stored in the last sector of the root directory.) NYB is highly prolific."

You (or somebody using your PC) may have accidentally left an floopy in it's drive on a subsequent re-boot.

• Obtain a CLEAN and Write-Protected System Bootdisk on floppy.
• Obtain a DOS-based virus checker (like F-Prot)
• Boot from the Bootdisk
• Switch floopies to the DOS a-virus floppy
• Run the scan from that floppy

That should lead to resolving your problem, BUT, you must now also v-scan and clean your "innocent-looking" floppies... :(


0

Response Number 15
Name: mandy
Date: August 5, 2002 at 18:17:07 Pacific
Reply:

the files are listed in order as in previous post.

Yes i've done scandisk - no errors
I've defragged - no errors.

I have tried fdisk /mbr with the bios virus scan both dissabled and enabled.

It is a myster on how to clean that boot sector that's infected.


0

Response Number 16
Name: mandy
Date: August 5, 2002 at 18:32:40 Pacific
Reply:

how am i gonna get f-prot on a diskette? it's too big a file to transfer.


0

Response Number 17
Name: michael
Date: August 5, 2002 at 21:33:56 Pacific
Reply:

f-prot /loaddef
will load the def files from a second floppy.

The first floppy should contain:

English.tx0
f-prot.exe
macro.def

The second floppy will contain the two sign.def files.


0

Response Number 18
Name: mandy
Date: August 6, 2002 at 19:39:55 Pacific
Reply:

Hello Michael

Well thanks for that. However it didn't work.

I loaded F-prot.

Then it asked for a disk weith the two sign.def files and the macro.def file.
The new def files are too big with the macro.def file for one disk.

Still stuck!


0

Response Number 19
Name: michael
Date: August 6, 2002 at 22:03:45 Pacific
Reply:

You're quite right, that's why I listed which files go on which disk, the floppy with the sign.def and sign2.def files does not have the macro.def file on it. F-Prot should have asked for the macro.def file, at which point you would put the 1st floppy back in.

Sorry, I just checked the new August def files, and you're right, sign.def and sign2.def won't fit on a single floppy anymore (1k too big). Now we'll have to use 3 diskettes for it. Or put the sign2.def file on the 1st floppy. That should work.

The /loaddef switch only means to look on another floppy for the def files.


0

Sponsored Link
Ads by Google
Reply to Message Icon

AOL problems on Gateway 2... How to create Cutom Bootd...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows 95/98 Forum Home


Sponsored links

Ads by Google


Results for: nyb virus

NYB Virus level 4 www.computing.net/answers/windows-95/nyb-virus-level-4/70811.html

NYB VIRUS IN MY OTHER COMPUTER www.computing.net/answers/windows-95/nyb-virus-in-my-other-computer/43763.html

NYB virus found on WIN98 Master Boot Sector but DOS does not have MBR to fix.. Help www.computing.net/answers/windows-95/nyb-virus-found-on-win98-master-boot-sector-but-dos-does-not-have-mbr-to-fix-help/4934.html