Results 1 to 10 of 10

Thread: How to Remove MBR Virus?

  1. #1
    cheap_kaspersky Guest

    How to Remove MBR Virus?

    I am running windows vista 32 bits. However since i installed the vista there is something strange when start booting. Sometimes weird binary codes automatically written itself on the screen, at other times it says missing GLDR or NTLDR.

    Now i suspected a virus, worms, or trojans is infecting the Master Boot Record.

    I run kaspersky scan, no virus is found. However there are two strange file in windows that is password protected which Kaspersky did not scan. Below is the two file.

    C:\Windows\Setup\Scripts\Biestart.exe
    C:\Windows\Setup\Scripts\Start.exe

    How the my question is how can i detect anymore MBR viruses in the boot sector and remove them once and for all. As well as scanning the two password protected files to check if it contains virus

    Hope to hear perfect solutions.

  2. #2
    Join Date
    Nov 2005
    Posts
    2,483

    Re: How to Remove MBR Virus?

    When disinfecting a boot sector virus, the system should always be booted from a known clean system disk. Microsoft provides a customized antivirus tool that can be used for these types of viruses. Whether you use a third-party antivirus program or AVBoot, be sure to regularly update the virus signature files. Once you install an antivirus program, immediately update the signature files, usually through an Internet connection. On a DOS-based PC, a bootable system disk can be created on a clean system running the exact same version of DOS as the infected PC. From a DOS prompt, type:SYS C:\ A:\ and press enter. This will copy the system files from the local hard drive (C:\) to the floppy drive (A:\).

  3. #3
    Join Date
    Sep 2005
    Posts
    2,327

    Re: How to Remove MBR Virus?

    Try doing this -

    * Boot your system into MS-DOS with a bootable disk or floppy.
    * Type fdisk /mbr and press ENTER
    * Restart

    Hope this helps you.

  4. #4
    cheap_kaspersky Guest

    Re: How to Remove MBR Virus?

    Quote Originally Posted by maxforu View Post
    When disinfecting a boot sector virus, the system should always be booted from a known clean system disk. Microsoft provides a customized antivirus tool that can be used for these types of viruses. Whether you use a third-party antivirus program or AVBoot, be sure to regularly update the virus signature files. Once you install an antivirus program, immediately update the signature files, usually through an Internet connection. On a DOS-based PC, a bootable system disk can be created on a clean system running the exact same version of DOS as the infected PC. From a DOS prompt, type:SYS C:\ A:\ and press enter. This will copy the system files from the local hard drive (C:\) to the floppy drive (A:\).
    Can you explain in simple how the booting is done and what should i do first?

  5. #5
    Join Date
    Apr 2008
    Posts
    2,347

    Re: How to Remove MBR Virus?

    Boot-sector viruses are spread to computer systems by booting, or attempting to boot, from an infected floppy disk. Even if the disk does not contain the MS-DOS system files needed to successfully boot, an attempt to boot from an infected disk will load the virus into memory.

    Check this microsoft guide for more information : Methods to Detect a Boot-Sector Virus

  6. #6
    cheap_kaspersky Guest

    Re: How to Remove MBR Virus?

    Quote Originally Posted by deoWo View Post
    Boot-sector viruses are spread to computer systems by booting, or attempting to boot, from an infected floppy disk. Even if the disk does not contain the MS-DOS system files needed to successfully boot, an attempt to boot from an infected disk will load the virus into memory.

    Check this microsoft guide for more information : Methods to Detect a Boot-Sector Virus
    Hmm...you are directing to a page where i need to read again which i have done before. Can anyone find a straight forward solution without explaining too many and directing to other sites

  7. #7
    Join Date
    Nov 2005
    Posts
    2,327

    Re: How to Remove MBR Virus?

    Here are some thread made on how to remove virus from your computer I think you just look at the solution & you will definitely can remove all the infected virus on your computer.... Hope this helps you.....!

    http://forums.techarena.in/windows-x...ort/776842.htm
    http://forums.techarena.in/guides-tutorials/501102.htm
    Can't remove spyware virus

  8. #8
    Join Date
    May 2008
    Posts
    1,822

    Re: How to Remove MBR Virus?

    To remove a boot sector virus you will need to boot your system with a clean system disk. First you will have to create a startup disk. In a different pc which is not infected with virus and ruining on the same os run the dos tool. Insert a floppy and give the command SYS C:\ A:\. Press enter. If the disk is not formatted then use Format /S command and then give the above command back. Insert the disk in your system and boot your computer.

  9. #9
    Join Date
    Oct 2008
    Posts
    454

    Re: How to Remove MBR Virus?

    Running Fdisk /mbr in MS-DOS overwrites only the first 446 bytes of the MBR, the portion known as the master boot code, leaving the existing partition table intact. However, if the signature word, the last two bytes of the MBR, has been deleted, the partition table entries are overwritten with zeroes. If an MBR virus overwrites the signature word, access to all partitions and logical volumes is lost.

    Fixmbr command

    The Recovery Console, a troubleshooting tool in Windows , offers a feature called Fixmbr . However, it functions identically to the Fdisk /mbr command, replacing only the master boot code and not affecting the partition table. For this reason, it is also unlikely to help resolve an infected MBR.

  10. #10
    cheap_kaspersky Guest

    Re: How to Remove MBR Virus?

    Alright i appreciate all your help. I try the whole day to manage scan the boot disk and remove the virus. And i found a tutorial using the Kaspersky Rescue Disk. Now the disk is clean and need reformat. I need to reinstall with Windows XP. Thanks all with so many of your help

Similar Threads

  1. How to remove NBT/NBT.exe virus
    By Abriennea in forum Networking & Security
    Replies: 2
    Last Post: 25-08-2011, 11:02 AM
  2. Want to remove this BAT.Ftp.dm virus
    By Kalanidhi in forum Networking & Security
    Replies: 4
    Last Post: 30-03-2010, 06:31 AM
  3. How to remove this VBS.Lee virus?
    By Sydney_7 in forum Networking & Security
    Replies: 4
    Last Post: 23-03-2010, 05:59 AM
  4. How to remove RPC virus
    By AbrahamL in forum Networking & Security
    Replies: 5
    Last Post: 09-02-2010, 06:01 AM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,713,460,281.24098 seconds with 17 queries