Go Back   TechArena Community > Hardware > Hardware Peripherals
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read

Sponsored Links



How to Remove MBR Virus?

Hardware Peripherals


Reply
 
Thread Tools Search this Thread
  #1  
Old 07-07-2009
cheap_kaspersky
 
Posts: n/a
How to Remove MBR Virus?
  

I am running windows vista 32 bits. However since i installed the vista there is something strange when start booting. Sometimes weird binary codes automatically written itself on the screen, at other times it says missing GLDR or NTLDR.

Now i suspected a virus, worms, or trojans is infecting the Master Boot Record.

I run kaspersky scan, no virus is found. However there are two strange file in windows that is password protected which Kaspersky did not scan. Below is the two file.

C:\Windows\Setup\Scripts\Biestart.exe
C:\Windows\Setup\Scripts\Start.exe

How the my question is how can i detect anymore MBR viruses in the boot sector and remove them once and for all. As well as scanning the two password protected files to check if it contains virus

Hope to hear perfect solutions.

Reply With Quote
  #2  
Old 07-07-2009
Member
 
Join Date: Nov 2005
Posts: 2,475
Re: How to Remove MBR Virus?

When disinfecting a boot sector virus, the system should always be booted from a known clean system disk. Microsoft provides a customized antivirus tool that can be used for these types of viruses. Whether you use a third-party antivirus program or AVBoot, be sure to regularly update the virus signature files. Once you install an antivirus program, immediately update the signature files, usually through an Internet connection. On a DOS-based PC, a bootable system disk can be created on a clean system running the exact same version of DOS as the infected PC. From a DOS prompt, type:SYS C:\ A:\ and press enter. This will copy the system files from the local hard drive (C:\) to the floppy drive (A:\).
Reply With Quote
  #3  
Old 07-07-2009
Member
 
Join Date: Sep 2005
Posts: 2,315
Re: How to Remove MBR Virus?

Try doing this -

* Boot your system into MS-DOS with a bootable disk or floppy.
* Type fdisk /mbr and press ENTER
* Restart

Hope this helps you.
Reply With Quote
  #4  
Old 07-07-2009
cheap_kaspersky
 
Posts: n/a
Re: How to Remove MBR Virus?

Quote:
Originally Posted by maxforu View Post
When disinfecting a boot sector virus, the system should always be booted from a known clean system disk. Microsoft provides a customized antivirus tool that can be used for these types of viruses. Whether you use a third-party antivirus program or AVBoot, be sure to regularly update the virus signature files. Once you install an antivirus program, immediately update the signature files, usually through an Internet connection. On a DOS-based PC, a bootable system disk can be created on a clean system running the exact same version of DOS as the infected PC. From a DOS prompt, type:SYS C:\ A:\ and press enter. This will copy the system files from the local hard drive (C:\) to the floppy drive (A:\).
Can you explain in simple how the booting is done and what should i do first?
Reply With Quote
  #5  
Old 07-07-2009
Member
 
Join Date: Apr 2008
Posts: 2,330
Re: How to Remove MBR Virus?

Boot-sector viruses are spread to computer systems by booting, or attempting to boot, from an infected floppy disk. Even if the disk does not contain the MS-DOS system files needed to successfully boot, an attempt to boot from an infected disk will load the virus into memory.

Check this microsoft guide for more information : Methods to Detect a Boot-Sector Virus
Reply With Quote
  #6  
Old 07-07-2009
cheap_kaspersky
 
Posts: n/a
Re: How to Remove MBR Virus?

Quote:
Originally Posted by deoWo View Post
Boot-sector viruses are spread to computer systems by booting, or attempting to boot, from an infected floppy disk. Even if the disk does not contain the MS-DOS system files needed to successfully boot, an attempt to boot from an infected disk will load the virus into memory.

Check this microsoft guide for more information : Methods to Detect a Boot-Sector Virus
Hmm...you are directing to a page where i need to read again which i have done before. Can anyone find a straight forward solution without explaining too many and directing to other sites
Reply With Quote
  #7  
Old 07-07-2009
Member
 
Join Date: Nov 2005
Posts: 2,326
Re: How to Remove MBR Virus?

Here are some thread made on how to remove virus from your computer I think you just look at the solution & you will definitely can remove all the infected virus on your computer.... Hope this helps you.....!

http://forums.techarena.in/windows-x...ort/776842.htm
http://forums.techarena.in/guides-tutorials/501102.htm
Can't remove spyware virus
Reply With Quote
  #8  
Old 07-07-2009
Member
 
Join Date: May 2008
Posts: 1,813
Re: How to Remove MBR Virus?

To remove a boot sector virus you will need to boot your system with a clean system disk. First you will have to create a startup disk. In a different pc which is not infected with virus and ruining on the same os run the dos tool. Insert a floppy and give the command SYS C:\ A:\. Press enter. If the disk is not formatted then use Format /S command and then give the above command back. Insert the disk in your system and boot your computer.
Reply With Quote
  #9  
Old 07-07-2009
Member
 
Join Date: Oct 2008
Posts: 454
Re: How to Remove MBR Virus?

Running Fdisk /mbr in MS-DOS overwrites only the first 446 bytes of the MBR, the portion known as the master boot code, leaving the existing partition table intact. However, if the signature word, the last two bytes of the MBR, has been deleted, the partition table entries are overwritten with zeroes. If an MBR virus overwrites the signature word, access to all partitions and logical volumes is lost.

Fixmbr command

The Recovery Console, a troubleshooting tool in Windows , offers a feature called Fixmbr . However, it functions identically to the Fdisk /mbr command, replacing only the master boot code and not affecting the partition table. For this reason, it is also unlikely to help resolve an infected MBR.
Reply With Quote
  #10  
Old 07-07-2009
cheap_kaspersky
 
Posts: n/a
Re: How to Remove MBR Virus?

Alright i appreciate all your help. I try the whole day to manage scan the boot disk and remove the virus. And i found a tutorial using the Kaspersky Rescue Disk. Now the disk is clean and need reformat. I need to reinstall with Windows XP. Thanks all with so many of your help
Reply With Quote
Reply

  TechArena Community > Hardware > Hardware Peripherals
Tags: , ,



Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "How to Remove MBR Virus?"
Thread Thread Starter Forum Replies Last Post
How to remove NBT/NBT.exe virus Abriennea Networking & Security 2 25-08-2011 11:02 AM
How to remove n.exn virus. Micmac Networking & Security 6 20-07-2010 06:22 AM
Want to remove this BAT.Ftp.dm virus Kalanidhi Networking & Security 4 30-03-2010 06:31 AM
How to remove this VBS.Lee virus? Sydney_7 Networking & Security 4 23-03-2010 05:59 AM
How to remove RPC virus AbrahamL Networking & Security 5 09-02-2010 05:01 AM


All times are GMT +5.5. The time now is 10:08 AM.