Virus Problems Please help!

Waffen

Member
Jun 25, 2001
47
0
0
Hey guys, I think my dad downloaded a virus on my comp or somthing. I came back from work one day and found a majority of my folders with tons of .eml files that I have NEVER seen. One of them being I_love_you.eml and I about crap my pants. Anyway I formated my drive thinking that it would get rid of it but no! After a clean sweep of the drive it was back again! I was informed that it could be in the /mbr so.... how do I get rid of this? I have no problems with formating the drive I just want to get rid of all these god damn emails that keep appearing in dir's even after I format! Thanks for the quick responce
 

Mookow

Lifer
Apr 24, 2001
10,162
0
0
I think fdisk/mbr should rebuild the MBR. I think it could be nimda. I just had Nimda, asnd got rid of it using the nimda remove tool found at symantec, who are the people that make Norton
 

Mookow

Lifer
Apr 24, 2001
10,162
0
0
Note: I say it could be Nimda because I suddenly aquired many new .eml files, too. Nimda never got into my MBR, though. I caught it pretty quickly, though, so................
 

Mookow

Lifer
Apr 24, 2001
10,162
0
0
It should be entirely non-destructive to the rest of your drive...... It just rebuilds the MBR........ I think......... let others weigh in before doing it.......
 

Waffen

Member
Jun 25, 2001
47
0
0
???? I am about to do this command all I need to know is if I am gona have to install somthing after I type the command?
 

Waffen

Member
Jun 25, 2001
47
0
0
ok, I just got conformation on what you said on other fourms. I will give this a try. In the other forums I got the msg to type format /mbr any difference there?
 

Mookow

Lifer
Apr 24, 2001
10,162
0
0
If you reformatted your drive already, then yeah, whatever was on it is gone. Otherwise, no, it shouldnt do anything to the rest of your system.
 

Mookow

Lifer
Apr 24, 2001
10,162
0
0
yeah..... just hold up a second, let someone else confirm..... It shoudl do the same thing (between the two different commands)... but my DOS is rusted
 

AMD4ME2

Senior member
Jul 25, 2000
664
0
0
well, I guess it depends on which virus it is.. but the first thing I would try would be

fdisk /mbr

which will rewrite your master boot record.

if you didn't fdisk the drive and wipe the partition tables I would do that as well..

also make sure you kill the power to the computer, some viruses stay resident in memory even
when the computer is shut down. a simple reboot will not get them out of memory, I would go as far as to unplug the power supply unit.

I've also heard of viruses infecting the bios chip.. just off the top of my head this sounds like that nasty magistrate(magistrar? can't remember the exact name) virus from a few months back. if it is that virus, it could be on your bios chip... clearing the cmos by shorting the jumper pins momentarily may help as well..

 

Waffen

Member
Jun 25, 2001
47
0
0
This is the answer I got on ardforums

fdisk, kill allyour partitions
reboot
fdisk /mbr
reboot
unplug your machine
go away for 2 minutes
plug it back in
format
reboot
unplug your machine
go away for 2 minutes
plug it back in
install your OS
install some antivirus software

They say its nimda so.....
 

Mookow

Lifer
Apr 24, 2001
10,162
0
0
dude, if you have AIM, I can send you the Nimda removal tool, or you can d/l it from symantec. You really dont have to reformat