The Deployer

February 27, 2005

Boot Viruses

Filed under: Malware — Lucian Daniliuc @ 12:38

Boot viruses can be easily removed from the hard-drive by booting from a clean disk and typing fdisk /mbr. What I didn’t knew is that it is also required (in some cases) that the command sys c: is typed. This is at least true for a windows 98 second edition installation infected by Preboot.A (alias WYZ or something like that). This is because fdisk /mbr only cleans the Master Boot Record, leaving the boot partiton’s sector intact (and infected), and for wich is required to launch sys c: to rebuild the system sector of the selected partition.

No Comments »

No comments yet.

RSS feed for comments on this post. TrackBack URL

Leave a comment

Powered by WordPress