The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    T boot virus on M1330

    Discussion in 'Security and Anti-Virus Software' started by samuraitor, May 23, 2008.

  1. samuraitor

    samuraitor Notebook Enthusiast

    Reputations:
    0
    Messages:
    22
    Likes Received:
    0
    Trophy Points:
    5
    hi there,

    my M1330 has a T boot virus which I tried to remove from safe mode with Nod 32, however, when tried to start the scanning in safe mode, Nod 32 said kernel problems.


    How can I remove the virus?
     
  2. bmwrob

    bmwrob Notebook Virtuoso

    Reputations:
    4,591
    Messages:
    2,128
    Likes Received:
    0
    Trophy Points:
    55
    I've never before heard of a T boot virus. What does that mean?
     
  3. laptop4life

    laptop4life Notebook Consultant

    Reputations:
    25
    Messages:
    265
    Likes Received:
    0
    Trophy Points:
    30
    if you mean a boot sector virus, this is what it does: A boot sector virus infects or substitutes its own code for either the DOS boot sector or the Master Boot Record (MBR). The MBR is small program that runs every time the computer starts up. It controls the boot sequence and determines which partition the computer boots from. The MBR generally resides on the first sector of the hard disk.

    Since the MBR executes every time a computer is started, a boot sector virus is extremely dangerous. Once the boot code on the drive is infected, the virus will be loaded into memory on every startup. From memory the boot virus can spread to every disk that the system reads.

    What it does:
    It can cause a variety of boot or data retrieval problems. In some cases, data disappears from entire partitions. In other cases, the computer suddenly becomes unstable. A common problem is failure to start up or to find the hard drive.
     
  4. Greg

    Greg Notebook Nobel Laureate

    Reputations:
    7,857
    Messages:
    16,212
    Likes Received:
    58
    Trophy Points:
    466
    Best way is to completely wipe the hard drive...but you MIGHT be able to use a Windows disc to completely erase and re-create the MBR.
     
  5. samuraitor

    samuraitor Notebook Enthusiast

    Reputations:
    0
    Messages:
    22
    Likes Received:
    0
    Trophy Points:
    5
    is there any other way to remove the boot virus without formating/?
     
  6. Baserk

    Baserk Notebook user

    Reputations:
    2,503
    Messages:
    1,794
    Likes Received:
    1
    Trophy Points:
    56
    Are you by any chance using an encryption or backup program, something like Jetico's BestCrypt Volume Encryption/BCVE or Paragon BackUp?
    If so, that might cause a false positive.
    Programs like these can modify the MBR to provide pre-boot authentification.
    NOD32 has been seen reacting to this with false positives, it would warn about a 'TSR boot virus'.

    However, you write about a 'T boot virus' and that's something else.
    So if the above information doesn't apply to you, you might try a program like Avira's bootable Antivir Rescuesytem, download it and burn it to a CD and then run it by making your CD/DVD-player the first bootable device in your BIOS.
    Just run the program and see if gives you a warning about your MBR also.

    If it would be my laptop however, I would erase the hard drive with a program like DBAN or KillDisk using one-pass zero's and re-install the OS.
    That way you can be really sure you have a clean machine.
     
  7. samuraitor

    samuraitor Notebook Enthusiast

    Reputations:
    0
    Messages:
    22
    Likes Received:
    0
    Trophy Points:
    5
    Well it is a boot virus in the boot sector of the hard drive.

    I have scanned my system several times ,and no viruses. however, a window pops up every now and then about this boot virus which cannot be deleted.

    So there is no other way than just to delete the damn hard drive ? not even in the safe mode?

    is it possible to from boot from a usb drive?