Remove a Boot Sector Virus

Has your computer been acting strange lately? Has it been running slow, or telling you that your computer needs a certain program? If so it may have a virus. This article deals with ones called Boot Sector Viruses. These reside in the sectors that are used to start your Operating System. A simple operating system replacement may leave the virus to continue its evil ways.

Steps

  1. Remove any important files and shut down the infected computer. You can not begin to remove the virus if it is in the RAM in your computer.
  2. Option 1: Take the drive to a pro. UNPLUG the computer, and all monitors, etc. Remove the HDD (hard disk drive or hard drive) from the infected computer. Be sure to remove all of the static electricity from your self by touching the metal case.
  3. Option 2: Use software on a CD-ROM or floppy (yes, you can still download recovery tools as floppy images) to scan the drive and fix the MBR. Start with the OS install CD. Use the Windows Recovery Console option if you are using Windows XP.
  4. To change the boot order: Enter BIOS via appropriate startup key for your computer. When the BIOS setup page shows, set the CD or floppy drive to boot first.
  5. Sources of that software: Find out which company manufactures your HDD and see if they have a utility that will do a low-level format. This part is important because it deletes everything from your hard drive so that no one can get it back, including the virus. Some common HDD manufacturers' tools for doing this can be found here.
  6. Run the formatting utility provided by your HDD manufacturer.
  7. If you have errors booting the OS, reinstall your operating system of choice however you want to.
  8. And the most important thing is that you use trusted software to remove the virus or else you will be in more trouble (if that software is infected). Some software will show many virus 'hits' in order to sell the full version, so read reviews first.

Tips

  • If you feel uncomfortable completing any of the steps, take your computer in to a specialist.
  • A bootable floppy is NOT required, just a formatted floppy. Check to see if your floppy is formatted for Mac or PC on the label. If required, in MS Windows, go to My Computer, right click on your floppy drive, click "Format...",etc. Then run the downloaded hard-drive floppy image installer. A CD image will require burning software.

Warnings

  • Be sure to write protect the floppy after writing using the sliding tab, because any virus that is residing in the boot sector of your HDD may copy itself.
  • A Low-Level format will erase anything and everything on your HDD. It does this because it erases the whole disk, and not just the File Allocation Table (FAT) which is the directory for the hard drive. Its kind of like a telephone directory. When you delete things or do a format in Windows or DOS, known as a High-Level format, it tells the FAT that there is nothing there anymore, but leaves the data on the disk. A Low-Level format or delete tells the FAT that there is nothing there and then rewrites the sectors on the HDD where the file was. Because of this there is no possible way to get your data back after this process is complete. Back up before performing a low level format!

Related Articles