How can I delete the boot virus?

Status
Not open for further replies.

ciao

Level 1
Thread author
Nov 22, 2022
46
Hello, how can I permanently delete the boot virus? can you help?
 

icotonev

Super Moderator
Verified
Staff Member
Mar 9, 2017
538
Hello..! Welcome to MalwareTips..! :)

Please follow the following instruction ..:

Download Farbar Recovery Scan Tool and save it to your desktop. --> IMPORTANT

If your antivirus software detects the tool as malicious, it’s safe to allow FRST to run. It is a false-positive detection.
If English is not your primary language, right click on FRST.exe/FRST64.exe and rename to FRSTEnglish.exe/FRST64English.exe

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click the FRST icon to run the tool. When the tool opens click Yes to disclaimer.
  • Press Scan button and wait for a while.
  • The scanner will produced two logs on your Desktop: FRST.txt and Addition.txt.
  • Please attach the content of these two logs in your next reply.
---------------------------------------------------

In your next reply, please include:
  • FRST.txt
  • Addition.txt
 
  • Like
Reactions: Trident

ciao

Level 1
Thread author
Nov 22, 2022
46
Hello..! Welcome to MalwareTips..! :)

Please follow the following instruction ..:

Download Farbar Recovery Scan Tool and save it to your desktop. --> IMPORTANT

If your antivirus software detects the tool as malicious, it’s safe to allow FRST to run. It is a false-positive detection.
If English is not your primary language, right click on FRST.exe/FRST64.exe and rename to FRSTEnglish.exe/FRST64English.exe

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click the FRST icon to run the tool. When the tool opens click Yes to disclaimer.
  • Press Scan button and wait for a while.
  • The scanner will produced two logs on your Desktop: FRST.txt and Addition.txt.
  • Please attach the content of these two logs in your next reply.
---------------------------------------------------

In your next reply, please include:
  • FRST.txt
  • Addition.txt
Hello, I'm talking about the boot partition, I know that farbar only gives the partition on the computer. What exactly will this do for you? @icotonev
 

icotonev

Super Moderator
Verified
Staff Member
Mar 9, 2017
538
Removing a boot sector virus can be difficult because it may encrypt the boot sector. If the virus cannot be removed due to encryption or excessive damage to existing code, the hard drive may need reformatting to eliminate the infection. But before that, we can try to remove it as long as you send me the necessary analysis logs.
 

ciao

Level 1
Thread author
Nov 22, 2022
46
Removing a boot sector virus can be difficult because it may encrypt the boot sector. If the virus cannot be removed due to encryption or excessive damage to existing code, the hard drive may need reformatting to eliminate the infection. But before that, we can try to remove it as long as you send me the necessary analysis logs.
Hı, thanks for your answers
Right now I'm not so sure there is a boot virus, I just suspect, if we format the disk, can this virus infect my wifi and infect other devices from there and go back to the computer when I format the disk again, or can it go to the BIOS before the disk is formatted and prevent the deletion?
 

icotonev

Super Moderator
Verified
Staff Member
Mar 9, 2017
538
boot viruses are now known as 'bootkits'. They write their code in the MBR as a bootloader at the beginning of the boot process and then disguise the actions of malware running under Windows.But I'm not sure with you if that's what it's about ..! Please do the following:

 

ciao

Level 1
Thread author
Nov 22, 2022
46
boot viruses are now known as 'bootkits'. They write their code in the MBR as a bootloader at the beginning of the boot process and then disguise the actions of malware running under Windows.But I'm not sure with you if that's what it's about ..! Please do the following:

Hı, thanks for your answers
So they can't do something like this? Is it impossible for them to do such a thing? also does the same apply to the gpt mode of boot? And if you hide it, can antiviruses find this malware?
Note: I used tdskiller but nothing came out as far as I remember @icotonev
 

ciao

Level 1
Thread author
Nov 22, 2022
46
Of course I will try..! :) Does your OS boot in normal mode..?
if yes, what's the problem with sending me logs with FRST...I want to review them to get an idea of what we're dealing with..!
Thanks, obviously I don't want to send the FRST records as they contain my information (filename etc.). but if that will help me to be absolutely sure that my boot is free of viruses, I can throw it away. Normal mode as far as I know, not quite sure @icotonev
 

icotonev

Super Moderator
Verified
Staff Member
Mar 9, 2017
538
Thanks, obviously I don't want to send the FRST records as they contain my information (filename etc.)

How can I help you in that case?

 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top