Techware Labs Header

Forums have moved

See this announcement for more details, or just go directly there.

  #1  
Old 06-29-2006, 04:46 PM
psham psham is offline
Junior Techie
 
Join Date: Jun 2006
Posts: 5
Default Ntldr+viruses

Got an error on my xp coumputer "ntldr error", is it possible that a virus called Worm_mytob.j caused this or was it just the hard drive was corrupt.
Reply With Quote
  #2  
Old 06-29-2006, 05:09 PM
vee_ess's Avatar
vee_ess vee_ess is offline
Super Moderator
 
Join Date: Aug 2001
Location: Phoenix, Arizona
Posts: 2,781
Send a message via ICQ to vee_ess Send a message via AIM to vee_ess Send a message via MSN to vee_ess Send a message via Yahoo to vee_ess
Default

Using Google, I found a description by Symantec. According to that, it just self-propogates and blocks access to specific secure sites, that type of worm will not likely affect NTLDR.
Reply With Quote
  #3  
Old 06-29-2006, 05:29 PM
psham psham is offline
Junior Techie
 
Join Date: Jun 2006
Posts: 5
Default Ntldr+viruses

I am having a disagreement with my tech support company, they found the mytob.j virus on my hard drive when they came to fix my computer, they say that it was this virus caused the ntldr error and have to charge call out as a result. My hard drive crashed a couple of months ago with missing boot.ini files but no virus was present at that stage... Is there any way to find out for sure was it or not the virus or just a hard ware problem
Reply With Quote
  #4  
Old 06-29-2006, 05:59 PM
vee_ess's Avatar
vee_ess vee_ess is offline
Super Moderator
 
Join Date: Aug 2001
Location: Phoenix, Arizona
Posts: 2,781
Send a message via ICQ to vee_ess Send a message via AIM to vee_ess Send a message via MSN to vee_ess Send a message via Yahoo to vee_ess
Default

I'm not sure, but I believe the burden is on your tech support to prove that. Besides, mytob.j doesn't touch the boot sector. At the same time, NTLDR really is not often a hardware failure, it's more often a Windows failure.
Reply With Quote
  #5  
Old 06-29-2006, 06:04 PM
psham psham is offline
Junior Techie
 
Join Date: Jun 2006
Posts: 5
Default

Thanks for your input, it looks like its going to be hand bags at dawn tomorrow, we'll see what happens
Reply With Quote
  #6  
Old 06-29-2006, 06:13 PM
vee_ess's Avatar
vee_ess vee_ess is offline
Super Moderator
 
Join Date: Aug 2001
Location: Phoenix, Arizona
Posts: 2,781
Send a message via ICQ to vee_ess Send a message via AIM to vee_ess Send a message via MSN to vee_ess Send a message via Yahoo to vee_ess
Default

Hopefully we'll figure out a solid way for you to ensure that they can't take advantage of the situation.
Reply With Quote
  #7  
Old 06-30-2006, 05:03 AM
psham psham is offline
Junior Techie
 
Join Date: Jun 2006
Posts: 5
Default anybody have any ideas

still looking for anyone who can help me
Reply With Quote
  #8  
Old 06-30-2006, 01:24 PM
vee_ess's Avatar
vee_ess vee_ess is offline
Super Moderator
 
Join Date: Aug 2001
Location: Phoenix, Arizona
Posts: 2,781
Send a message via ICQ to vee_ess Send a message via AIM to vee_ess Send a message via MSN to vee_ess Send a message via Yahoo to vee_ess
Default

You can prove that the virus is functioning as it's author intended by checking that the following files are in place:

%System%\taskgmr.exe
%SystemDrive%\funny_pic.scr
%SystemDrive%\my_photo2005.scr
%SystemDrive%\see_this!!.scr

%System% and %SystemDrive% are variables that will coincide C:\Windows\System32 and C:\, unless you or the installer set them differently.

If you can verify those are in place, you can argue that the worm is functioning as the author intended. This would prove that the virus has had no impact on the boot sector or the NT Loading files.
Reply With Quote
  #9  
Old 07-04-2006, 04:23 AM
psham psham is offline
Junior Techie
 
Join Date: Jun 2006
Posts: 5
Default

right ill have a look at that, cheers
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 03:46 PM. Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Forum style by ForumMonkeys.