HardDrive converted to Non-DOS format by Virus

Discussion in 'Software' started by TreasureDiver7, Dec 10, 2008.

  1. TreasureDiver7

    TreasureDiver7 Private E-2

    Recently, my old Gateway was infected by a virus (possible Trojan, Super Stealth) which changed my FAT table to a Non-DOS format, and deleted or changed my Operating System (OS) so as to make my system non bootable.

    I am on NetZero Platinum dial-up, with the Norton AV paid software, and I never even recieved a warning that the infection was taking place. This was on a WIN98SE OS, and the error message was:

    This PC is a Gateway- with a Pentium III-450MHz At initial start-up, the Gateway logo comes up, and at the bottom of the screen is two options:

    To change system settings, press the <F1> key
    To display system messages, press the <Tab>key

    The "Password" to access the system comes up as well. Upon starting up the computer, putting in the system administrator password, and striking "enter", the first message on the screen is:

    Load Error...!

    Press a key to reboot...

    After pressing a key, this message displays next:

    Operating System not found

    Repeated attempts at pressing a key to reboot repeat the same message, ad
    infinitum. Operating System not found. It repeats.........

    ***********
    After a shut-down using "control-alt-delete", then with a restart, and :
    Attempting to check system messages by holding down the "<TAB>" key after giving the system password-which is accepted, brings up this information:

    Phoenix ix BIOS 4.0 Release 6.0
    Copyright 1985-1999 Phoenix Technologies Ltd.
    Copyright 1996-1999 Intell Corp.
    4W4SB0X0.15A.0015.P10Gateway LogoIntel (R) Pentium (R) III
    Processor 450MHz
    192 MB System RAMLegacy Keyboard-Detected
    Legacy Mouse-DetectedATAPI CD-ROM: SONY CD-RW CRX 140E-(PM)
    Fixed Disk 0: WDC WD102AA-(SM)

    ********************************
    Pressing <F1> to enter SETUPBIOS Setup Utility in the "Boot" heading shows this information:
    First Boot Device CD-ROM
    Second Boot Device Floppy Disk
    Third Boot Device Hard Drive

    *Note: I have used all three in attempts to boot up. I have tried to boot from a WIN98 CD using the CD ROM as the first Boot Device, as well as the Hard Disk, and not been
    successful. I have also put in the Spotmau CD and tried to boot the OS from it with no
    success.

    Although the Spotmau CD boots to display it's information, there is no Operating System
    from which to boot the computers harddisk, so I've tried to use my WIN98 Floppy Start
    Up disk to install the necessary tools to troubleshoot the system. The tools are installed,
    but without any OS in the sector for the Non-DOS sector, I'm getting nowhere!

    After installing the WIN98 Start Up disk I made from the WIN98 CD I have, this is what I get from the A:/ prompt:

    A:/FDisk
    FDISK Options
    Current fixed disk drive: 1
    Choose one of the following:
    1. Create DOS partition or Logical DOS Drive
    2. Set active partition
    3. Delete partition or Logical DOS Drive
    4. Display partition information

    *Note: I am reticent about creating a DOS partition, as I am worried about losing all of
    my programs, data, photos, etc. I can see that there is a partition for the hard disk
    already, although it is a NON DOS partition with 100% of my data on it.
    I do not wish to delete anything, so I chose to display partition information by selecting number 4. This is the information I get:

    Display Partition Information

    Current fixed disk drive: 1
    Partition Status Type Volume Label Mbytes System Usage
    1 Non-DOS 9766 100%
    C: 2 PRI DOS FAT12 16 %

    % Total Disk Spaces 9782 Mbytes
    ***********************************
    I have checked troubleshooting from most perspectives, but unless I can convert the Non-
    DOS back to DOS, nothing will function to solve this dilemma.
    I have run Chkdisk, Config.Sys etc. and am not knowledgeable enough to do a re-partition
    without some definitave advice, for fear of losing all my data.

    I have considerable amounts of saved files from my military service, jobs, etc, that I just won't risk losing without some very experienced technical advice on how to accomplish
    this at no risk to them being deleted or currupted in any attempt to change back to the necessary DOS OS.

    I hope that I have provided enough information for a solution to this problem to be forthcoming. Short of taking my Harddisk in to a computer repair shop, and trusting the expertise of one of their techs, I am in hopes of your providing a step-by-step process to recover my files and OS on this Harddisk.

    I do have a few other Hard Drives, and have the necessary cables to set this one up as a
    slave, but having tried this already, don't see how it can be effective in restoring my OS, and converting my HD back to a DOS format. HELP!!!
    I keep Spybot and Norton updated on a daily basis, or as updates are available.

    I hope someone can give me some definitave advice on a procedure, as my next option is to have my HD copied and data retrieved by a pro.

    Thanks,
    TreasureDiver7
     
    Last edited: Dec 10, 2008
  2. Corporal Punishment

    Corporal Punishment Administrator Staff Member

    Most likely partition 1 should be the active partition. However, generally non-dos partitions you see as Linux or other OS’s and. So I am wondering if it was reformatted on you already. I suspect that simply recreating the partition and setting it active would work as long as the MBR is still intact…..BUT………….

    FAT12 is old school as heck. Could be the recovery files from the manufacturer – but it could be the virus hiding.

    Honestly, without a backup and important files on there, you should take this to a reputable local shop with the correct tools to image the drive first. Then see what can be recovered.

    Note: This thread has been moved from the Malware Forum to the Software Forum.
     
    Last edited by a moderator: Dec 11, 2008
  3. TreasureDiver7

    TreasureDiver7 Private E-2

    Thanks Corporal,
    Actually WIN98SE uses FAT32, and my start up floppy says so, but the read out came back from fdisk as FAT12, so I suspect you are correct, and the virus is hiding there.

    I have found a tech locally who will image the HD for $100. and put my data on a second HD to find the problem, solve it, then reformat my original HD back.

    Thanks for your input, as it confirmed what I was told by several techs I called. Most wanted over $150 to do this, but I got lucky and found one who would do it for $100.!

    Kudos to you, from a former Marine Sergeant (Nam Vet).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds