Tuesday, April 22, 2008

Infected with virus?

Infected by virus on your PC could make you feel fizzy, it's so hard to handle sometimes.

Recently my customer's computers were infected with virus.

There are so many kinds of virus around. Some could crash your software, eg. OS like Windows, DOS, while some could damage your hardware, eg. hard disk being unable to boot up or be detected, motherboard breaking down.

The cases, so far, I handle and rectify successfully were to recover the motherboard to function properly, and to solve Windows that won't boot properly.

For the former case, the symptom of motherboard appeared were it couldn't boot up, but with LED light on inside it while plugging with main supply. In fact, it was infected with virus at its BIOS chip, the firmware was modified. My solution to it was to take off the CMOS battery for some mins, and replaced it back, turn the power on and it booted successfully.

Another case was Windows XP being infected with W32.Sasser.Worm. The symptom was it displayed "lsass.exe system error, an invalid parameter was passed to a service or function". I tried to use anti virus to scan and repair under DOS, yet the infected files were skipped to be scanned. I would like to give a try on re-installation of Windows XP, however it will take much time to do it without having exact result you predict. As a result, I try to boot the computer up with Windows XP installation CD, and repaired it under Recovery Console. (Of course you need to know Administrator's password to proceed.) What I did was I copied all the files under c:\windows\repair to c:\windows\system32\config and replaced all of them. Restarted the PC, it could boot successfully, however, the PC was still infected with virus. The next thing needs to be followed up was, downloading the latest version of anti virus and to scan the whole system throughly.

Well, I am learning how to recover the data from a problem hard disk effectively, that's to reduce data loss.

BTW, today is my birthday! For both Chinese & Western Calendar. :)

No comments: