PPRuNe Forums - View Single Post - irritating virus
View Single Post
Old 25th Oct 2011, 20:11
  #29 (permalink)  
IO540
 
Join Date: Jun 2003
Location: EuroGA.org
Posts: 13,787
Likes: 0
Received 0 Likes on 0 Posts
It is not so much "DOS" you need to run.

The key point is that you need to boot the machine from an O/S which is not loaded by the boot sector of the hard drive of the potentially infected machine.

What that O/S is is irrelevant. It could be a normal copy of winXP, Unix, whatever. For example the Micro$oft boot-CD virus scanner (which I have used successfully to detect really clever infections) actually loads a copy of win7. This is no suprise, since you want that O/S to support peripherals like network controllers, USB, etc, and you want it to be able to get onto the internet and download the latest virus definitions. Plain DOS would be no good; apart from anything else DOS 6.2 only supported hard drives up to 2GB

Once the stuff has booted off the CD, everything on the HD is treated as passive data and can be freely scanned. Since nothing on the HD is executed (as program code) there is no way for anything on the HD to interfere with this virus scan.

You can achieve a similar result without a boot CD. For example if you suspect your drive C: has a virus, you can take the HD out of that machine and pop it into another machine as a secondary HD and virus scan it. Or, more cleverly, you can make a Trueimage (or some ISO) image of the whole drive, copy it to another machine (one guaranteed to be virus free) where you use TI to mount it as a logical drive, and virus scan that logical drive.

FWIW, I have seen many infected machines but nothing that I have sole access to has ever got infected. That's why I think people catch the nasties in particular ways.
IO540 is offline