I am creating a drive here at work to do this very thing, thanks. Looks like
it killed everything though according to this:

http://www.symantec.com.au/avcenter/venc/data/pf/w32.opaserv.k.worm.html

"a. First, the worm creates the following files:
C:\Msdos.sys (19 bytes): This file contains an option not to display the
Windows logo image at startup. 
C:\Autoexec.bat (15 bytes): This file contains an instruction to run
Mslicenf.com.
C:\Mslicenf.com (1,706 bytes): When this file runs, it overwrites the MBR of
all the physical drives with itself. The code contained in Mslicenf.com
destroys all the data on all the physical drives and displays a message.
C:\Boot.ini (88 bytes): If the operating system is Windows NT/2000/XP, this
file causes the operating system to load and run C:\Bootsect.dos.
C:\Bootsect.dos (512 bytes).
If the operating system is Windows NT/2000/XP, this file will be loaded and
run. The code contained in Bootsect.dos will destroy all the data on all the
physical drives."

That doesn't lift my hopes, but I'll still try.

Dave Lum - [EMAIL PROTECTED]
Sr. Network Specialist - Textron Financial
503-675-5510

-----Original Message-----
From: Ed Esgro [mailto:[EMAIL PROTECTED]
Sent: Wednesday, February 26, 2003 07:35 AM
To: NT 2000 Discussions
Subject: RE: [OT] Data recovery


How about installing a second boot drive and try accessing infected drive as
a slave? Or at least maybe you can run some utilities against it. I recall
an old program called lost and found.

Ed

-----Original Message-----
From: Lum, David [mailto:[EMAIL PROTECTED] 
Sent: Wednesday, February 26, 2003 10:11 AM
To: NT 2000 Discussions
Subject: [OT] Data recovery


Guys, 

I managed to nuke myself with an infected (OPASERV) bootable floppy in spite
of A-V protection (long story). This virus has modified my partition
information and possibly overwrote the first 8GB. System does not boot but I
can get to BIOS.

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV
.R

Has anyone used a recovery utility that won't create additional damage if it
doesn't work? Recommend a data recovery service perhaps?

Dave Lum - [EMAIL PROTECTED]
Sr. Network Specialist - Textron Financial
503-675-5510

------
You are subscribed as [EMAIL PROTECTED]
Archives: http://www.swynk.com/sitesearch/search.asp
To unsubscribe send a blank email to %%email.unsub%%





*****This email and any files transmitted with it are confidential and
intended solely for the use of the addressee. If you have received this
email in error please notify [EMAIL PROTECTED] Any views or opinions
presented in this email are solely those of the author and do not
necessarily represent those of Stainsafe Inc. or any of its subsidiaries or
affiliates. The company accepts no liability for any damage caused by any
virus transmitted by this email.*****

------
You are subscribed as [EMAIL PROTECTED]
Archives: http://www.swynk.com/sitesearch/search.asp
To unsubscribe send a blank email to %%email.unsub%%

------
You are subscribed as [EMAIL PROTECTED]
Archives: http://www.swynk.com/sitesearch/search.asp
To unsubscribe send a blank email to [EMAIL PROTECTED]

Reply via email to