I am creating a drive here at work to do this very thing, thanks. Looks like it killed everything though according to this:
http://www.symantec.com.au/avcenter/venc/data/pf/w32.opaserv.k.worm.html "a. First, the worm creates the following files: C:\Msdos.sys (19 bytes): This file contains an option not to display the Windows logo image at startup. C:\Autoexec.bat (15 bytes): This file contains an instruction to run Mslicenf.com. C:\Mslicenf.com (1,706 bytes): When this file runs, it overwrites the MBR of all the physical drives with itself. The code contained in Mslicenf.com destroys all the data on all the physical drives and displays a message. C:\Boot.ini (88 bytes): If the operating system is Windows NT/2000/XP, this file causes the operating system to load and run C:\Bootsect.dos. C:\Bootsect.dos (512 bytes). If the operating system is Windows NT/2000/XP, this file will be loaded and run. The code contained in Bootsect.dos will destroy all the data on all the physical drives." That doesn't lift my hopes, but I'll still try. Dave Lum - [EMAIL PROTECTED] Sr. Network Specialist - Textron Financial 503-675-5510 -----Original Message----- From: Ed Esgro [mailto:[EMAIL PROTECTED] Sent: Wednesday, February 26, 2003 07:35 AM To: NT 2000 Discussions Subject: RE: [OT] Data recovery How about installing a second boot drive and try accessing infected drive as a slave? Or at least maybe you can run some utilities against it. I recall an old program called lost and found. Ed -----Original Message----- From: Lum, David [mailto:[EMAIL PROTECTED] Sent: Wednesday, February 26, 2003 10:11 AM To: NT 2000 Discussions Subject: [OT] Data recovery Guys, I managed to nuke myself with an infected (OPASERV) bootable floppy in spite of A-V protection (long story). This virus has modified my partition information and possibly overwrote the first 8GB. System does not boot but I can get to BIOS. http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV .R Has anyone used a recovery utility that won't create additional damage if it doesn't work? Recommend a data recovery service perhaps? Dave Lum - [EMAIL PROTECTED] Sr. Network Specialist - Textron Financial 503-675-5510 ------ You are subscribed as [EMAIL PROTECTED] Archives: http://www.swynk.com/sitesearch/search.asp To unsubscribe send a blank email to %%email.unsub%% *****This email and any files transmitted with it are confidential and intended solely for the use of the addressee. If you have received this email in error please notify [EMAIL PROTECTED] Any views or opinions presented in this email are solely those of the author and do not necessarily represent those of Stainsafe Inc. or any of its subsidiaries or affiliates. The company accepts no liability for any damage caused by any virus transmitted by this email.***** ------ You are subscribed as [EMAIL PROTECTED] Archives: http://www.swynk.com/sitesearch/search.asp To unsubscribe send a blank email to %%email.unsub%% ------ You are subscribed as [EMAIL PROTECTED] Archives: http://www.swynk.com/sitesearch/search.asp To unsubscribe send a blank email to [EMAIL PROTECTED]
