Formatering af computer........

hej jeg har et lille problem, jeg ved ikke hvordan jeg formatere min computer når jeg har win me... :(
Jeg kan ikke komme ud i kommandoprompten så jeg kan ikke skrive Format c:...... Det skal lige siges at jeg har en Virus (W32.Sircam.Worm@mm) som nok er i min bios og jeg ved heller ikke hvordan jeg fjerner den derfra :( så hvis der er nogen der kan hjælpe må i meget gerne skrive.......
02. august 2001 - 22:38 #1
Kender ikke lige den virus, men hvis du laver en bootdisk under kontrolpanel > tilføj / fjern programmer > startdiskette, så kan du boote på den og derved komme frem til en promt hvorfra du kan formatere lige det du ønsker!

02. august 2001 - 22:40 #2
Det er Røde Orm du har fået, og den går ikke i BIOS
Læs mere her:

02. august 2001 - 22:41 #3
02. august 2001 - 22:41 #4
er enig med beach. Hvis du har virus ville jeg nok forsøge at installere en form for antivirus (hvis der er muligt) før du formaterer. Els får du nok ikk så meget ud af din formatering (hvis du er uheldig).
02. august 2001 - 22:41 #5
jamen hvorfor kommer der så fejle hver gang jeg starter win op????
02. august 2001 - 22:43 #6
Du kan læse den NIPC´s advarsel her:
NIPC er en underafdeling af FBI der tager sig af bla. hackerangreb mm.
02. august 2001 - 22:46 #7
Jeg har fjernet alt virus der er i de mapper jeg har på min computer men der bliver ved med at komme fejl og jeg kan ikke forstå det
02. august 2001 - 22:49 #8
Jeg har brugt McAfee
02. august 2001 - 22:50 #9
Download en viruschecker fra nettet og kør den. De skulle alle være opdateret med bla.
Mere info fra Symantec her:

Detected as:


Area of Infection:
.EXE Files

No additional information.

This threat is detected by the latest Virus Definitions.

All computer users should employ safe computing practices, including:

Keeping your Virus Definitions updated.
Installing Norton AntiVirus program updates, when available.
Deleting suspicious looking emails.
You may also scan your PC for threats now, by using the free online Symantec Security Check.

To ensure complete protection against viruses and similar threats, please review Symantec\'s product offerings for Home and Corporate users.

02. august 2001 - 22:52 #10
Ups, her er den rigtige virus som du har fået:
Der står også en masse om hvordan du fjerner den!!!


W32.Sircam.Worm@mm Removal Tool
Last Updated on: August 1, 2001 at 08:35:22 AM PDT

Printer-friendly version

The W32.Sircam.Worm@mm Fix tool deletes the files infected with the W32.Sircam.Worm@mm worm and removes the changes that were made to a computer by this virus.

To obtain and run the tool:

1. Go to http://www.sarc.com/avcenter/FixSirc.com
2. Download the Fixsirc.com file to a convenient location, such as your download folder or the Windows desktop. If you are on a network, the removal tool should be applied on all computers, including the server.
3. To check the authenticity of the digital signature, refer the section The digital signature.
4. Close all programs before running the tool, including any antivirus scanners such as NAV Auto-Protect.

CAUTION: Do not skip this step. You must disable Auto-Protect before you run the tool. For instructions, see the document How to enable and disable Norton AntiVirus Auto-Protect.

5. If you are on a network, or have a full time connection to the Internet, disconnect the computer from the network and the Internet. Disable or password protect file sharing before reconnecting computers to the network or to the internet. Because this worm spreads by using shared folders on networked computers, to ensure that the worm does not reinfect the computer after it has been removed, Symantec suggests sharing with read-only access or using password protection. For instructions on how to do this, see your Windows documentation or the document How to configure shared Windows folders for maximum network protection.

CAUTION: Do not skip this step. You must disconnect from the network befor running the tool.

6. If you are using Windows Me, then disable System Restore. Please refer the section System Restore option in Windows Me for additional details.

NOTE: If you are running Windows Me, we strongly recommend that you do not skip this step.

7. Double-click the Fixsirc.com file to start the removal tool.

NOTE: If you downloaded the tool to a floppy disk, and want to run it from the floppy, see the section How to run the tool from a floppy disk at the end of this document for special instructions.

NOTE: If you are using Windows Me, and the System Restore remains enabled, you will see a warning message. You can choose to run the removal tool with the System Restore option enabled or exit the removal tool.

8. Click Start to begin the process, and then allow the tool to run.
9. If you are using Windows Me, then reenable System Restore.
10. Reenable Auto-Protect

If you see a message that the tool must re run in Safe mode, restart the computer in Safe mode and run the tool again. Please follow this instruction to ensure that the virus does not reinfect the computer. To restart in Safe mode, see the document How to restart Windows 9x or Windows Me in Safe Mode
The removal procedure might be unsuccessful in case of enabled System Restore under Windows\'ME because Windows prevents System Restore from being modified by outside programs. Because of this, any worm removal attempts made by the removal tool might fail.
When the procedure is finished, the removal tool may detect that you are using Windows\'ME and the System Restore remains disabled. In this case, you will see the reminder message to reenable this option.
If you need to run the tool in login scripts or batch files with no messages displayed, then use the following command line syntax for the \"Silent\" mode:
Fixsirc.com /s

When the tool has finished running, you will see a message indicating whether the computer was infected by the W32.Sircam.Worm@mm worm. In the case of a removal of the worm, the program displays the following results:
The total number of the scanned files.
The number of deleted files.
The number of registry keys that were fixed.

What the tool does
The W32.Sircam.Worm@mm removal tool does the following:
1. It scans and deletes files infected with the W32.Sircam.Worm@mm worm.

2. The tool removes the following registry key:


3. In the registry key


it deletes the following value:


4. In the registry key


the tool modifies the [Default] value by setting it to:

\"%1\" %*

5. The tool removes the line \"@win \\recycled\\sirc32.exe\" from the C:\\Autoexec.bat file.
6. The tool restores Rundll32.exe file, renamed by the worm.

The digital signature
FixSirc.com is digitally signed. Symantec recommends that you only use copies of FixSirc.com that have been downloaded directly from the SARC download site. To check the authenticity of the digital signature, follow these steps:
1. Go to http://www.wmsoftware.com/pub/chktrust.exe.
2. Save the Chktrust.exe file to the same folder where you saved FixSirc.com, for example, C:\\Downloads
3. Click Start, point to Programs, and click MS-DOS Prompt.
4. Change to the folder where FixSirc.com and Chktrust.exe are stored, and then type:

chktrust -i FixSirc.com

For example, if you saved the file to the C:\\Downloads folder:

cd downloads
chktrust -i FixSirc.com

Press Enter after typing each command.

5. If the digital signature is valid, you will see the following:

Do you want to install and run \"FixSirc.com\" signed on 7/31/2001 9:36 AM and distributed by Symantec Corporation.

The date and time that are displayed in this dialog will be adjusted to your time zone if your computer is not set to the Pacific time zone.
If you are using Daylight Saving time, the time that is displayed will be exactly one hour earlier.
If this dialog does not appear, do not use your copy of fixsirc.com. It is not from Symantec.

6. Click Yes to close the dialog box.
7. Type exit and then press Enter. This will close the MS-DOS session.

System Restore option in Windows Me:
One of the new features of Windows Me is System Restore. This feature, which is enabled by default, is used by Windows to restore files on your computer in case they become damaged. Windows Me keeps the restore information in the _RESTORE folder. A _RESTORE folder is created on each hard drive on the computer; these folders are updated when the computer restarts.

If the computer is infected with W32.Sircam.Worm@mm, then it is possible that the worm could be backed up in the _RESTORE folder. By default, Windows prevents System Restore from being modified by outside programs. Because of this, any repair attempts made by the removal tool will fail. To work around this, you must disable System Restore, and restart the computer. This will purge the contents of the _RESTORE folder. You must then run the removal tool again.
02. august 2001 - 23:08 #11
tak men nu har jeg et problem hvordan slår jeg det der _RESTORE fra?
02. august 2001 - 23:13 #12
Kører du dk eller uk version af Win me?

02. august 2001 - 23:16 #13
02. august 2001 - 23:22 #14
Umidelbart så skal du bare gå ind og lave en sikker genstart (F8 når den booter) lade den komme op og køre, checke at systemet kørere i kontrol > system > enheder.
Hvis det gør det så lukker du ned og booter igen, så skulle det være væk!

02. august 2001 - 23:25 #15
Altså det vil sige at jeg skal lave en fejlsikker genstart eller hvad det nu hedder..... Men hvordan slår jeg det _RESTORE fra?
02. august 2001 - 23:26 #16
Det skulle gå væk automatisk når du efter en sikker genstart booter på ny!
Er ikke helt sikker, men prøv:-)

02. august 2001 - 23:30 #17
jamen hvad mener du med at den booter
02. august 2001 - 23:31 #18
hvad skal jeg gøre for at den booter
02. august 2001 - 23:36 #19
Booter = genstarter på dansk:-)
Sorry, men sidder og roder lidt rundt i DK og UK Ver. af Me*S*

02. august 2001 - 23:39 #20
hedder det ikke reboot
02. august 2001 - 23:40 #21
jeg kan ikke helt få det til at virke... :( så jeg spørger lige alle de andre...... så er det okay hvis du kun får 200 ? 
02. august 2001 - 23:45 #22
Jo, det gør det måske nok. Men når snakken går mellem freaks så bliver det aldrig til mere end boot. Så kan man lave en varm-boot som f.eks. Ctrl+Alt+Del eller en kold-boot som er en total sluk for computeren så alle HD (Harddiske) ram(hukommelse), MB (Motherbord) mm. får fjernet power (strøm) altså det samme som når maskinen er HELT slukket og derefter bliver tænt igen.

Nu har jeg prøvet at oversætte det, men det er lidt svært en gang i mellem at slå over i dansk da det meste af en computer jo sker på engelsk inkl. en boot på en bootdisc til en dos-promt hvor alle commands (komandoer) jo også sker på engalsk.

02. august 2001 - 23:53 #23
Nu kom du jo til at give mig alle point.
Du kan tage de 29 tilbage her:
Og kan da kun sige tak, og til en anden gang så havde du fået de samme svar hvis du havde banket 60 eller... point af. Så længe det ikke handler om rigtige kugler så tror jeg ikke det er nødvendigt at bruge SÅ mange point. Vi er her jo alle for at få og give hjælp får hjælpen og glædens skyld:-)

Men siger jo ikke nej til 200 point da jeg kan bruge den i en lille intern kamp mellem jeg selv og en anden bruger om hvem der kan hive flest point ind inden 1/1-2002!

