Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Rootkits
#31
Hi Britec
Hans my husband says , he don't know if the PC will support USB booting for the Norton Bootable Recovery Tool to run on a USB device , she is from the time you had to boot with disket.
I don't have diskets anymoore , I can burn a DVD , but don't know if it will do.
Reply

#32
If you have a pen drive, XP can boot to that drive as long as you change boot order to boot to pen drive first

How to Change the Boot Sequence in the BIOS
<left><form action="https://www.paypal.com/cgi-bin/webscr" method="post">If you are satisfied with my help, consider a donation. Thank you so much for your continued support! 
<input type="hidden" name="cmd" value="_s-xclick">
<input type="hidden" name="hosted_button_id" value="Y4ZDLXGFS4F8Q">
<input type="image" src="https://www.paypalobjects.com/en_US/GB/i/btn/btn_donateCC_LG.gif" border="0" name="submit" alt="PayPal — The safer, easier way to pay online.">
<img alt="" border="0" src="https://www.paypalobjects.com/en_GB/i/scr/pixel.gif" width="0" height="0">
</form>

   </div></left> 
Reply

#33
Here is how to create a DVD

Creating Norton Bootable Recovery Tool on a DVD
<left><form action="https://www.paypal.com/cgi-bin/webscr" method="post">If you are satisfied with my help, consider a donation. Thank you so much for your continued support! 
<input type="hidden" name="cmd" value="_s-xclick">
<input type="hidden" name="hosted_button_id" value="Y4ZDLXGFS4F8Q">
<input type="image" src="https://www.paypalobjects.com/en_US/GB/i/btn/btn_donateCC_LG.gif" border="0" name="submit" alt="PayPal — The safer, easier way to pay online.">
<img alt="" border="0" src="https://www.paypalobjects.com/en_GB/i/scr/pixel.gif" width="0" height="0">
</form>

   </div></left> 
Reply

#34
Hi Britec :
The PC does not allow the NPE.exe to get installed , and we think the PC can not boot from USB . (disket )
She is still working , we don't see on the surface funny things happening .
Is the thread too dangerous ? AVG marked as medium thread yellow and aswmbr marked as suspicious yellow .
THX
Reply

#35
Bea you can run aswMBR again and when complete, click the fix button, you will only need to click fixmbr button if MBR has been change.
<left><form action="https://www.paypal.com/cgi-bin/webscr" method="post">If you are satisfied with my help, consider a donation. Thank you so much for your continued support! 
<input type="hidden" name="cmd" value="_s-xclick">
<input type="hidden" name="hosted_button_id" value="Y4ZDLXGFS4F8Q">
<input type="image" src="https://www.paypalobjects.com/en_US/GB/i/btn/btn_donateCC_LG.gif" border="0" name="submit" alt="PayPal — The safer, easier way to pay online.">
<img alt="" border="0" src="https://www.paypalobjects.com/en_GB/i/scr/pixel.gif" width="0" height="0">
</form>

   </div></left> 
Reply

#36
Will he damage the PC ? So I need firs to do the boot thing ?

Is scanning now .
Reply

#37
It should remove what it finds. It detected suspicious files, which you are concerned about.
The only other option is to backup data and wipe the system clean and re-install windows and I know you said you don't want to do that.

There is always a risk when removing rootkits, because they can render the system unbootable.

I know you hesitant, but your going to have to make a decision.

1. Leave it on the system. (it could be a false positive , but if its not, its not good to leave it on there. you could send the sample to AVG)

2. Run aswMBR and fix the issue by cleaning. (some well know rootkit tools have not found nothing on that system)

3. Play it safe, backup and wipe the system clean and re-install windows for peace of mind.

Hope this helps.
<left><form action="https://www.paypal.com/cgi-bin/webscr" method="post">If you are satisfied with my help, consider a donation. Thank you so much for your continued support! 
<input type="hidden" name="cmd" value="_s-xclick">
<input type="hidden" name="hosted_button_id" value="Y4ZDLXGFS4F8Q">
<input type="image" src="https://www.paypalobjects.com/en_US/GB/i/btn/btn_donateCC_LG.gif" border="0" name="submit" alt="PayPal — The safer, easier way to pay online.">
<img alt="" border="0" src="https://www.paypalobjects.com/en_GB/i/scr/pixel.gif" width="0" height="0">
</form>

   </div></left> 
Reply

#38
OK , I'll do that , you are right , Play safe.
Back up is ready , I'm waiting for the scan to finish.
Thank you .

When clicking fixMBR
It says a new master boor record to your system partition could dammage your partition tables and cause your partition to become inaccesible .
This application writes standard Windows MBR code .
Are you sure you want to fix the MBR ?
Yes
And we'll see.
Reply

#39
There is a Fix button there and a FixMBR press the fix button
<left><form action="https://www.paypal.com/cgi-bin/webscr" method="post">If you are satisfied with my help, consider a donation. Thank you so much for your continued support! 
<input type="hidden" name="cmd" value="_s-xclick">
<input type="hidden" name="hosted_button_id" value="Y4ZDLXGFS4F8Q">
<input type="image" src="https://www.paypalobjects.com/en_US/GB/i/btn/btn_donateCC_LG.gif" border="0" name="submit" alt="PayPal — The safer, easier way to pay online.">
<img alt="" border="0" src="https://www.paypalobjects.com/en_GB/i/scr/pixel.gif" width="0" height="0">
</form>

   </div></left> 
Reply

#40
The only option was FixMBR , I did it , said , sucessfully fixed , scaned again , said mal function for all the yellow areas that were bad , they are stil there , but they were fixed acording to the program , I'm rebooting now , and she started . Is very slow for starting , and then she is ok .
What do you think ? Bingo ?

Hi Britec , the program said succesfully fixed , but everything is still there , I' ll contact tomorrow AVG and send them the txt as you said.
We have to do a job bevoor january , then I'll have moore time to format as you said .

How do we contact you if we have one moore case ?
Thank you .
Reply



Forum Jump:


Users browsing this thread:
2 Guest(s)

Powered By MyBB, © 2002-2024 Melroy van den Berg.