Перейти к содержимому


Фото
- - - - -

Livecd


  • Please log in to reply
5 ответов в этой теме

#1 ricd

ricd

    Newbie

  • Posters
  • 5 Сообщений:

Отправлено 30 Ноябрь 2009 - 20:46

Sorry to post in English.

downloaded LiveCD 2 hrs ago and burned iso image.
my laptop starts to boot but if I select graphical mode (default) it hangs on Preparing the LiveCD environment....
If I select safe-mode -
1st try hangs at Load module : pata_qdi
tried 3 more times in Safe and those all stopped at Load module : raid456

laptop is IBM T42
Pentium Centrino 1.7GHz
1024 mem

my virus was 1st picked up by McAfee as sandboxie
it appears it is the Backdoor.TDSS
tried cleaning w/ malwarebytes and thought I had it cured but after reboot and a clean scan I re-ran the scan and had 800+ infected items

If there is an English only Forum please point me there.

Thank you in advance for any assistance!

#2 PAUK

PAUK

    Guru

  • Posters
  • 3 236 Сообщений:

Отправлено 30 Ноябрь 2009 - 21:16

my virus was 1st picked up by McAfee as sandboxie
it appears it is the Backdoor.TDSS
tried cleaning w/ malwarebytes and thought I had it cured but after reboot and a clean scan I re-ran the scan and had 800+ infected items


Try this: Dr.Web CureIt!
"объективность" – понятие глубоко субъективное
- Мы здесь все сумасшедшие. Я сумасшедший. Ты сумасшедшая.
- Откуда вы знаете, что я сумасшедшая? - спросила Алиса.
- Ты безусловно должна быть сумасшедшей, - ответил Кот, - иначе ты не попала-бы сюда.

#3 ricd

ricd

    Newbie

  • Posters
  • 5 Сообщений:

Отправлено 30 Ноябрь 2009 - 22:01

I forgot to mention that I can no longer boot into WinXP
Both safe-mode and normal, as well as last known good config, blue screen on me which is what led me to try LiveCD

#4 Borka

Borka

    Забанен за флуд

  • Members
  • 19 512 Сообщений:

Отправлено 30 Ноябрь 2009 - 22:07

had 800+ infected items

What items? Where was they found? What are their names?

I forgot to mention that I can no longer boot into WinXP
Both safe-mode and normal, as well as last known good config, blue screen on me which is what led me to try LiveCD

What BSOD code did you get? Have you minidump?
С уважением,
Борис А. Чертенко aka Borka.

#5 PAUK

PAUK

    Guru

  • Posters
  • 3 236 Сообщений:

Отправлено 30 Ноябрь 2009 - 22:13

I forgot to mention that I can no longer boot into WinXP


Oops :)
probably system destroyed by the actions of other anti-virus software!
Try other LiveCD, not based on Linux... and try use Dr.Web CureIt!®...
"объективность" – понятие глубоко субъективное
- Мы здесь все сумасшедшие. Я сумасшедший. Ты сумасшедшая.
- Откуда вы знаете, что я сумасшедшая? - спросила Алиса.
- Ты безусловно должна быть сумасшедшей, - ответил Кот, - иначе ты не попала-бы сюда.

#6 ricd

ricd

    Newbie

  • Posters
  • 5 Сообщений:

Отправлено 03 Декабрь 2009 - 05:11

had 800+ infected items

What items? Where was they found? What are their names?

I unfortunately did not copy off the log to a thumb drive before rebooting. I reviewed the log quicky and know atapi.sys was in the list.

I forgot to mention that I can no longer boot into WinXP
Both safe-mode and normal, as well as last known good config, blue screen on me which is what led me to try LiveCD

What BSOD code did you get? Have you minidump?




I cannot get the BSOD codes as they only stay on the screen for 1-2 seconds and then system reboots.
How I found DRWeb was from this post so I am guessing these are the codes I have. Symptoms are the same.

AntiVirus ProОтправленное изображение and others nasties are now dropping the Backdoor.TDSS into "atapi.sys".

After a partial cleaning, you'll get an endless reboot of Stop 0X0A in normal mode and 0X7E in safe mode...

Pull down a Dr.Web live CD, burn it, boot it, and clean up your machine.
http://www.freedrweb.com/livecd/

I did have AVP popping up as well as System Defender

My issue now is that I cannot get LiveCD to boot. I am looking for XP Pro cd also.