Announcement

Collapse
No announcement yet.

Bartpe to the rescue

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Bartpe to the rescue

    One of the most useful peices of software around this.

    After battling with Boran Spyware which nothing could remove. Despite claims to contrary I finally removed the drive and put it in another laptop. The host machines DVD was broken.

    Scanning the drive from another Winxp machine pronounced it clean whatever virus checker you used.

    Scanning in safe mode using any spyware removal tool didn't work as the spyware was loaded and just replaced the registry keys or the spyware program just hung.

    Booted Bartpe used the registry plugin to load up the registry and delete delete delete. Folder prevously hidden appeared delete delete delete.

    Put the hard drive back in reboot in safe mode and the virus checker found another virus which it removed and scanned through. Another reboot and still clean.

    Orginally the machine was harvesting IP address's. The first antispy run found 4000 items of spyware and 1000 Trojan. I thought I was winning when I got it down to 20 or so then came the hard work trying to find the files reloading the software.

    Hopefully it's just a final cleanup tomorrow.
    Chief Lemon Buyer no more Linux sucks but not as much
    Weather nut and sad git.

    My Weather Page

  • #2
    BartPE has revolutionized desktop support. I love it!
    “Inside every sane person there’s a madman struggling to get out”
    –The Light Fantastic, Terry Pratchett

    Comment


    • #3
      I wish companies would follow Acronis lead and offer you free plugins for it if you buy their software.
      Chief Lemon Buyer no more Linux sucks but not as much
      Weather nut and sad git.

      My Weather Page

      Comment


      • #4
        BartPE rocks. It rocks even more when you add all the SysInternals stuff to it. MU-AH!

        LOCKSMITH IS YOUR FRIEND!
        The Internet - where men are men, women are men, and teenage girls are FBI agents!

        I'm the least you could do
        If only life were as easy as you
        I'm the least you could do, oh yeah
        If only life were as easy as you
        I would still get screwed

        Comment


        • #5
          Bad eyesight mean't I missed a couple of registry edits. Damn hex numbers. Taking those out revealed another load of infected files.

          Now everything says it's clean but I'm far from convinced for the following reasons.


          Disk space drops by 300 to 400mb when you're in normal mode suggesting that something is reserving it. Maybe legit but since the machine is in Chinese I can't tell what he's got installed.

          The machine keeps trying to connect to network connections. One too an ip address off campus on port 8080 and it also tries to do netbios connections to machines at random and then stops. Netstat just shows Explorer and two normal windows .dlls nothing strange. WE checked the off campus IP address and that doesn't reveal anything.

          Anyway the machine is being monitored over the weekend to see if does anything else naughty.
          Chief Lemon Buyer no more Linux sucks but not as much
          Weather nut and sad git.

          My Weather Page

          Comment

          Working...
          X