Re: Which live CD for recovery

2006-12-06 Thread David Robillard

On 12/6/06, Erik Norgaard <[EMAIL PROTECTED]> wrote:

> Do you have a USB drive? Can you mount it on the crippled Windows Box?
> If so, then I would suggest that you backup the user's data, format
> the crippled box's disk drive and do a clean Windows install. After
> all, there probably was a virus on this box. Are you sure you want to
> take chances?

Well, the system won't boot, not even in safemode, so there is no such
alternative. I hope this is just some systemfile in the vault of AVG
anti virus.

Take the chance... well it can't get much worse. If at least the system
gets back working then I can try other ways to clean it.


If you can get the machine to mount the USB drive or have it's network
connection online, you can simply backup the contents of
"C:\Documents and Settings\All Users"
"C:\Documents and Settings\${username}" (replace ${username} with the
various usernames configured on the crippled box).

Once you backup the content of those two directories, you should have
all of your user's data. Therefore you should be ok to wipe the disk
and perform a clean Windows install.

I suggest, however, that you upload those backup onto another Windows
machine and have your user double-check to see if you have everything.
Better be safe than sorry.

Cheers,

David
--
David Robillard
UNIX systems administrator & Oracle DBA
CISSP, RHCE & Sun Certified Security Administrator
Montreal: +1 514 966 0122
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Which live CD for recovery

2006-12-06 Thread Erik Norgaard

David Robillard wrote:


So, I need to recover data to some other machine, and then see if I can
recover the system file without a full reinstall.


Do you have a USB drive? Can you mount it on the crippled Windows Box?
If so, then I would suggest that you backup the user's data, format
the crippled box's disk drive and do a clean Windows install. After
all, there probably was a virus on this box. Are you sure you want to
take chances?


Well, the system won't boot, not even in safemode, so there is no such 
alternative. I hope this is just some systemfile in the vault of AVG 
anti virus.


Take the chance... well it can't get much worse. If at least the system 
gets back working then I can try other ways to clean it.


Thanks, Erik

--
Ph: +34.666334818  web: http://www.locolomo.org


smime.p7s
Description: S/MIME Cryptographic Signature


Re: Which live CD for recovery

2006-12-06 Thread David Robillard

Which live CD is recommended for recovery? What I'd like is to have as
many disk analysis tools at hand just in case.


There are a lot to choose from, as you can see from this list:
http://www.frozentech.com/content/livecd.php


I believe one of two things has happened: the anti virus placed a system
file in the vault, or running windows update the "genuine windows
disadvantage tool" disabled the system because it may have been pirate
(don't know).


AFAIK the Windows Genuine Advantage never prevents you from booting
your machine. It will annoy you with pop-ups about your license (or
lack of it). Fortunately, you can disable the pop-ups. Keep in mind
that a non-legit Windows machine can only perform the Security
updates, but cannot perform the other Windows Updates. This can be
confusing for a technologically challenged user.


So, I need to recover data to some other machine, and then see if I can
recover the system file without a full reinstall.


Do you have a USB drive? Can you mount it on the crippled Windows Box?
If so, then I would suggest that you backup the user's data, format
the crippled box's disk drive and do a clean Windows install. After
all, there probably was a virus on this box. Are you sure you want to
take chances?

Good luck,

David
--
David Robillard
UNIX systems administrator & Oracle DBA
CISSP, RHCE & Sun Certified Security Administrator
Montreal: +1 514 966 0122
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Which live CD for recovery

2006-12-06 Thread Kay Abendroth

Erik Norgaard wrote:

Hi:

Which live CD is recommended for recovery? What I'd like is to have as 
many disk analysis tools at hand just in case.


The case is that I am not recovering a FBSD system but Windows XP 
(*sigh*). After trying to help a friend clean her pc for virus it won't 
boot, even in safe mode... ps.


I believe one of two things has happened: the anti virus placed a system 
file in the vault, or running windows update the "genuine windows 
disadvantage tool" disabled the system because it may have been pirate 
(don't know).


So, I need to recover data to some other machine, and then see if I can 
recover the system file without a full reinstall.


I would give Knoppix [ www.knoppix.org ] a try. You should be able to 
read-only mount the NTFS/FAT-32 partition and copy it to a safe place.


After that try booting from the Windows-CD and repair the installation 
(without reformatting first). If that won't help, you have to make a 
fresh install.



Kay

--
GnuPG-Key-ID: 0x4CCBF36C
Fingerprint:  7098 E6AA 4706 1CB5 62D9  CCD3 6CD4 777D 4CCB F36C

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"