We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

redirecting me to other websites

1678911

Comments

  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    Did you download & save the file gparted-live-0.11.0-7.iso to your computer?
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    waddler_8 wrote: »
    Then it could be the infection stopping it. That points to the new variant of the TDL4 bootkit.

    Dont take this the wrong way, its good that your helping the OP and others. Im just curious as to how youve jumped to the conclusion the problem is the TDL4 bootkit?
    :idea:
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    I don't know what waddler had in mind for F8 so I won't speculate.

    ...Using the command prompt from the RE to restore the MBR using MBRfix (it can be run via the RE). The USB flash drive is for a tool that can also be run via the RE from a flash drive.

    The partition table shows 4 partitions - I'm presuming; 1. Recovery (hidden), 2. The OS partition, 3. A backup/data partition & of course 4. The rootkit's partition (hidden).

    The boot flag has to be set correctly, so I have to know exactly which partition the OS is on - I can't just presume the above - I need to know for sure.
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    aliEnRIK wrote: »
    Dont take this the wrong way, its good that your helping the OP and others. Im just curious as to how youve jumped to the conclusion the problem is the TDL4 bootkit?
    From the symptoms + I've got a copy of the MBR that the OP emailed me - Examining that you can see the rootkits partition and that it's set as the active partition.
  • closed
    closed Posts: 10,886 Forumite
    edited 14 January 2012 at 1:47AM
    Can't guarantee it.

    Haven't read the whole thread, but if it is what you suspect, disk administrator is an easier way to change active partitions, assuming it isn't blocked by the infection - suggest the op posts a disk administrator screen shot before going down the gparted route.
    !!
    > . !!!! ----> .
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Makes sense now.
    Although it would be nice if information was shared on the thread because how would anyone else know?
    :idea:
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    closed wrote: »
    but if it is what you suspect, disk administrator is an easier way to change active partitions, assuming it isn't blocked by the infection
    I do know that it cant be done through DM with the infection active.
  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    aliEnRIK wrote: »
    Makes sense now.
    Although it would be nice if information was shared on the thread because how would anyone else know?
    I did post it earlier somewhere (I think...)
  • closed
    closed Posts: 10,886 Forumite
    surprised it got past kaspersky.
    !!
    > . !!!! ----> .
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352K Banking & Borrowing
  • 253.5K Reduce Debt & Boost Income
  • 454.2K Spending & Discounts
  • 245K Work, Benefits & Business
  • 600.6K Mortgages, Homes & Bills
  • 177.4K Life & Family
  • 258.8K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.