|
#1
|
|||
|
|||
|
Hi all,
A Dell inspiron 1525 running Windows 7 came in with lots of evidence of malware (many instances of avp32.exe in processes etc). Still booted to the desktop but lots of 16-bit program won't start errors. My normal practice for heavy infestations has been to pull the drive and slave it, make an image and then work on it. I connected it and started the workshop machine, the drivers installed and then the 2 partitions autoran (what would you like to do with the drive etc) but when I went to look at them in explorer, the OS partition needs to be formatted. I've tried to get to the files with Ubuntu but it won't recognise the partition either. It shows the SMART status as healthy. The client has important files on the desktop and no backup. Do I do a quick format and try Recuva? Do I send her to a specialist? What are your thoughts? Thanks for your help!
__________________
http://www.homecomputercare.com.au |
|
#2
|
||||
|
||||
|
Hey PaulJD as long as the HD is powering up you still have a chance of backing up data from the HD. Don't reformat as yet, give this software a try (Pandora Recovery 2.1.1) which you can find here for free, Also try some malware scans in safe mode using Malwarebytes or superantispyware etc. Keep us updated...
http://download.cnet.com/Pandora-Rec...-10694796.html Last edited by Skillachi; 12-01-2010 at 05:35 AM. |
|
#3
|
|||
|
|||
|
Thanks for the recommendation Skillachi, I'll give Pandora a try first thing in the morning (its 6.50pm here in rainy Sydney and time to knock off).
I forgot to mention that I also tried putting the drive back in the Inspiron and now it won't boot - after the Dell screen I get this: Loading DMK version 8.00 (dell real mode kernel). I'll let you know how I go.
__________________
http://www.homecomputercare.com.au |
|
#4
|
||||
|
||||
|
Quote:
(link) http://www.cooldrives.com/index.php/saandidehadr1.html But you can get it for much cheaper on ebay or amazon.com keep us posted..... |
|
#5
|
||||
|
||||
|
DRMK is related to Dell recovery image on the Hard Disk.
What information does Disk Management give you about the drive when it is connected. Quote:
|
|
#6
|
||||
|
||||
|
It work for me before, many times too...
|
|
#7
|
||||
|
||||
|
I have never come accross that, If one controller can't access the data, I don't think another would either...I could be wrong
![]() This however sounds more like it is related to the disk being dynamic. |
|
#8
|
|||
|
|||
|
Thanks for your replies.
TLE: Disk Manager shows F: as 140.84 GB FAT Healthy (Active, primary Partition) but it only has the recovery partition files on it. In explorer it shows as 62Mb. Disk Manager shows G: as 8.20 GB RAW Healthy (Primary Partition) but explorer can't read it - it needs to be formatted. So my analysis is that when the OS partition autoran as I turned on the worshop machine with the drive in question slaved, either the virus or Kaspersly (which found a Rootkit.Win32.TDSS immediately and cleaned it) wrecked the file structure. Realistically, in a Dell PC of this age, only the recovery partition would be FAT. The operating system partition would be NTFS. Neither Recuva or Panda can see anything other than the recovery partition files. All is not lost though, I'm running a trial version of Advanced NTFS Recovery and it shows 3 versions of F: the 62Mb FAT 16 (Dell Utility), a 140Gb FAT 16 (Dell Utility) and a 32 Gb FAT 32 (NO NAME) It also shows the NTFS 8.2Gb volume. It is currently scanning the 140Gb drive (phew!) and has located 96064 folders and 1040000 files so far. I'm keeping my fingers crossed.....
__________________
http://www.homecomputercare.com.au Last edited by PaulJD; 12-02-2010 at 02:20 AM. |
|
#9
|
|||
|
|||
|
tried other trial including Get Data Back but this one (Advanced NTFS Revovery) was the only one that worked so forked out the $100 and all the data was retrieved.
I guess I'm going into the data retrieval business. thanks for your help and interest.
__________________
http://www.homecomputercare.com.au |
|
#10
|
||||
|
||||
|
Quote:
Nice one, Getdataback has helped me a few times. |
![]() |
| Thread Tools | |
| Display Modes | |
|
|