Welcome, Guest. Please Login
 
  HomeHelpSearchLogin FAQ Radified Ghost.Classic Ghost.New Bootable CD Blog  
 
Page Index Toggle Pages: 1
Send Topic Print
Ghost 2001 (Read 6248 times)
Gotki
N00b
Offline



Posts: 4
USA


Back to top
Ghost 2001
Jun 5th, 2007 at 1:21pm
 
Well, I have lot of rootkits on my pc so I decided to restore the image file from ghost 2001. But I don't know how to restore the image file by using ghost cuz there are options like local>disk and local partitions Cry So I came here. Sorry if I had posted this in wrong thread. But I want to know the step by step procedure of restoring file from ghost. I have 4 files of ghost. First the main ghostpe, and the three other are old.gho, setup.gho and setup001.ghs. What if I restore them would it restore the full c:. They are images of c: and also, I want to restore only the setup.gho file. Please someone reply to this cuz its very important.
 
 
IP Logged
 

NightOwl
Radministrator
*****
Offline


"I tought I saw a puddy
tat..."

Posts: 5826
Olympia, WA--Puget Sound--USA


Back to top
Re: Ghost 2001
Reply #1 - Jun 5th, 2007 at 10:53pm
 
Gotki

Quote:
Well, I have lot of rootkits on my pc so I decided to restore the image file from ghost 2001.

I'm no *rootkit* expert--but a simple restore to an existing drive that is already partitioned will not effect any code that is stored in the first 63 boot sectors of a HDD, i.e. absolute sectors 0 through 62--total of 63--so if there's any chance that malicious code has been stored in the boot region, you need to use a program that will zero out or wipe the code in those first 63 sectors.  A restore will not effect those sectors--even re-partitioning or a re-format will not touch those first 63 sectors!

Almost any DOS disk editor could do it for you (Download PTS Disk Editor here:).  

This program will work:   MBRWizard - The MBR utility you've been looking for!.

If you have all the Ghost 2001 files, then you may have Ghost's *gdisk*--Symantec's command line partitioning tool--a substitute for *fdisk*--but it also has a wiping function that will wipe the first 63 sectors along with the rest of the drive.

These are powerful disk editing tools--make sure you are comfortable with their use, make sure you have a good backup of important data, and make sure you are editing the correct HDD--possibly disconnect any others until the editing is done, and make sure you're ready to proceed!

Quote:
have 4 files of ghost. First the main ghostpe, and the three other are old.gho, setup.gho and setup001.ghs. What if I restore them would it restore the full c:.

Well, did you create the backup files?  Do you know what's on them--obviously, we don't!!!

*ghostpe.exe* is the Ghost program file.

It looks like you have two different backups:  1.  *old.gho* which takes up less than 2 GB of data, and 2.  *setup.gho* which is a two file set--the first one being probably about 2 GB and the second spanned file is *setup001.ghs* with something less than 2 GB of data--so these two are a pair of a single backup image set.

Restoring either one of those will result in the data that was present when those files were made to be restored.

Use *Local > Disk > from Image* as the restore command.

If you have zeroed out the first 63 sectors, Ghost will have the Master Boot Sector from the original HDD stored in the image file and will restore that along with all the other data stored in the image file.

Quote:
But I want to know the step by step procedure of restoring file from ghost.

This may help: Guide to Norton Ghost
 

____________________________________________________________________________________________

No question is stupid ... but, possibly the answers are Wink !
 
IP Logged
 
Gotki
N00b
Offline



Posts: 4
USA


Back to top
Re: Ghost 2001
Reply #2 - Jun 6th, 2007 at 1:12am
 
Well It looks like I have got some fine problems. When I checked the image setup.gho then it was successfull. But after that when it asked me to insert the next media, I located the setup001.ghs file and it said that it was not the right kind of span media file. Though should I try to restore them? I am looking forward to this when I found something by rootkit hook analyzer. Click the link to see it:-
http://uploadimages.com/manage/MTE3NTcuMTIzOTg=.45419

It is saying runtime2.sys in kernel modules.

Do I have to wipe out all the things by using disk editors and then restore?
 
 
IP Logged
 
NightOwl
Radministrator
*****
Offline


"I tought I saw a puddy
tat..."

Posts: 5826
Olympia, WA--Puget Sound--USA


Back to top
Re: Ghost 2001
Reply #3 - Jun 6th, 2007 at 1:24am
 
Gotki

Quote:
When I checked the image setup.gho then it was successfull. But after that when it asked me to insert the next media, I located the setup001.ghs file and it said that it was not the right kind of span media file.

If you were doing an *Integrity* check--it's never a good thing if Ghost will not successfully finish the integrity check saying the image passes the test!

Quote:
I found something by rootkit hook analyzer

Does the *analyzer* have the ability to clean or remove the rootkit problems it finds?
 

____________________________________________________________________________________________

No question is stupid ... but, possibly the answers are Wink !
 
IP Logged
 
Gotki
N00b
Offline



Posts: 4
USA


Back to top
Re: Ghost 2001
Reply #4 - Jun 6th, 2007 at 2:47am
 
Currently I'm searching if there are any rootkit hook removers so I'll be posting in the next post all the necessary things. It is possible if the rootkit remover runs then it will removes the rootkits and I won't need any restoration. And The Image if you have seen, is of rootkit hook analyzer and it do not removes the hooks. Even I'm not able to start my pc in safe mode.
 
 
IP Logged
 
Gotki
N00b
Offline



Posts: 4
USA


Back to top
Re: Ghost 2001
Reply #5 - Jun 6th, 2007 at 4:47am
 
Woohoo, Finally I have got sophos anti rootkit and deleted the runtime2.sys file once but there are also some other files which I need to remove and it will take sometime. Thanks buddy for the help though. But if there will be any more problem then you won't be able to resist me.  Grin
 
 
IP Logged
 
Page Index Toggle Pages: 1
Send Topic Print