Jump to content











Photo
- - - - -

virus in LiveXP ????


  • Please log in to reply
3 replies to this topic

#1 cdmaker

cdmaker
  • Members
  • 1 posts
  •  
    India

Posted 03 July 2010 - 03:33 PM

Hi.. ;) :cheers: ;) :unsure:
this is my first post to the forum
i have just made a cd with winbuilder : LiveXP
everything went fine but when i boot with it a
blue screen appeared in my Acer 5740G....i feel is cause
my laptop has SATA drive and maybe this LiveXP doesnt work with
it. Also I noticed that the following files has trojans :


D:\I386\SYSTEM32\deskadp.dll (Malware.Packer.Gen) -> No action taken.
D:\I386\SYSTEM32\deskmon.dll (Trojan.Agent) -> No action taken.
D:\I386\SYSTEM32\deskperf.dll (Trojan.Agent) -> No action taken.
D:\I386\SYSTEM32\themeui.dll (Malware.Packer.Gen) -> No action taken.

this results were passed by Malwarebytes...which seems to be a really nice antivirus.

with virtual pc it works fine..but not when booting directly from it....apart of the trojans, that i will like to know were to get these files but clean....

thanks to all in advance
cdmaker

#2 Lancelot

Lancelot

    Frequent Member

  • .script developer
  • 5013 posts
  • Location:Turkiye/Izmir
  • Interests:*Mechanical stuff and Physics,
    *LiveXP, BartPE, SherpyaXPE,
    *Basketball and Looong Walking,
    *Buying outwear for my girlf (Reason: Girls are stupid about buying bad stuff to make themselves uglier :))
    *Girls (Lyric: Girl,...., You will be a womann, Soon)
    *Answering questions for "Meaning of life",
    *Helping people,

    Kung with LiveXP, Fu with Peter :)
  •  
    Turkey

Posted 03 July 2010 - 04:01 PM

Hi cdmaker,

files you mention are not coming from livexp, they come from your source cd :unsure:.

#3 pscEx

pscEx

    Platinum Member

  • Team Reboot
  • 12707 posts
  • Location:Korschenbroich, Germany
  • Interests:What somebody else cannot do.
  •  
    European Union

Posted 03 July 2010 - 04:21 PM

For 99,9% Lancelot is right.

But maybe that, in addition to the LiveXP apps, you included a 3rd party app script in your project which overwrites the files in question with infected files.

To be sure, please use Debug Log functionality.

In WB, click "Tools" in the upper right, then check 'Debug log' in the middle right, and rebuild the project.

If there is no warning about overwriting the files in question, your source CD seems really to be infected (Is it any Warez or Torrent product?)
If there is a warning, you propably found the 'bad boy'.

Peter

#4 dera

dera

    Gold Member

  • .script developer
  • 1335 posts
  •  
    Hungary

Posted 03 July 2010 - 08:26 PM

in \Components\Tweaks\DisplayProperties.script
in section [Process]
try to comment out the line #47:
//Run,%ScriptFile%,Process-UPX

in this case do you still get the virus alert?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users