Using Pstart + Repair kit + Write Protected drive

ITMAN

Member
Reaction score
0
Location
Nr Oxford, UK
Using Pstart + Repair kit + Write Protected drive = ERROR

ok i had my kit on USB, but av on clients machines, the AV kept deleting things! so I invested in a 4GB SD + USB adaptor

All good i thought, I created kit, write protected, and voila, no more writing / deleting things

BUT, now when I try to start PStart, I get an error

The disk cannot be written to becasue it is write protected..."

So, firstly, what is pstart trying to write? and how can i get around this issue?

also, Smitfrauidfix, for example was one of the prgrams that the AV tried to delete, but now, I cant run it, becuase it want to write?
 
Last edited:
Simple solution, always carry a copy of your software toolkit on a read-only medium such as CD or DVD.
 
Hi MM

yes thats exactly what i have bought, and a 4gb SD card

Placed the tech toolkit (orginal) on it, and write protected it

Now, if i try to run pstart, or some other programs, like smitfraud, it gives the error writing

How do you (MM - as i know you use it) get around this on a clients machine? disable AV first?
 
I agree with having a write protect switch, but it can be a pain. This is what I do: I have two flash drives that go with me on call. The first one has very few tools on it, nothing that would flag an AV program. What it does have are tools to remove Mcafee and Norton among others. I will not work on a system that has one of these delete without asking programs installed. Thats the first thing to go period. After thats taken care of I'll insert my larger mobile kit with all of my goodies on it and do what ever needs done to the system. On this drive I also keep a copy of the whole kit in a password protected zip file. That way even if some things do get deleted I can blow the whole thing away and restore it in minutes.
 
Not sure how it would work but along the lines of the mentioned here I figure maybe a registry file can be made that when merged turns on/off write protect, likely reboot to reinitialized registry would be required so not sure there, or encryption software that protects drive..thinking out loud I suppose...
 
I have a Kanguru2.0 drive (4GB) that comodo used to do that to, but when the message for found malware comes up I hit add to exclusions, haven't had a problem since.

I love the physical write mechanism it has on there.
 
Interesting solution, I like it. Also came across this software USB drive write protect utility:

http://www.irongeek.com/i.php?page=security/thumbscrew-software-usb-write-blocker

It has to be on the system first and running in the sys tray, so it's still a two drive solution....unless you use it along with a truecrypt volume containing all your real tools...hmmm

This is what I suggested above but without using a program, figured adding two reg files with the switch on/off perhaps designed to run when the drive is inserted and before it is removed, program like this same thing, maybe some find it easier, thanks for link.
 
Whenever I put my flash drive into a computer I'll make the the write-protect switch is on. Then I'll manually navigate through My Computer and copy/paste what software I'm going to use onto the desktop. After a certain amount of time and no write errors I'll switch off the write-protect and open PStart.

I've tried looking for a menu that doesn't write to the drive, but I'm having a hard time finding on I like. If you wondering though PStart is updating it's config file with how many times you've ran each piece of software.
 
I also use PStart with a write protect switch, and sometimes the errors are really annoying. If you make pstart.exe and the xml setting file read only - Pstart assumes your running of a CD drive and so it doesn't update the eunning count in the settings file.

However, the problem is with how PStart displays the icons in the system tray. The API it calls, generates write protect errors.
 
I'm experiencing the same problem and the solutions given didn't work. Anyone got it working?
 
Back
Top