Results 1 to 17 of 17

Thread: Removing Persistant Viruses

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Arena Senior Member Crazed Rabbit's Avatar
    Join Date
    May 2003
    Location
    Between the Mountain and the Sound
    Posts
    11,074
    Blog Entries
    1

    Default Removing Persistant Viruses/Using a Boot Disk for system Recovery

    So my parent's computer has become severely infected after my brother disabled virus protection like AntiVir and Ad-Aware, in an effort to speed the several years old computer up.

    Now, you can't go anywhere on the internet but virus sites, applications like task manager won't run, etc.

    I installed spybot S&D on a flash drive and attempted to run it, but I got an error saying the .exe was infected and wouldn't run. I suspect this is the work of the virus (no **** Sherlock, huh?).

    Anyways, I need some way to wipe a computer that can get past that executable block.

    Any possibilities?

    Thanks,
    CR
    Last edited by Crazed Rabbit; 12-03-2009 at 02:38.
    Ja Mata, Tosa.

    The poorest man may in his cottage bid defiance to all the forces of the Crown. It may be frail; its roof may shake; the wind may blow through it; the storm may enter; the rain may enter; but the King of England cannot enter – all his force dares not cross the threshold of the ruined tenement! - William Pitt the Elder

  2. #2
    Boy's Guard Senior Member LeftEyeNine's Avatar
    Join Date
    Sep 2003
    Location
    Yozgat
    Posts
    5,168

    Default Re: Removing Persistant Viruses

    I wonder if Safe Mode could change a thing or two.

  3. #3
    Needs more flowers Moderator drone's Avatar
    Join Date
    Dec 2004
    Location
    Moral High Grounds
    Posts
    9,286

    Default Re: Removing Persistant Viruses

    Quote Originally Posted by LeftEyeNine View Post
    I wonder if Safe Mode could change a thing or two.
    IIRC, you probably won't be able to run from a flash drive in Safe Mode, but you can try it. If you can get your anti-malware installed, definitely run your scans in safe mode. In this age of rootkits and considering the likely state of the machine, you are probably going to have to boot off a CD and scan the drive from there.
    The .Org's MTW Reference Guide Wiki - now taking comments, corrections, suggestions, and submissions

    If I werent playing games Id be killing small animals at a higher rate than I am now - SFTS
    Si je n'étais pas jouer à des jeux que je serais mort de petits animaux à un taux plus élevé que je suis maintenant - Louis VI The Fat

    "Why do you hate the extremely limited Spartan version of freedom?" - Lemur

  4. #4
    Master of useless knowledge Senior Member Kitten Shooting Champion, Eskiv Champion Ironside's Avatar
    Join Date
    Sep 2003
    Location
    Sweden
    Posts
    4,902

    Default Re: Removing Persistant Viruses

    I've seen it mentioned that simply renaming the exe file for spybot S&D might do the trick for it to run (fooling the malware). Never been needing to try it out myself though.
    We are all aware that the senses can be deceived, the eyes fooled. But how can we be sure our senses are not being deceived at any particular time, or even all the time? Might I just be a brain in a tank somewhere, tricked all my life into believing in the events of this world by some insane computer? And does my life gain or lose meaning based on my reaction to such solipsism?

    Project PYRRHO, Specimen 46, Vat 7
    Activity Recorded M.Y. 2302.22467
    TERMINATION OF SPECIMEN ADVISED

  5. #5
    Arena Senior Member Crazed Rabbit's Avatar
    Join Date
    May 2003
    Location
    Between the Mountain and the Sound
    Posts
    11,074
    Blog Entries
    1

    Default Re: Removing Persistant Viruses

    Quote Originally Posted by drone View Post
    IIRC, you probably won't be able to run from a flash drive in Safe Mode, but you can try it. If you can get your anti-malware installed, definitely run your scans in safe mode. In this age of rootkits and considering the likely state of the machine, you are probably going to have to boot off a CD and scan the drive from there.
    There may be some anti-virus software still on (just not running on startup). I had forgotten about safemode.

    Do you have a link to more explanation about booting from a CD?

    I'll try renaming the exe too.

    CR
    Ja Mata, Tosa.

    The poorest man may in his cottage bid defiance to all the forces of the Crown. It may be frail; its roof may shake; the wind may blow through it; the storm may enter; the rain may enter; but the King of England cannot enter – all his force dares not cross the threshold of the ruined tenement! - William Pitt the Elder

  6. #6
    Amphibious Trebuchet Salesman Member Whacker's Avatar
    Join Date
    Nov 2006
    Location
    in ur city killin ur militias
    Posts
    2,934

    Default Re: Removing Persistant Viruses

    If it's as infected as you say, it may be a lost cause. First question is, can it boot from a USB key? There are some linux distributions you can slot onto those and boot from them, leaving your cd/dvd burner free to use as a back up mechanism. This would allow you to mount the HDD and save whatever you wanted to off of it, like bookmarks, documents, etc. Once you've done that and burned them to optical media, you can proceed to blow away the HDD and start from scratch.

    "Justice is the firm and continuous desire to render to everyone
    that which is his due."
    - Justinian I

  7. #7
    Arena Senior Member Crazed Rabbit's Avatar
    Join Date
    May 2003
    Location
    Between the Mountain and the Sound
    Posts
    11,074
    Blog Entries
    1

    Default Re: Removing Persistant Viruses

    Safe mode doesn't work. Renaming the Spybot exe didn't work. Looks like drastic measures may be necessary.

    I'm not sure if it can boot from a USB.

    EDIT: Still not sure about the USB thing, but it does have two CD/DVD drives, so I figure that should allow for copying of files.

    CR
    Last edited by Crazed Rabbit; 12-02-2009 at 21:54.
    Ja Mata, Tosa.

    The poorest man may in his cottage bid defiance to all the forces of the Crown. It may be frail; its roof may shake; the wind may blow through it; the storm may enter; the rain may enter; but the King of England cannot enter – all his force dares not cross the threshold of the ruined tenement! - William Pitt the Elder

  8. #8
    The very model of a modern Moderator Xiahou's Avatar
    Join Date
    Aug 2002
    Location
    in the cloud.
    Posts
    9,007

    Default Re: Removing Persistant Viruses/Using a Boot Disk for system Recovery

    Quote Originally Posted by Crazed Rabbit View Post
    So my parent's computer has become severely infected after my brother disabled virus protection like AntiVir and Ad-Aware, in an effort to speed the several years old computer up.
    You've probably realized this by now, but that's a pretty horrible idea. If you want to try to speed up a well-used PC, start with a defrag.

    You could clean it up some, but really, you'd never know if you got everything or if there was still some malicious software left lurking. If you're going to fly without antivirus software, you should at least have NoScript and AdBlockPlus to protect your browsing a little. I use those plus AVG, and never seem to pick up any malware on my PC. Also, from people I've talked to, AdAware has fallen out of favor somewhat. My friend raves about SuperAntiSpyware.

    So anyway, I'm with Whacker. Backup any files that you can't live without, and then format everything and reinstall.
    "Don't believe everything you read online."
    -Abraham Lincoln

  9. #9
    Backordered Member CrossLOPER's Avatar
    Join Date
    Sep 2006
    Location
    Brass heart.
    Posts
    2,414

    Default Re: Removing Persistant Viruses

    Get a program to bombard the hard drive with random characters for about ten passes and then reinstall Windows.
    Requesting suggestions for new sig.

    -><- GOGOGO GOGOGO WINLAND WINLAND ALL HAIL TECHNOVIKING!SCHUMACHER!
    Spoiler Alert, click show to read: 
    WHY AM I NOT BEING PAID FOR THIS???

  10. #10
    Arena Senior Member Crazed Rabbit's Avatar
    Join Date
    May 2003
    Location
    Between the Mountain and the Sound
    Posts
    11,074
    Blog Entries
    1

    Default Re: Removing Persistant Viruses

    Had some luck removing parts of the virus. Task manager will run now, but not spybot.

    We got the needed info off, though, so I'll recommend a wipe.

    CR
    Ja Mata, Tosa.

    The poorest man may in his cottage bid defiance to all the forces of the Crown. It may be frail; its roof may shake; the wind may blow through it; the storm may enter; the rain may enter; but the King of England cannot enter – all his force dares not cross the threshold of the ruined tenement! - William Pitt the Elder

  11. #11
    Member Member Sevis's Avatar
    Join Date
    Oct 2009
    Location
    Netherlands
    Posts
    165

    Default Re: Removing Persistant Viruses

    Quote Originally Posted by CrossLOPER View Post
    Get a program to bombard the hard drive with random characters for about ten passes and then reinstall Windows.
    Absolutely useless. A reinstall of Windows will remove any active viruses - thus, they will not autorecover themselves - and if anything new creeps up, it'll have an easier time downloading more than it would trying to dig up something you previously formatted away.

  12. #12
    Backordered Member CrossLOPER's Avatar
    Join Date
    Sep 2006
    Location
    Brass heart.
    Posts
    2,414

    Default Re: Removing Persistant Viruses

    It's general procedure for me.
    Requesting suggestions for new sig.

    -><- GOGOGO GOGOGO WINLAND WINLAND ALL HAIL TECHNOVIKING!SCHUMACHER!
    Spoiler Alert, click show to read: 
    WHY AM I NOT BEING PAID FOR THIS???

  13. #13
    Member Member Sevis's Avatar
    Join Date
    Oct 2009
    Location
    Netherlands
    Posts
    165

    Default Re: Removing Persistant Viruses

    It can take hours on a decent-size drive, if not days.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Single Sign On provided by vBSSO