PDA

View Full Version : Tech help for virus removal


View Full Version : Tech help for virus removal


uselesscrap
January 5th, 2006, 07:45 AM
i am not a tech, nor do I pretend to be. however, i am wondering if there is an easier way to remove viruses from my neighbours computer. it seems to be happening a lot and they keep asking me to help. I'm sure their kid is to blame. anyhow, what i am thinking is installing XP on a 10 gb hard drive and install AVG on it. i then make sure the definitions are up to date, then off to the neighbours i go with my HD, making it the master and theirs the slave and scan for viruses. would this work okay? any techie's here?

thepuzzler
January 5th, 2006, 07:57 AM
Why not just burn a CD with AVG on it, and update the virus definitions from their internet connection. (I presume they're conected to the internet if they keep getting viruses).

Your way will work, but it seems like a lot of hassle. Is it because they're running Windows '98 and AVG is incompatible or something?

pimpinaman
January 5th, 2006, 08:29 AM
I would try safe mode and then run AVG. You will find stuff more in safe mode than in normal mode.

axlman
January 5th, 2006, 08:45 AM
Yes, loading AVG on an infected machine could work, although it is not recommeded to do so. What ever you do, rather it's load a drive and Master/Slave them then scan, etc. or Load AVG on the infected machine, make sure that you go into the settings of AVG and set them to scan all files, the default is to mainly scan program files only.

Another option the try first, is if it's connected to the internet, then run an Online Scan.

You can go here http://housecall.trendmicro.com/
House call will need to install an Active X control, but nothing to worry about. It uses Java as well.

House call may or may not beable to delete some Viruses, but whatever it can not remove, then at least you will know what viruses they are and can go to somewhere like Symantec and maybe download the removal tools.

Hope this helps.

uselesscrap
January 5th, 2006, 09:21 AM
Why not just burn a CD with AVG on it, and update the virus definitions from their internet connection. (I presume they're conected to the internet if they keep getting viruses).

Your way will work, but it seems like a lot of hassle. Is it because they're running Windows '98 and AVG is incompatible or something?

they already have AVG installed, but it's buggered. I tried for over two hours last night to run it, and even in safe mode it won't work. also, housecall would not install. that's why I was thinking of running AV from another HD. i will surely ghost their drive when this is done.

anyway can anti-virus be run from a usb stick?

thepuzzler
January 5th, 2006, 09:28 AM
anyway can anti-virus be run from a usb stick?
I haven't tried personally, but you can boot linux from a USB stick, so I don't see why not. It's gotta be easier to try to do that before you start luggin hard drives around.

shawners
January 5th, 2006, 10:06 AM
Reformat and install windows xp professional, then put norton (Retail) on it without being connected the internet for obvious reasons of calling back to check serial, then update and reboot til all is done. And GET RID OF INTERNET EXPLORER, DELETE short cuts and install FIREFOX with thunderbird email client and possibly lecture them on what to install and what not to install!

pimpinaman
January 5th, 2006, 10:42 AM
if you need to save the drive then do what you are thinking and put the hard drive in a usb hard drive carrier and scan the drive with your system....

uselesscrap
January 5th, 2006, 11:28 AM
Reformat and install windows xp professional, then put norton (Retail) on it without being connected the internet for obvious reasons of calling back to check serial, then update and reboot til all is done. And GET RID OF INTERNET EXPLORER, DELETE short cuts and install FIREFOX with thunderbird email client and possibly lecture them on what to install and what not to install!

though reformatting may fix all, it is not the simple answer to virus repair. are you telling me every time someone brings their computer in the tech shop for virus repair they format them?

thanks for your input anyways.

shawners
January 5th, 2006, 12:12 PM
though reformatting may fix all, it is not the simple answer to virus repair. are you telling me every time someone brings their computer in the tech shop for virus repair they format them?

thanks for your input anyways.

Most people that have a pc know how to remove a virus without formatting and may be able to use GOOGle.
But im telling you to reformat and install a clean version of windows xp, and with the apps necessary, as well as removing internet explorer shortcuts and making firefox the default browser. Installing antivirus on a pc that may be infected could cause it to not install properly or remove the files necessary to update or remove it self.. And if they have a kid, chances are they got tons of spyware, and tons of junk clustering it up.

axlman
January 5th, 2006, 12:21 PM
Since the infected machine already has AVG on it, Install a clean copy of AVG onto the USB Stick ( Create a folder called something like (AVG) and install to that folder on the USB Stick. Load the update Virus Def's of course, From your machine that you load the AVG on, make sure to change the settings to scan all files, etc. then connect the the USB stick to the infected machine and then change the desktop shortcut's "target" (if there is one) and point it to that USB Stick.

Example:"J:\AVG\Grisoft\AVG Free\avgw.exe"

If that works, then don't forget to change the AVG shortcut back to it's default target: "C:\Program Files\Grisoft\AVG Free\avgw.exe" after the system has been cleaned.


If that don't work.... then I would just go ahead and slave that drive and scan/clean it! If all else fails, then yes...buy all means, Format that drive!


let us know if you know how to do that or not. I would think that it may run that way.

uselesscrap
January 5th, 2006, 01:26 PM
Since the infected machine already has AVG on it, Install a clean copy of AVG onto the USB Stick ( Create a folder called something like (AVG) and install to that folder on the USB Stick. Load the update Virus Def's of course, From your machine that you load the AVG on, make sure to change the settings to scan all files, etc. then connect the the USB stick to the infected machine and then change the desktop shortcut's "target" (if there is one) and point it to that USB Stick.

Example:"J:\AVG\Grisoft\AVG Free\avgw.exe"

If that works, then don't forget to change the AVG shortcut back to it's default target: "C:\Program Files\Grisoft\AVG Free\avgw.exe" after the system has been cleaned.


If that don't work.... then I would just go ahead and slave that drive and scan/clean it! If all else fails, then yes...buy all means, Format that drive!


let us know if you know how to do that or not. I would think that it may run that way.

okay, thanks. I will give that a try when I get home today.

If all else fails, I will go shawners route and format.

shawners
January 5th, 2006, 05:14 PM
You know how viruses are, they get in to the boot sectors, or have dummy dll files that rewrites to the directory if you happen to delete it and such. Plus removing spyware-adware will do crazy stuff to the registry where some programs wont run as smoothly, then that may have to be fixed and its just as easy as PIE, plus the pc runs faster since its defraged essentialy.

uselesscrap
January 5th, 2006, 05:35 PM
You know how viruses are, they get in to the boot sectors, or have dummy dll files that rewrites to the directory if you happen to delete it and such. Plus removing spyware-adware will do crazy stuff to the registry where some programs wont run as smoothly, then that may have to be fixed and its just as easy as PIE, plus the pc runs faster since its defraged essentialy.

I find after formatting and installing the basics of software my HD is usually very fragmented. Most often I defrag after a fresh installation, unless I'm using a ghost image.

axlman
January 5th, 2006, 07:03 PM
So did it work?

cpugeniusmv
January 5th, 2006, 07:11 PM
Most people that have a pc know how to remove a virus without formatting and may be able to use GOOGle.
What world do you live in? My bags are packed, I'm ready to move whereever you are.

MorphineInduced
January 5th, 2006, 07:55 PM
your best bet is if its already to the point that your own virus programs arent even running correctly then you should reformat but then get them something like pccillin from trend mirco or f-secure you can easly get them that with free updates from any credible warez site they all come with cracks or sometype of keygen but other than that get them trojanhunter and webroots spysweeper........you can get the same patchs and what not if you search around for them ..........after that put them all on high and just get them to update and weekly check....... now it is the kid if you ask me unless the father likes alot of porn cuz he aint gettin none...... so im sure he will still get somethings but if he keeps them current and weekly checks it will save you time from always being the nice guy and helping.......... dont carry around a harddrive get a memory stick and run these programs off of them if need be........ and if this is becomeing a ritual like it sounds tell them that time is money and they just need to start paying for your help..........

CRLocky
January 5th, 2006, 08:19 PM
What world do you live in? My bags are packed, I'm ready to move whereever you are.

haha, ohhh what it must be like to be a genius...

Afn
January 6th, 2006, 05:09 AM
If you have the nail.exe virus on your computer, you have to reformat your harddrive and install XP again. A relative had it, and it was interesting how it embedded itself into windows. Even in safemode you could not get rid of it.

Auggie2k
January 6th, 2006, 05:12 AM
If you have the nail.exe virus on your computer, you have to reformat your harddrive and install XP again. A relative had it, and it was interesting how it embedded itself into windows. Even in safemode you could not get rid of it.
I find it hard to believe that a reformat is the only possible solution?

What about reinstalling Windows on another partition and using that as your work space?

I've done it before to get rid of some really nasty crap (turns out my Auto-Protect was off)

uselesscrap
January 6th, 2006, 07:25 AM
well, in this case I should have listened to shawners. i was able to scan their HD from my 10 gig drive and remove over 1500 infected files. bloodhound, w32.dabra, w32.bagle, as well as a ton of spyware. istbar. searchbar, etc.

so after wasting two or three hours of my time, I discovered things were still extremely slow and buggy, I reluctantly decided to format. the reason I didn't want to do this is because I also had to back up their data to an external drive, which takes more time. they will not have this problem again, as I will be ghosting their drive after work today.

soulxtc
January 6th, 2006, 12:34 PM
speaking of viruses, my spare Pc just got a fricken trojan Im afraid, supposedly that SpyAxe crap from the looks of it, it seems winlogin.exe is corrupted, with this message before the login screen somes up


instruction at 0x7597ebd2 referenced memory 0x78000044 memory could not be read.
press ok to terminate cancel to debug.


any of you ever seen this before?


Can boot up in safe mode, so something's f-ing it up, uninstalled last 10 programs for safe measure and even tried system restore to no avail, also tried to find a registry problem but nothing comes up as symantec says should, i.e trojan "winlogon.exe" vs "winlogin.exe".


Its really pissing me off.........f-in Outpost firewall sucks balls, and its spyware scan is no help.....


If one of you mofo's can fix this crap will send the cash that my otherwise be spent on sedatives or therapy if I cant fix.......my spare PC is the one with all my Tribe and Beastie's stuff on it.....f

kokanezub
January 6th, 2006, 12:41 PM
u have the reinstall disk? if u do then delet win logon or win login one of them and see if u can reboot one is a viri and try to use hijackthis or spybot

soulxtc
January 6th, 2006, 02:34 PM
i tried ad-aware, will try the other two, spybot, and hijackthis(?).....thx, hopefully it works......

The Hunter
January 6th, 2006, 02:38 PM
Hey soul give this a try, and let us know how you make out.

http://housecall.trendmicro.com/

soulxtc
January 6th, 2006, 02:52 PM
Thanx Hunter will do................Im just glad its my spare thats f-'d up....

The Hunter
January 6th, 2006, 04:05 PM
More info here.

http://www.bleepingcomputer.com/forums/topic36868.html

http://vil.nai.com/vil/content/v_137512.htm

http://blogs.zdnet.com/Spyware/index.php?p=728

soulxtc
January 6th, 2006, 07:38 PM
Hmm, yah tried those links and they propose a different registry alteration for spyaxe, I dont see the alterations in my registry that it claims to perform.................so I think Im just gonna transfer all my important shit to my slave drive and then reformat my c drive, 90G of music may take a while unfortunately.................oh well.....thanx though for help Hunter.