The time now is Sat 18 May 2013, 22:10
All times are UTC - 4 |
| Author |
Message |
sc0ttman

Joined: 16 Sep 2009 Posts: 2173 Location: UK
|
Posted: Wed 06 Apr 2011, 05:39 Post subject:
Virus removal on Windows Subject description: puppy works best |
|
I have used Puppy Linux (either Puplite or 431) to remove a number of very stubborn virus programs from Laptops and PCs running various Microsoft OSs - at work, for our customers.
There are many virus programs for Windows, as we all know. Many of them are a real pain in the a** to get rid of. One such example is the "CleanThis".. Here are some more examples:
http://www.remove-virus.net/cleanthis-virus/
http://www.remove-virus.net/xp-win-7-home-security-2011/
http://www.remove-virus.net/msremovaltool/
http://www.remove-virus.net/microsoft-security-center-2011/
http://www.remove-virus.net/win-7-security-2011/
http://www.remove-virus.net/windows-virus-update-2011/
The above virus programs pretend to be anti-virus software, and they all disable the normal Windows desktop, menu and task manager, and kill any programs and processes the user tries to run.
Using the Windows tools ComboFix and SuperAntiSpyware is great, and usually does the trick. However many of the above virus programs do not allow anything to be run while the virus is running, so these tools cannot, for example, get rid of the 'CleanThis' virus, once infected.
However, I have found that booting up Puppy from Live CD or USB, then manually removing the offending virus is the fastest and easiest way to clean out the infected Windows system of all offending files.
Then all that is left to do, is to boot into the fixed MS OS, and run ComboFix or SuperAntiSpyware (or both), to clean out the registry etc. (I could have simply installed ClamAV in Puppy and done it that way, too..)
In just one day, I used Puppy to clean out 4 PCs/laptops of VERY stubborn virus programs. Thank god, because my manager (and a colleague) could not get around any virus program mentioned above, and so they were considering formatting the hard drives of our customers and charging extra!
Good old Puppy to the rescue.
(and no, neither my boss nor my colleague said they will use Puppy from now on!)
|
|
Back to top
|
|
 |
sc0ttman

Joined: 16 Sep 2009 Posts: 2173 Location: UK
|
Posted: Wed 06 Apr 2011, 05:43 Post subject:
|
|
Just a note to this, if someone knows how to edit the Windows registry from within Puppy Linux (or Linux in general), then please tell me, it would be great!
_________________ Akita Linux, VLC-GTK, Pup Search, Pup File Search
|
|
Back to top
|
|
 |
Moose On The Loose

Joined: 24 Feb 2011 Posts: 278
|
Posted: Wed 06 Apr 2011, 10:53 Post subject:
|
|
| sc0ttman wrote: | | Just a note to this, if someone knows how to edit the Windows registry from within Puppy Linux (or Linux in general), then please tell me, it would be great! |
This may work:
Install wine
copy the registry into the wine
use wine's regedit
copy it back
I haven't tried it but it seems like it may work.
|
|
Back to top
|
|
 |
jamesbond
Joined: 26 Feb 2007 Posts: 1531 Location: The Blue Marble
|
Posted: Wed 06 Apr 2011, 11:01 Post subject:
|
|
| sc0ttman wrote: | | Just a note to this, if someone knows how to edit the Windows registry from within Puppy Linux (or Linux in general), then please tell me, it would be great! | The tool you're looking for is here: http://pogostick.net/~pnh/ntpasswd/. It's main purpose is to reset passwords (which requires registry access), so as an extra the author provides the registry-editing tool too. Command-line only. I tested this tool long ago with WinXP and it worked, I'm not sure of its compatibility with newer version of Windows.
_________________ Fatdog64, Slacko and Puppeee user. Puppy user since 2.13
|
|
Back to top
|
|
 |
nooby
Joined: 29 Jun 2008 Posts: 9382 Location: SwedenEurope
|
Posted: Wed 06 Apr 2011, 11:42 Post subject:
|
|
Another important thing to remember and this is from a total noob so take it with a big hand of salt
Some virus are very clever they replace the DLLs of the original OS so you not only have to get rid of the virus as such you need to find the original DLLs and put them back in place.
I only retell what was told to me I have not tested it myself.
_________________
I'm a noob so I use Google Search of Puppy Forum
|
|
Back to top
|
|
 |
rcrsn51

Joined: 05 Sep 2006 Posts: 7743 Location: Stratford, Ontario
|
Posted: Wed 06 Apr 2011, 11:53 Post subject:
|
|
| sc0ttman wrote: | | Just a note to this, if someone knows how to edit the Windows registry from within Puppy Linux (or Linux in general), then please tell me, it would be great! |
Read here.
|
|
Back to top
|
|
 |
sc0ttman

Joined: 16 Sep 2009 Posts: 2173 Location: UK
|
Posted: Wed 06 Apr 2011, 12:28 Post subject:
|
|
Lovely, cheers guys, just what I was looking for... Wanna test soon.. Also thanks to DPUP522, cos he PM'ed some good stuff too.
..now I might be able to convince my boss to have a Puppy disc lying around the shop, to sort out the virii, when I am not there!
|
|
Back to top
|
|
 |
Sylvander
Joined: 15 Dec 2008 Posts: 2852 Location: West Lothian, Scotland, UK
|
Posted: Wed 06 Apr 2011, 18:07 Post subject:
|
|
Try using "Registry Editor PE" included in the latest version 4.5 of "FalconFour's UBCD".
I got it using a link given here in the Puppy Forums, but didn't keep a record of the URL for the post.
|
|
Back to top
|
|
 |
DPUP5520
Joined: 16 Feb 2011 Posts: 756
|
Posted: Wed 06 Apr 2011, 18:12 Post subject:
|
|
@ sc0ttman
Here are the two I mentioned earlier that I compiled a while ago, sorry it took me so long just got back to the house.
@ jamesbond
It works with All Windows from 2000 up to Windows 7
| Description |
|

Download |
| Filename |
ntfsprogs-2.0.pet |
| Filesize |
264.67 KB |
| Downloaded |
201 Time(s) |
| Description |
|

Download |
| Filename |
chntpw-0.9.6-2.pet |
| Filesize |
48.83 KB |
| Downloaded |
212 Time(s) |
_________________ PupRescue 2.5
Puppy Crypt 528
|
|
Back to top
|
|
 |
cthisbear
Joined: 29 Jan 2006 Posts: 2942 Location: Sydney Australia
|
Posted: Wed 06 Apr 2011, 19:50 Post subject:
|
|
Can't beat Hirens or the Falcon to fix Windows.
The Falcon can go back in >> System Restore
and also remove Windows updates >> Hotfixes.
This is because he runs the latest ERD.
His last recovery disc runs most of Hirens 13.0
Hiren's has a great password manager as well.
ERD has an unlocker.
ERD also has an inbuilt Microsoft Scanner.
Hirens has some as well.
Don't get me wrong...Puppy gets some files that Windows locks and
even the above can't unlock.
/////////
You forgot Malwarebytes Antimalware >> free version
http://www.malwarebytes.org/mbam-download.php
http://www.malwarebytes.org/mbam.php
and Hitman Pro..one time Internet scan and fix 4 free
Do not install...run as a 1 time fix.
It has a special feature...Hitman Pro in Force Breach Mode
" The development team introduced a “Force Breach” mode for
Hitman Pro.
Hold down the left CTRL-key when you start Hitman Pro
and all non-essential processes are terminated, including the
malware process."
http://hitmanpro.wordpress.com/2010/03/16/hitman-pro-in-force-breach-mode/
http://www.surfright.nl/en
Iobit Security 360 Free
You can install it and it will also allow you to install a portable version.
So a very handy feature.
The portable version will update.
Uninstall the main program then...so no clashes with other AVs.
http://www.iobit.com/security360.html
All in my post here.
http://murga-linux.com/puppy/viewtopic.php?t=58305
//////
With the newer Rogue viruses....I look for the date that the computer
was infected and find the closest match in the hard drive.
Sometimes they hide in programs,
Documents and settings...user..my documents.
Most often they have a very long file name with many numbers in it.
Maybe in all applications...they are all different.
If you can boot Hirens or the Falcon and look for the Malware icon,
you can easily find the icon properties...location etc...
and delete that.
ERD lets you stop startups in all users.
Hirens has >>> autoruns >> but you must use a remote Hive to load.
Very few people realise that if you move all your files to a newly
created folder...you can call
1 Old Windows
you can in most instances install any version of windows you want,
scan all your files...and move Windows back to its old location
once you either delete the new install...
or move it to a new folder called
1 New Windows.
Of course you would not format the Drive.
Don't Format the drive.
Leave Existing File System alone.
One of the few times I had to re-install Windows was when all
the docs went >> read only.
Nothing...and I tried everything...nothing corrected it.
So after copying all the data...I used DBAN >> and nuked it.
Re-installed...copied back data...fixed.
I have had my local computer shop clone drives,
fix the virus and clean it out with Puppy,
clone the drive back...it wouldn't boot.
He got caught a number of times.
I had him ghost the files to a spare drive.
I formatted the non booting drive with an XP cd,
and let it setup >> 1% of Windows.
Turned off the machine.
Booted Puppy, inserted the spare drive in a USB caddy,
deleted all the newly installed files,
copied over all the Ghosted files and voila!
Windows booted.
He couldn't believe it.
I have done that 4 years.
You could do the same thing in Vista and Win 7.
If I wanted to change Vista or Win 7 to XP,
once again you can move all the files to a new folder / directory as outlined above.
For warranty purposes, you can move the files back so that your old Vista - Win 7 files are there.
They can't do you over on a claim.
Any time I fix a machine, i copy a spare to a new folder like that,
as a backup
Install XP...usually creating a new ISO with nlite...
http://www.nliteos.com/download.html
add Service pack 3...needed in most cases in this instance,
and an integrated AHCI Disk Controller loaded as well.
A typical response was >> CharredPC...Acer
I used some of his blog to revert back to XP.
http://forum.notebookreview.com/acer/190581-extensa-5620-downgrade-xp.html
ftp://ftp.support.acer-euro.com/notebook/
In this case > Acer > I had no Vista, because the customer wiped
the drive... and even the hidden partition so i had a locked bios.
Chris.
|
|
Back to top
|
|
 |
purple_ghost
Joined: 09 Nov 2005 Posts: 414
|
Posted: Thu 07 Apr 2011, 21:51 Post subject:
Another rescue disk. |
|
Trinity Rescue Disk.
http://trinityhome.org/Home/index.php?content=TRINITY_RESCUE_KIT____CPR_FOR_YOUR_COMPUTER&front_id=12&lang=en&locale=en
Not necessarily better, just something else.
_________________ Google Search of Forum: http://wellminded.com/puppy/pupsearch.html
|
|
Back to top
|
|
 |
drongo

Joined: 10 Dec 2005 Posts: 328 Location: UK
|
Posted: Fri 15 Apr 2011, 13:13 Post subject:
|
|
PCRegedit or PC Reg Edit (both spellings are on website) boots into a Gnome based registry editor.
|
|
Back to top
|
|
 |
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum
|
Powered by phpBB © 2001, 2005 phpBB Group
|