Puppy Linux Discussion Forum Forum Index Puppy Linux Discussion Forum
Puppy HOME page : puppylinux.com
"THE" alternative forum : puppylinux.info
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

The time now is Sat 18 May 2013, 22:10
All times are UTC - 4
 Forum index » Taking the Puppy out for a walk » Puppy Power
Virus removal on Windows
Moderators: Flash, JohnMurga
Post new topic   Reply to topic View previous topic :: View next topic
Page 1 of 1 [12 Posts]  
Author Message
sc0ttman


Joined: 16 Sep 2009
Posts: 2173
Location: UK

PostPosted: Wed 06 Apr 2011, 05:39    Post subject:  Virus removal on Windows
Subject description: puppy works best
 

I have used Puppy Linux (either Puplite or 431) to remove a number of very stubborn virus programs from Laptops and PCs running various Microsoft OSs - at work, for our customers.

There are many virus programs for Windows, as we all know. Many of them are a real pain in the a** to get rid of. One such example is the "CleanThis".. Here are some more examples:

http://www.remove-virus.net/cleanthis-virus/
http://www.remove-virus.net/xp-win-7-home-security-2011/
http://www.remove-virus.net/msremovaltool/
http://www.remove-virus.net/microsoft-security-center-2011/
http://www.remove-virus.net/win-7-security-2011/
http://www.remove-virus.net/windows-virus-update-2011/

The above virus programs pretend to be anti-virus software, and they all disable the normal Windows desktop, menu and task manager, and kill any programs and processes the user tries to run.

Using the Windows tools ComboFix and SuperAntiSpyware is great, and usually does the trick. However many of the above virus programs do not allow anything to be run while the virus is running, so these tools cannot, for example, get rid of the 'CleanThis' virus, once infected.

However, I have found that booting up Puppy from Live CD or USB, then manually removing the offending virus is the fastest and easiest way to clean out the infected Windows system of all offending files.

Then all that is left to do, is to boot into the fixed MS OS, and run ComboFix or SuperAntiSpyware (or both), to clean out the registry etc. (I could have simply installed ClamAV in Puppy and done it that way, too..)

In just one day, I used Puppy to clean out 4 PCs/laptops of VERY stubborn virus programs. Thank god, because my manager (and a colleague) could not get around any virus program mentioned above, and so they were considering formatting the hard drives of our customers and charging extra!

Good old Puppy to the rescue.
(and no, neither my boss nor my colleague said they will use Puppy from now on!)
Back to top
View user's profile Send private message 
sc0ttman


Joined: 16 Sep 2009
Posts: 2173
Location: UK

PostPosted: Wed 06 Apr 2011, 05:43    Post subject:  

Just a note to this, if someone knows how to edit the Windows registry from within Puppy Linux (or Linux in general), then please tell me, it would be great!
_________________
Akita Linux, VLC-GTK, Pup Search, Pup File Search
Back to top
View user's profile Send private message 
Moose On The Loose


Joined: 24 Feb 2011
Posts: 278

PostPosted: Wed 06 Apr 2011, 10:53    Post subject:  

sc0ttman wrote:
Just a note to this, if someone knows how to edit the Windows registry from within Puppy Linux (or Linux in general), then please tell me, it would be great!


This may work:

Install wine
copy the registry into the wine
use wine's regedit
copy it back

I haven't tried it but it seems like it may work.
Back to top
View user's profile Send private message 
jamesbond

Joined: 26 Feb 2007
Posts: 1531
Location: The Blue Marble

PostPosted: Wed 06 Apr 2011, 11:01    Post subject:  

sc0ttman wrote:
Just a note to this, if someone knows how to edit the Windows registry from within Puppy Linux (or Linux in general), then please tell me, it would be great!
The tool you're looking for is here: http://pogostick.net/~pnh/ntpasswd/. It's main purpose is to reset passwords (which requires registry access), so as an extra the author provides the registry-editing tool too. Command-line only. I tested this tool long ago with WinXP and it worked, I'm not sure of its compatibility with newer version of Windows.
_________________
Fatdog64, Slacko and Puppeee user. Puppy user since 2.13
Back to top
View user's profile Send private message 
nooby

Joined: 29 Jun 2008
Posts: 9382
Location: SwedenEurope

PostPosted: Wed 06 Apr 2011, 11:42    Post subject:  

Another important thing to remember and this is from a total noob so take it with a big hand of salt

Some virus are very clever they replace the DLLs of the original OS so you not only have to get rid of the virus as such you need to find the original DLLs and put them back in place.

I only retell what was told to me I have not tested it myself.

_________________

I'm a noob so I use Google Search of Puppy Forum

Back to top
View user's profile Send private message 
rcrsn51


Joined: 05 Sep 2006
Posts: 7743
Location: Stratford, Ontario

PostPosted: Wed 06 Apr 2011, 11:53    Post subject:  

sc0ttman wrote:
Just a note to this, if someone knows how to edit the Windows registry from within Puppy Linux (or Linux in general), then please tell me, it would be great!

Read here.
Back to top
View user's profile Send private message 
sc0ttman


Joined: 16 Sep 2009
Posts: 2173
Location: UK

PostPosted: Wed 06 Apr 2011, 12:28    Post subject:  

Lovely, cheers guys, just what I was looking for... Wanna test soon.. Also thanks to DPUP522, cos he PM'ed some good stuff too.

..now I might be able to convince my boss to have a Puppy disc lying around the shop, to sort out the virii, when I am not there!
Back to top
View user's profile Send private message 
Sylvander

Joined: 15 Dec 2008
Posts: 2852
Location: West Lothian, Scotland, UK

PostPosted: Wed 06 Apr 2011, 18:07    Post subject:  

Try using "Registry Editor PE" included in the latest version 4.5 of "FalconFour's UBCD".

I got it using a link given here in the Puppy Forums, but didn't keep a record of the URL for the post. Sad
Back to top
View user's profile Send private message 
DPUP5520

Joined: 16 Feb 2011
Posts: 756

PostPosted: Wed 06 Apr 2011, 18:12    Post subject:  

@ sc0ttman

Here are the two I mentioned earlier that I compiled a while ago, sorry it took me so long just got back to the house.

@ jamesbond

It works with All Windows from 2000 up to Windows 7
ntfsprogs-2.0.pet
Description 
pet

 Download 
Filename  ntfsprogs-2.0.pet 
Filesize  264.67 KB 
Downloaded  201 Time(s) 
chntpw-0.9.6-2.pet
Description 
pet

 Download 
Filename  chntpw-0.9.6-2.pet 
Filesize  48.83 KB 
Downloaded  212 Time(s) 

_________________
PupRescue 2.5
Puppy Crypt 528
Back to top
View user's profile Send private message 
cthisbear

Joined: 29 Jan 2006
Posts: 2942
Location: Sydney Australia

PostPosted: Wed 06 Apr 2011, 19:50    Post subject:  

Can't beat Hirens or the Falcon to fix Windows.

The Falcon can go back in >> System Restore

and also remove Windows updates >> Hotfixes.

This is because he runs the latest ERD.

His last recovery disc runs most of Hirens 13.0

Hiren's has a great password manager as well.
ERD has an unlocker.

ERD also has an inbuilt Microsoft Scanner.
Hirens has some as well.

Don't get me wrong...Puppy gets some files that Windows locks and
even the above can't unlock.

/////////

You forgot Malwarebytes Antimalware >> free version

http://www.malwarebytes.org/mbam-download.php

http://www.malwarebytes.org/mbam.php

and Hitman Pro..one time Internet scan and fix 4 free
Do not install...run as a 1 time fix.
It has a special feature...Hitman Pro in Force Breach Mode

" The development team introduced a “Force Breach” mode for
Hitman Pro.
Hold down the left CTRL-key when you start Hitman Pro
and all non-essential processes are terminated, including the
malware process."

http://hitmanpro.wordpress.com/2010/03/16/hitman-pro-in-force-breach-mode/

http://www.surfright.nl/en

Iobit Security 360 Free
You can install it and it will also allow you to install a portable version.
So a very handy feature.
The portable version will update.
Uninstall the main program then...so no clashes with other AVs.

http://www.iobit.com/security360.html

All in my post here.

http://murga-linux.com/puppy/viewtopic.php?t=58305

//////

With the newer Rogue viruses....I look for the date that the computer
was infected and find the closest match in the hard drive.

Sometimes they hide in programs,
Documents and settings...user..my documents.

Most often they have a very long file name with many numbers in it.

Maybe in all applications...they are all different.
If you can boot Hirens or the Falcon and look for the Malware icon,
you can easily find the icon properties...location etc...
and delete that.

ERD lets you stop startups in all users.

Hirens has >>> autoruns >> but you must use a remote Hive to load.

Very few people realise that if you move all your files to a newly
created folder...you can call

1 Old Windows

you can in most instances install any version of windows you want,
scan all your files...and move Windows back to its old location
once you either delete the new install...

or move it to a new folder called
1 New Windows.

Of course you would not format the Drive.
Don't Format the drive.
Leave Existing File System alone.

One of the few times I had to re-install Windows was when all
the docs went >> read only.
Nothing...and I tried everything...nothing corrected it.

So after copying all the data...I used DBAN >> and nuked it.
Re-installed...copied back data...fixed.

I have had my local computer shop clone drives,
fix the virus and clean it out with Puppy,
clone the drive back...it wouldn't boot.

He got caught a number of times.
I had him ghost the files to a spare drive.

I formatted the non booting drive with an XP cd,
and let it setup >> 1% of Windows.

Turned off the machine.
Booted Puppy, inserted the spare drive in a USB caddy,

deleted all the newly installed files,
copied over all the Ghosted files and voila!

Windows booted.
He couldn't believe it.
I have done that 4 years.
You could do the same thing in Vista and Win 7.

If I wanted to change Vista or Win 7 to XP,
once again you can move all the files to a new folder / directory as outlined above.

For warranty purposes, you can move the files back so that your old Vista - Win 7 files are there.
They can't do you over on a claim.

Any time I fix a machine, i copy a spare to a new folder like that,
as a backup

Install XP...usually creating a new ISO with nlite...

http://www.nliteos.com/download.html

add Service pack 3...needed in most cases in this instance,
and an integrated AHCI Disk Controller loaded as well.

A typical response was >> CharredPC...Acer
I used some of his blog to revert back to XP.

http://forum.notebookreview.com/acer/190581-extensa-5620-downgrade-xp.html

ftp://ftp.support.acer-euro.com/notebook/

In this case > Acer > I had no Vista, because the customer wiped
the drive... and even the hidden partition so i had a locked bios.

Chris.
Back to top
View user's profile Send private message 
purple_ghost

Joined: 09 Nov 2005
Posts: 414

PostPosted: Thu 07 Apr 2011, 21:51    Post subject: Another rescue disk.  

Trinity Rescue Disk.

http://trinityhome.org/Home/index.php?content=TRINITY_RESCUE_KIT____CPR_FOR_YOUR_COMPUTER&front_id=12&lang=en&locale=en

Not necessarily better, just something else.

_________________
Google Search of Forum: http://wellminded.com/puppy/pupsearch.html
Back to top
View user's profile Send private message 
drongo


Joined: 10 Dec 2005
Posts: 328
Location: UK

PostPosted: Fri 15 Apr 2011, 13:13    Post subject:  

PCRegedit or PC Reg Edit (both spellings are on website) boots into a Gnome based registry editor.
Back to top
View user's profile Send private message 
Display posts from previous:   Sort by:   
Page 1 of 1 [12 Posts]  
Post new topic   Reply to topic View previous topic :: View next topic
 Forum index » Taking the Puppy out for a walk » Puppy Power
Jump to:  

You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group
[ Time: 0.0941s ][ Queries: 12 (0.0169s) ][ GZIP on ]