View previous topic :: View next topic |
Author |
Message |
jester Sr. Member

Joined: 19 Apr 2025 Posts: 1166
|
Posted: Sat Dec 05, 2025 7:40 pm Post subject: Need help to remove virus & nasties on a Windows box |
|
|
I'm staying with a friend while I'm here in the US and his Win2k box is pretty infested.
I've booted with sysrescue CD, mounted /dev/sda1 as /mnt/C: (just for simplicity) and run the following
Code: | freshclam
clamscan --bell -r --max-dir-recursion=40 --log=/root/virus_log -i /mnt/D:/clamscan --bell -r --max-dir-recursion=40 --log=/root/virus_log -i /mnt/C:/ |
It's chugging away and so far it's finding the nasties that are quarantined in Norton. My question is: If I now run
Code: | clamscan -vri –remove /mnt/C: |
will Norton throw a fit when he boots back into Win2k?
If anyone has experience of cleaning up a windows box from linux and can give some tips/has a better approach than mine above, I'd be very grateful
|
|
Back to top |
|
Germ Keeper of the BIG STICK

Joined: 30 Apr 2025 Posts: 12452 Location: Planet Earth
|
Posted: Sun Dec 06, 2025 12:42 am Post subject: |
|
|
I think Xeroid has some experience doing that. Hopefully, he will show up soon.
_________________ Laptop: Mandriva 2025 PowerPack - 2.6.33.5-0.2mnb
Desktop: Mandriva 2025 Free - kernel 2.6.33.2-1mib
|
|
Back to top |
|
melloe Ultimate Member

Joined: 20 Mar 2025 Posts: 2262 Location: Southern Illinois
|
Posted: Sun Dec 06, 2025 12:58 am Post subject: |
|
|
Before you boot back into 2K, if he still has the Norton's disk..a recent one. Boot with disk in tray, and boot Norton's CD.. When it asks if you want to scan, say yes. This will scan the HD for badies at a very low level. also. Can't hurt, and often catches ones napping. I suspect Norton's might well be broken or outdated is there are that many badies not in quarantine. Does he have spybot Search and destroy and / or Adaware ..or some such installed? Look for files close to those names which are often badies themselves posing as ad and spybot killers. Nortons often don't see them as redirectors or such. Clam win does a pretty good job against older known threats, but will not do the whole job. in most cases.
If it is not a recent disk, or virus software is outdated, you need to uninstall Nortons ( no small task to get it all out** ), and install a recent virus software. ( most will do a scan before they install ) A good firewall, and some form of ad and spybot protection.
** Downloading and running a few times jv16power tools will usually get most of the Nortons files out. I understand it has been sold and went commercial, but old versions of jv16power tools are still on the net, or it might be worth buying in the worst case. No other reg cleaner comes close to getting out all the Nortons crap left after a supposed "uninstall" It is everywhere. That is what makes it valuable when kept up to date.
AVAST and AVG both have a very good free version of virus sofware if he (she ) cannot aford virus software. But none will be totally effective unless you get all the Nortons crap out. Even a new copy of Nortons. New kids on the block in virus software that seem to work well are K7, Bullguard, and Fsecure. ( I am not saying they are better than some of the better known ones. Just that they worked well. ) For the club, we had a different virus software on each box with two exceptions. But ended up using the firewall with a suite or Zone alarm and one other which name I can't remember. Zone Alarm is a pain now because they want to sell their virus software suite, but does a good job.
_________________ mell0: 1. Kubuntu, XP, Sabayon 2. Mandriva,Mint, Mephis
Thor: 1. VISTA, Fedora 2. Chakra, Debian
Sam:XP, SuSE Zues: win7, SuSE testing
|
|
Back to top |
|
JP Linux Guru

Joined: 07 Jul 2025 Posts: 6670 Location: Central Montana
|
Posted: Sun Dec 06, 2025 6:00 am Post subject: |
|
|
We used TrendMicro Housecalls http://housecall.trendmicro.com/ , for the wife's XP - works real good, as well as Lavasoft Ad Aware (also free) ..... AVG is really good, but as melloe says, you've got to get rid of Norton ..... Norton was into her XP so bad, we had to just backup and reinstall without the Norton to get rid of it! If it were me, I'd try Housecall first, because it's just a very small download (launcher) and it works great ........ one note; try to download the newest each time you go there, as it doesn't automagically update the older one TrendMicro would be my preferred AV for purchase if I were to run WNDOS (which I won't), because it doesn't take over your computer like Norton and McAfee do, (at least it didn't used to).
_________________ Dell Box - Arch Linux
Dell Lappy - DreamLinux 3.5 - Default OS
Mepis 8.0 - Backup
|
|
Back to top |
|
Germ Keeper of the BIG STICK

Joined: 30 Apr 2025 Posts: 12452 Location: Planet Earth
|
Posted: Sun Dec 06, 2025 2:12 pm Post subject: |
|
|
Quote: | ...jv16power tools will usually get most of the Nortons files out. I understand it has been sold and went commercial... |
There is a free version called PowerTools Lite. I had my sis try it and it seemed to work good.
There's one called Easy Cleaner that is still free and does a pretty good job on the registry.
_________________ Laptop: Mandriva 2025 PowerPack - 2.6.33.5-0.2mnb
Desktop: Mandriva 2025 Free - kernel 2.6.33.2-1mib
|
|
Back to top |
|
lynch Moderator

Joined: 15 Nov 2025 Posts: 2659 Location: The Diamond State
|
Posted: Sun Dec 06, 2025 2:34 pm Post subject: |
|
|
I tell my winders friends and customers to use these free utilities:
Avast Free Edition
Malwarebytes
CCleaner
Avast has a pretty good virus/malware scanning engine that runs using little resources. ( I have found AVG's last few releases to be a bit hoggish with the memory).
Malwarebytes is a free spyware remover with updates.
CCleaner scans at startup to rid the drive of the gunk that gets collected by windows over time. Has a nice registry cleaner and application uninstaller also.
I would suggest trying melloe's tip and also try scanning from safe mode. Turn off system restore and delete all save points. If you can get W2K's service pack 4 and install that, you can clean up a whole lot of system files that may have gotten corrupted/overlooked.
servive pack 4
_________________ Mandriva 2025 Spring -2.6.31.12-server-2mnb
PCLinuxOS 2025 -2.6.26.8.tex3
|
|
Back to top |
|
jester Sr. Member

Joined: 19 Apr 2025 Posts: 1166
|
Posted: Sun Dec 06, 2025 4:30 pm Post subject: |
|
|
thanks for the suggestions guys - I'm going to have to leave him to do this for himself as I have to head off
I have to say, I have never seen a PC in this condition before...
_________________ Arch64 :: Funtoo64 :: FreeBSD-8.0 :: OSX-10.4.11 (PPC)
Testing: Fedora12_x86-64 :: Ubuntu-10.04-LTS_x86-64
|
|
Back to top |
|
crouse Site Admin

Joined: 17 Apr 2025 Posts: 11833 Location: Iowa
|
|
Back to top |
|
jester Sr. Member

Joined: 19 Apr 2025 Posts: 1166
|
|
Back to top |
|
crouse Site Admin

Joined: 17 Apr 2025 Posts: 11833 Location: Iowa
|
|
Back to top |
|
Lord.DragonFly.of.Dawn Advanced Member

Joined: 18 Jul 2025 Posts: 607 Location: South Portland, Maine, USA, Earth, Sol System
|
Posted: Tue Dec 08, 2025 2:37 am Post subject: |
|
|
i forget. are those better or worse than the ones where they bring the computer to you and then vanish after implying that they might be greatful for you fixing it but never actually asking you to fix it?
I never can remember. happens to me a couple of times a year too....
of course if you are mean and/or don't like the person. Just sell the computer and tell them later that their cut of the sale price was only $5 because the thing was a total POS. Of course when they complain you can simply explain that since they gifted the computer to you you felt it only fair that they get 10% of the sale price.
note that this is not a good thing to do. you would have to be a very mean person to do such a thing. very mean.
_________________ ArchLinux x86_64 - Custom Built Desktop
ArchLinux x86_64 - Compaq CQ50 Laptop
ArchLinux i686 - Acer Aspire One Netbook
ArchLinux i686 - Dell Presario ze2000 (w/ shattered LCD)
PuppyLinux, CloneZilla, PartedMagic, DBAN - rescue thumbdrives
Windows 7 (x86_64 desktop alternate boot)
|
|
Back to top |
|
VHockey86 Advanced Member

Joined: 12 Dec 2025 Posts: 988 Location: Rochester
|
Posted: Tue Dec 08, 2025 5:46 am Post subject: |
|
|
Interesting stuff, didn't realize those sorts of tools existed.
If anyone ever brought me a problem that couldn't be fixed with some simple freeware tools in Windows I would just recover the data using a live CD and reinstall like Crouse said. I generally found the time to backup + reinstall windows + install drivers / some basic programs quicker than researching what was actually wrong with it, and then never really feeling quite confident that it was indeed "clean".
_________________ Main Desktops : Kubuntu 10.4. ArchLinux 64-bit. Windows7 64-bit. Windows XP 32-bit.
MacBook: OS X Snow Leopard (10.6)
|
|
Back to top |
|
jester Sr. Member

Joined: 19 Apr 2025 Posts: 1166
|
Posted: Tue Dec 08, 2025 11:43 pm Post subject: |
|
|
Well it was entirely unplanned since I'm over in the US on business - 1 week Boston and 1 week Connecticut with the weekend in the middle at his place.
As the weather Saturday was so miserable it put paid to a lot of other things we had planned and so we stayed in and had a few beers which inevitably lead to 'finding out what was wrong with it'.
I actually thought Win2k was much better than the 9x/ME stable - it was the last Windows that I paid for (directly, at least - wife's Vaio has Vista), though I do use XP on the laptop provided by work (no choice, but also not accountable for fixing it).
My friend's real problem is that even if he could reinstall, most of the freeware apps no longer support Win2k, so he's facing the struggle against obsolescence as well as malware (funny how that stuff doesn't go past its sell-by-date...).
I didn't mind helping him, but it was mission impossible in the time and I had and the tools he was willing to use - at the end of the day, I reckon he should buy a new box, grab all his must keep files, install a Ubuntu on that old box along with OpenOffice, scan them with clamav and then transfer over the absolutely must-haves to the new box.
It'd take an epiphany (and not the Gnome browser) for him to switch to linux.
_________________ Arch64 :: Funtoo64 :: FreeBSD-8.0 :: OSX-10.4.11 (PPC)
Testing: Fedora12_x86-64 :: Ubuntu-10.04-LTS_x86-64
|
|
Back to top |
|
melloe Ultimate Member

Joined: 20 Mar 2025 Posts: 2262 Location: Southern Illinois
|
Posted: Wed Dec 09, 2025 2:33 am Post subject: |
|
|
http://www.macecraft.com/download/jv16powertools2009/
This one asks for email address, but I just hit download and got it.
Felt like I was stealing so went back <G><
_________________ mell0: 1. Kubuntu, XP, Sabayon 2. Mandriva,Mint, Mephis
Thor: 1. VISTA, Fedora 2. Chakra, Debian
Sam:XP, SuSE Zues: win7, SuSE testing
|
|
Back to top |
|
Xeroid Site Admin

Joined: 19 Apr 2025 Posts: 6456 Location: Georgia
|
|
Back to top |
|
|