Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me

The Shed is going Social! Join us on FaceBook and Twitter and chime in on the conversation.

Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old May 1st, 2010, 12:53 PM
CallowAdmin CallowAdmin is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2008
Location: CA
Posts: 258 CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 1 Day 7 h 45 m 13 sec
Reputation Power: 55
Virus Quetions

First of all, let me explain the problem: a windows based laptop won't boot in safe mode. It started in normal mode, but when I click on anything, messages about viruses pop-up. It's clearly infected. I can't get into msconfig, services, etc to shut down the virus on start up.

1. If I create a partition on the hard drive and backup my files to that partition, can the virus cross over to that partition and infect them (assuming it's not in the files I am moving).

2. If I bring this laptop to a shop that "repairs virus issues" without a clean install, what exactly do they do? i.e. is there software that removes viruses before the OS boots, etc?

Thanks.

Reply With Quote
  #2  
Old May 1st, 2010, 08:26 PM
hiker's Avatar
hiker hiker is offline
They're coming to take me away
Dev Shed God (5000 - 5499 posts)
 
Join Date: Jan 2005
Location: Florida
Posts: 5,091 hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)  Folding Points: 33832 Folding Title: Starter FolderFolding Points: 33832 Folding Title: Starter Folder
Time spent in forums: 3 Months 2 Weeks 6 Days 21 h 53 m 52 sec
Reputation Power: 5048
Quote:
Originally Posted by CallowAdmin
1. If I create a partition on the hard drive and backup my files to that partition, can the virus cross over to that partition and infect them (assuming it's not in the files I am moving).

My recommendation on this would be to back up the files to its own partition or hard drive, clean the machine (whether via software or complete reinstall) and then scan all the files before putting them back.

Quote:
2. If I bring this laptop to a shop that "repairs virus issues" without a clean install, what exactly do they do? i.e. is there software that removes viruses before the OS boots, etc?

Usually they run various software programs, but depending on how badly infected the machine is, they may recommend completely reinstalling.

If you can't get into Safe Mode, one thing you may want to try (which I do on occasion with various computers I work on), is boot into Windows normally, then quickly open task manager, and start killing processes that you don't need.... (shouldn't be too hard to determine what is unneeded)... Depending on the infection, you may be able to stop the process before it starts doing it's thing allowing you to be able to run scans and such.
__________________
"I don't need to get a life. I'm a gamer. I have lots of lives!"

Reply With Quote
  #3  
Old May 1st, 2010, 10:08 PM
CallowAdmin CallowAdmin is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2008
Location: CA
Posts: 258 CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 1 Day 7 h 45 m 13 sec
Reputation Power: 55
Quote:
Originally Posted by hiker
then quickly open task manager, and start killing processes that you don't need.... (shouldn't be too hard to determine what is unneeded)... Depending on the infection, you may be able to stop the process before it starts doing it's thing allowing you to be able to run scans and such.


Good point.
I did not think of that.
I tried opening msconfig quickly (to shut down processes at startup) but after about ten seconds the virus took control. Shutting down suspicious processes in that time period would probably yield better results.

Reply With Quote
  #4  
Old May 1st, 2010, 11:29 PM
hiker's Avatar
hiker hiker is offline
They're coming to take me away
Dev Shed God (5000 - 5499 posts)
 
Join Date: Jan 2005
Location: Florida
Posts: 5,091 hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)  Folding Points: 33832 Folding Title: Starter FolderFolding Points: 33832 Folding Title: Starter Folder
Time spent in forums: 3 Months 2 Weeks 6 Days 21 h 53 m 52 sec
Reputation Power: 5048
Quote:
Originally Posted by CallowAdmin
Good point.
I did not think of that.
I tried opening msconfig quickly (to shut down processes at startup) but after about ten seconds the virus took control. Shutting down suspicious processes in that time period would probably yield better results.


With msconfig, you usually need to restart for changes to take effect. Going through Task Manager is a better option as you're killing the process upon them starting. If you kill all the processes that are unneeded, you should have the basics running and should, in theory, be able to run msconfig afterwards....

Now.. just wondering... what happens when you try to boot into Safe Mode? Error...? Constant Reboot...?

Reply With Quote
  #5  
Old May 2nd, 2010, 01:37 AM
CallowAdmin CallowAdmin is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2008
Location: CA
Posts: 258 CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 1 Day 7 h 45 m 13 sec
Reputation Power: 55
Quote:
Originally Posted by hiker
With msconfig, you usually need to restart for changes to take effect. Going through Task Manager is a better option as you're killing the process upon them starting. If you kill all the processes that are unneeded, you should have the basics running and should, in theory, be able to run msconfig afterwards....

Now.. just wondering... what happens when you try to boot into Safe Mode? Error...? Constant Reboot...?


safe mode just hangs...it loads the basic drivers for hours and doesn't move. the only thing that actually loads is the full on version of windows in all it's glory.

Reply With Quote
  #6  
Old May 4th, 2010, 01:06 AM
CallowAdmin CallowAdmin is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2008
Location: CA
Posts: 258 CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 1 Day 7 h 45 m 13 sec
Reputation Power: 55
so the virus shuts down the computer when I hit control/alt/delete.

What I was curious about in my first question was if I created a new partition and put a new install of the OS on it would it be safe from the virus or can it cross over? Would a new partition/install be a good solution here to get into the registry etc and make changes needed to remove the virus?

Reply With Quote
  #7  
Old May 4th, 2010, 09:46 AM
CreativeOnline CreativeOnline is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2010
Location: Tampa, FL, USA
Posts: 7 CreativeOnline User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 h 6 m 47 sec
Reputation Power: 0
I want solution for virus which eaten my Address bar.

Reply With Quote
  #8  
Old May 4th, 2010, 10:17 AM
jzd's Avatar
jzd jzd is offline
Contributing User
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Feb 2007
Posts: 1,940 jzd User rank is General 32nd Grade (Above 100000 Reputation Level)jzd User rank is General 32nd Grade (Above 100000 Reputation Level)jzd User rank is General 32nd Grade (Above 100000 Reputation Level)jzd User rank is General 32nd Grade (Above 100000 Reputation Level)jzd User rank is General 32nd Grade (Above 100000 Reputation Level)jzd User rank is General 32nd Grade (Above 100000 Reputation Level)jzd User rank is General 32nd Grade (Above 100000 Reputation Level)jzd User rank is General 32nd Grade (Above 100000 Reputation Level)jzd User rank is General 32nd Grade (Above 100000 Reputation Level)jzd User rank is General 32nd Grade (Above 100000 Reputation Level)jzd User rank is General 32nd Grade (Above 100000 Reputation Level)jzd User rank is General 32nd Grade (Above 100000 Reputation Level)jzd User rank is General 32nd Grade (Above 100000 Reputation Level)jzd User rank is General 32nd Grade (Above 100000 Reputation Level)jzd User rank is General 32nd Grade (Above 100000 Reputation Level)jzd User rank is General 32nd Grade (Above 100000 Reputation Level) 
Time spent in forums: 2 Weeks 1 Day 4 h 7 m 2 sec
Reputation Power: 3116
CreativeOnline:
1. Please don't hijack other people's threads.
2. More than likely you just have your address toolbar unselected for the field is hidden. Mess around with your toolbar settings.

Reply With Quote
  #9  
Old May 4th, 2010, 10:15 PM
hiker's Avatar
hiker hiker is offline
They're coming to take me away
Dev Shed God (5000 - 5499 posts)
 
Join Date: Jan 2005
Location: Florida
Posts: 5,091 hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)  Folding Points: 33832 Folding Title: Starter FolderFolding Points: 33832 Folding Title: Starter Folder
Time spent in forums: 3 Months 2 Weeks 6 Days 21 h 53 m 52 sec
Reputation Power: 5048
Quote:
Originally Posted by CallowAdmin
so the virus shuts down the computer when I hit control/alt/delete.

What I was curious about in my first question was if I created a new partition and put a new install of the OS on it would it be safe from the virus or can it cross over? Would a new partition/install be a good solution here to get into the registry etc and make changes needed to remove the virus?


A virus can go from one partition to another... yes... but it depends on the virus really as to what would actually happen.

Also, if you were to reinstall windows (on a new partition), then the registry which was created for the new windows install wouldn't have info about the virus as that would be on the old OS installation.

Reply With Quote
  #10  
Old May 22nd, 2010, 07:38 AM
CreativeOnline CreativeOnline is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2010
Location: Tampa, FL, USA
Posts: 7 CreativeOnline User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 h 6 m 47 sec
Reputation Power: 0
Quote:
Originally Posted by jzd
CreativeOnline:
1. Please don't hijack other people's threads.
2. More than likely you just have your address toolbar unselected for the field is hidden. Mess around with your toolbar settings.
Really I have this question, I keep silent. OK?

Reply With Quote
  #11  
Old May 22nd, 2010, 11:24 AM
CallowAdmin CallowAdmin is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2008
Location: CA
Posts: 258 CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level)CallowAdmin User rank is Sergeant Major (2000 - 5000 Reputation Level) 
Time spent in forums: 1 Day 7 h 45 m 13 sec
Reputation Power: 55
Quote:
Originally Posted by hiker
A virus can go from one partition to another... yes... but it depends on the virus really as to what would actually happen.

Also, if you were to reinstall windows (on a new partition), then the registry which was created for the new windows install wouldn't have info about the virus as that would be on the old OS installation.


Thanks, Hiker.

What would you do given the scenario that you can't log into the computer to do a backup, can't boot into safe mode, can't get into msconfig to shutdown exes, etc. Basically, you can't do anything. Is there any solution other than losing the data and doing a complete reformat?

If I create a new volume up and put a clean OS on it, can I "cross over" and backup files from the other partition? Either in the GUI or DOS would be fine. I'm just not sure how that works since I never had two installs on one machine.

Reply With Quote
  #12  
Old May 22nd, 2010, 07:21 PM
Doug G Doug G is offline
Grumpier Old Moderator
Dev Shed God 19th Plane (14000 - 14499 posts)
 
Join Date: Jun 2003
Posts: 14,237 Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level) 
Time spent in forums: 1 Month 4 Weeks 14 h 43 m 55 sec
Reputation Power: 4445
I usually use a linux live cd to backup data from an unbootable windows system.

Also, you can boot from a clean windows installation and access the bad partitions, I would recommend you pull the bad drive, install a new drive, install windows, add the bad drive back as a 2nd disk.
__________________
======
Doug G
======
It is a truism of American politics that no man who can win an election deserves to. --Trevanian, from the novel Shibumi

Reply With Quote
  #13  
Old May 24th, 2010, 03:38 PM
hiker's Avatar
hiker hiker is offline
They're coming to take me away
Dev Shed God (5000 - 5499 posts)
 
Join Date: Jan 2005
Location: Florida
Posts: 5,091 hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)hiker User rank is General 61st Grade (Above 100000 Reputation Level)  Folding Points: 33832 Folding Title: Starter FolderFolding Points: 33832 Folding Title: Starter Folder
Time spent in forums: 3 Months 2 Weeks 6 Days 21 h 53 m 52 sec
Reputation Power: 5048
Quote:
Originally Posted by CallowAdmin
Thanks, Hiker.

What would you do given the scenario that you can't log into the computer to do a backup, can't boot into safe mode, can't get into msconfig to shutdown exes, etc. Basically, you can't do anything. Is there any solution other than losing the data and doing a complete reformat?

If I create a new volume up and put a clean OS on it, can I "cross over" and backup files from the other partition? Either in the GUI or DOS would be fine. I'm just not sure how that works since I never had two installs on one machine.


I, personally, would pull the hard drive out, place it in a 2.5" external enclosure, and copy the files I need to another hard drive (data files only while performing a scan on all of the files). Then completely reformat and reinstall after reinstalling the hard drive back into the laptop.

Or, as Doug mentioned, you can use a linux live cd or get a new hard drive altogether.

Reply With Quote
  #14  
Old May 27th, 2010, 05:31 AM
_Titan_ _Titan_ is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2010
Location: Earth
Posts: 48 _Titan_ Negative: is most likely a SPAMMER and a traitor to the cause. 
Time spent in forums: 15 h 22 m 2 sec
Reputation Power: 0
i agree with Doug G. You can use Live CD and solve your problem.

Reply With Quote
  #15  
Old May 30th, 2010, 01:38 AM
cwsmith92 cwsmith92 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2010
Posts: 7 cwsmith92 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 30 m 53 sec
Reputation Power: 0
Quote:
Originally Posted by CreativeOnline
I want solution for virus which eaten my Address bar.


The virus I have redirects me to multiple sites sometimes when I click on a link. Is that what you are talking about?

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > Virus Quetions

Developer Shed Advertisers and Affiliates



Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 


Powered by: vBulletin Version 3.0.5
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.

© 2003-2013 by Developer Shed. All rights reserved. DS Cluster - Follow our Sitemap