NationStates Jolt Archive


Cleaning a computer [Split thread]

Sanctaphrax
14-05-2005, 11:10
Ahhh! I see! Well, that's a horse of a different color. If I'd known that this was part of the problem and was making a difference in the matter, I'd have gladly split the topic for you. Just saying that the decision is unfair makes little sense, but if a virus is causing problems, then that's a little more understandable. :) Just keep in mind that I don't want to accomodate your virus forever. :p

Good Luck getting your computer cleaned.

--The Modified Democratic States of CogitationThanks Cog, even though I have no idea how I'm meant to clean it when anti-virus/anti-spyware programs refuse to work. :( I don't want to reformat because I have lots of stuff on the computer I don't want to get rid of. In other words, I'm screwed :p
Lets just hope the virus has a change of heart and leaves.

[Moderator Edit - Cogitation] This was split from here (http://www.forums.jolt.co.uk/showthread.php?t=418262). I have inserted a quote of the post Sanctaphrax was responding to for context.[/modedit]
Cogitation
14-05-2005, 16:59
Well, let's think about it for a moment. ;)

Can you open the important files and read them? Will copy-and-paste work? You can obviously post to forums. Find an offsite forum to copy the text over to (viruses should not be capable of tagging along in this manner), reformat your computer, and then copy everything back.

Can you copy your files to an external disk? Copy them off of your computer, reformat your computer, install anti-virus software, then scan the external disk.

--The Democratic States of Cogitation
Enlightened Humanity
14-05-2005, 17:07
you could download a linux live cd, such us ubuntu (http://ubuntulinux.com/) or knoppix (http://www.knoppix.org/), use that to copy off the files you need, then reformat. Be aware though that the files may have been infected and need VERY careful treatment when you return them to your pc.

If you can't download it, someone could post it to you perhaps?
Lord-General Drache
15-05-2005, 00:39
Have you tried booting into safe mode, and running your antivirus? Also, there's a program called Hijack This! which lets you end/delete processes and data streams that are running, which makes it a LOT easier to get virii off your computer. However, be VERY CERTAIN of what you stop/delete. If you're in doubt, ask someone knowledgable.

http://www.spywareinfo.com/~merijn/downloads.html
Cogitation
15-05-2005, 05:55
If he's using Windows, then he can press Control-Alternate-Delete, bring up the Task Manager, and use the Task Manager to kill the processes directly. Can't he?

(...of course, given all those cryptic names for the processes, it'd be a pain to figure out which one was which....)

--The Democratic States of Cogitation
Lord-General Drache
15-05-2005, 06:07
Yes, but the problem is, you can't always kill a process. Hijack This overrides that and allows you to shut ANYTHING off. Some virii will make it so you can't shut down the process normally, but Hijack This will allow you to do just that, which is why I love it.
Sanctaphrax
15-05-2005, 06:12
If he's using Windows, then he can press Control-Alternate-Delete, bring up the Task Manager, and use the Task Manager to kill the processes directly. Can't he?
(...of course, given all those cryptic names for the processes, it'd be a pain to figure out which one was which....)
--The Democratic States of Cogitation
Its pretty simple, a majority start with <name>. Trojan, for example, Startpage.Trojan.

As for ctrl+alt+delete, I unfortunately can't, because it'll only shut them down once, and I'll need to keep shutting them down each time I log on, and besides, only one program actually shows on the ctrl+alt+delete screen, some toolbar thing.
Tranquilis
15-05-2005, 07:34
If you have a Windows XP disc on hand, you could always use BartPE.
http://www.nu2.nu/pebuilder/
Its a bootable windows environment that lets you read and write to the NTFS partitions. Get the Pebuilder, specify the location of the i386 folder, and you should be good to go in generating your disc. You have to put the plugins you want into the correct folders though, like the antivirus programs, which is probably what you need.
TrendMicro, Sophos, McAfee, etc, all have standalone antivirus tools. You just download the executables and the new definitions in whatever format they come on, and I think BartPE lets you place them all as plugins (its easy...the help files will tell you).
However...not everybody has Windows XP full version cds, so you could always run antivirus utilities from Safe Mode.
ftp://ftp.nai.com/CommonUpdater/
Just get the lastest sdat file and extract it. Run it from commandline in safe mode (F8 during startup). Let the command line scanner do its work in safe mode.

Always go into safe mode/bootable cd when trying to fix viruses. If it lies dormant it will not be running in the background and you will not get those file in use messages. If you can boot from a BartPE disc, then it would be easiest, however I don't know if you have a copy of a full version of Windows XP. Hope this helps.
Cogitation
15-05-2005, 14:23
Its pretty simple, a majority start with <name>. Trojan, for example, Startpage.Trojan.

As for ctrl+alt+delete, I unfortunately can't, because it'll only shut them down once, and I'll need to keep shutting them down each time I log on, and besides, only one program actually shows on the ctrl+alt+delete screen, some toolbar thing.Well, these things are preventing you from saving your files, right? You only need them shut down once so that you can copy all the important stuff off.

I'm not on my office PC right now, so I don't remember the details. However, if I remember correctly, there are three tabs in the Task Manager. The applications tab, the middle tab (I think it's "Processes"), and the Performance tab. The middle tab, when displayed, has the option of showing you all sorts of technical information. The most obvious thing to look for is any process that's eating up lots of CPU time for no apparent reason.

--The Democratic States of Cogitation
"Think about it for a moment."
Sanctaphrax
15-05-2005, 14:52
Windows TaskManager has encountered a problem and needs to close. We are sorry for the inconvenience.


I didn't know *that* could happen :confused:
Takuma
15-05-2005, 15:06
Thanks Cog, even though I have no idea how I'm meant to clean it when anti-virus/anti-spyware programs refuse to work. :( I don't want to reformat because I have lots of stuff on the computer I don't want to get rid of. In other words, I'm screwed :p
Lets just hope the virus has a change of heart and leaves.

[Moderator Edit - Cogitation] This was split from here (http://www.forums.jolt.co.uk/showthread.php?t=418262). I have inserted a quote of the post Sanctaphrax was responding to for context.[/modedit]

Well, I'm not sure if you have the means to do this, but I did it when I got massively virused.

Basically, you have three options with my plan:
1. A CD (preferably DVD) burner. This is most likely out of the question for you, correct?
2. A computer connected over a network, or that could be very quickly.
3. A partition management program.

For (1), simply copy everything you need to save to a DVD/CD then format.

For (2), hook the computers over a network (Make sure you have your antivirus software working on the second computer correctly before you connect them!) and copy the files. Then format your main computer and copy the stuff back.

For (3), first make sure you have a couple GB of free space. Make a new, non-bootable partition (i.e. not primary), copy all your files to it then reformat the main partiton (the one with Windows).

To put it simply, if you have a massive virus/spyware/trojan infection, it's much easier to backup your data and format then it is to go through and clean everything.

If these don't work and don't apply, then I hope something works for you!

Note: if you need instructions or a good Partition modifier, please feel free to e-mail me.