Fedora Linux Support Community & Resources Center
Sections ›› Home | Forums | Guidelines | Forum Help | Fedora FAQ | Fedora News 

Go Back   FedoraForum.org > Fedora Support > General Support

General Support Fedora general support. Ask questions here that do not belong in any other forum.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 2009-11-03, 01:44 PM CST
Pyxel Studio Offline
Registered User
 
Join Date: Aug 2009
Posts: 9
windows_vistafirefox
how can i remove a virus

Hi all, i have done some research and i can't seem to find a very good
tutorial or help on this problem, i have a dual boot pc, windows vista and
fedora 11, i want to remove some virus that i have on windows and also
on a portable hard drive, can some one tell me step by step on how to do
this.
Reply With Quote
  #2  
Old 2009-11-03, 02:02 PM CST
Iron_Mike's Avatar
Iron_Mike Offline
Registered User
 
Join Date: Jul 2005
Location: Bora Bora, French Polynesia
Posts: 3,311
windows_vistaie
How do you know you have a virus? The program that identified the virus should be able to remove it.
Reply With Quote
  #3  
Old 2009-11-03, 02:30 PM CST
Dies Offline
Registered User
 
Join Date: Oct 2006
Posts: 3,948
linuxubuntufirefox
Sure.

Step 1 - Delete any and all files related to virus
Step 2 - Reverse any and all changes this virus may have made to the system

There you have it, a step by step as vague and as valid as your question.
Reply With Quote
  #4  
Old 2009-11-03, 02:41 PM CST
badger_fruit Offline
Registered User
 
Join Date: Nov 2008
Posts: 45
linuxfedorafirefox
Quote:
Originally Posted by Pyxel Studio View Post
i want to remove some virus that i have on windows and also
on a portable hard drive, can some one tell me step by step on how to do
this.
This is not a windows forum - although people here use it at some point, it's totally different.
It's like me posting in a Ferrari forum about a problem about a problem I have with a Vauxhall just because I drove a Ferrari once.

Virus removal is a tricky process, having done it myself on a friend's windows XP machine.
All I can advise is you:-

Disconnect from the internet (remove LAN/Network cable)
Run an Anti-virus program from safe mode (assuming Vista has a safe-mode).
Plug in the portable drive and scan that too. IIRC safe-mode should disable auto-run of inserted devices.

But seriously, ditch Vista and replace with Win7 if you really want/need Windows - get protection BEFORE you go online though
Reply With Quote
  #5  
Old 2009-11-03, 02:48 PM CST
bob's Avatar
bob Offline
Administrator
 
Join Date: Jul 2004
Location: Colton, NY; Junction of Heaven & Earth.
Age: 64
Posts: 16,497
linuxfedorafirefox
Here's the best method that I've had for my Windows friends. I personally run this in Safe Mode to avoid having the viruses load any more than absolutely necessary at start-up.

The top three links are to the tools and the instructions follow:

Sysclean: http://www.trendmicro.com/download/dcs.asp
LPT Virus Pattern files: http://www.trendmicro.com/download/viruspattern.asp
Spyware Pattern files: http://www.trendmicro.com/download/spywarepattern.asp


I. Description

This self-extracting archive is a stand-alone fix package that
incorporates the Trend Micro VSAPI Malware and Spyware scanning engines
as well as the Trend Micro Damage Cleanup Engine and Template.

This tool supports the following features:

o Terminate all detected malware/spyware instances in memory
o Remove malware/spyware registry entries
o Remove malware/spyware entries from system files
o Scan for and delete all detected malware/spyware copies in all local
drives

II. File List

o sysclean.com - the main executable module
o readme.txt - this file
o lpt$vpn.XXX - malware pattern file (see Requirements)
o ssapiptn.da5 - spyware pattern file (see Requirements)

III. Requirements

1. Download the latest versions of the following pattern files:

lpt$vpn.XXX in ZIP format as lptXXX.ZIP

from the following location:
<http://www.trendmicro.com/download/viruspattern.asp>

ssapiptn.da5 in ZIP format as ssapiptnXXX.ZIP

from the following location:
<http://www.trendmicro.com/download/spywarepattern.asp>

These files must be saved in the same folder where you run
this fix package.

2. This tool is designed to run under Windows NT/2000/XP/2003/VISTA 32-bit.

For users running Windows NT 4.0, you need to copy the file, PSAPI.DLL,
to the Windows system directory, which is usually C:\WINNT\system32.
You can find the file in the Windows NT 4.0 Setup CD at the
following locations:
\Support\Debug\i386\PSAPI.DLL

3. The Trend Micro Spyware Engine only supports Windows 2000/XP/2003/VISTA 32-bit
systems. The spyware scan feature is disabled in lower versions of
the Microsoft operating systems.

IV. How to Use
Performing System Scan and Cleanup

1. Create a temporary folder and copy SYSCLEAN.COM into this folder.

NOTE: This temporary folder should be created on a local or mapped drive.

2. Download latest malware and spyware pattern files.
Extract the downloaded ZIP pattern files into the created folder.

3. Close all applications running on your system, including any
antivirus software.

4. Run the executable file, SYSCLEAN.COM, by either:

a. Double-clicking the tool in Windows Explorer.
b. Executing it via command prompt using syntax based on the
aforementioned parameters.

5. Enable any antivirus software that is installed on your system and
perform a manual scan.

NOTE: This fix tool generates the log file, SYSCLEAN.LOG, in its
current folder.



Good luck with it.
__________________
Linux & Beer - That TOTALLY Computes!
Registered Linux User #362651

Don't forget to comment when your problem is solved - others will be searching for solutions too!
Reply With Quote
  #6  
Old 2009-11-03, 02:52 PM CST
Dies Offline
Registered User
 
Join Date: Oct 2006
Posts: 3,948
linuxubuntufirefox
Wow!
Bob, so you really just keep that info handy like that?

You must have some really dopey "Windows friends".
Reply With Quote
  #7  
Old 2009-11-03, 04:01 PM CST
bob's Avatar
bob Offline
Administrator
 
Join Date: Jul 2004
Location: Colton, NY; Junction of Heaven & Earth.
Age: 64
Posts: 16,497
linuxfedorafirefox
They are spread all across the east coast, so I sometimes have to email them the info. This is all copy/paste from Trend Micro's website, btw.

The nice thing with it is that there's an anti-virus tool, but also an anti-spyware tool involved, since most of the crapola today is likely spyware-related. Attack it with this, whatever virus tool your protection has provided, Spybot and Ad-Aware and you've got at least a good chance of success.

However, these days the attacks are much tougher to battle. My belief is that Win7 is a serious necessity if you skipped Vista.
__________________
Linux & Beer - That TOTALLY Computes!
Registered Linux User #362651

Don't forget to comment when your problem is solved - others will be searching for solutions too!
Reply With Quote
  #8  
Old 2009-11-03, 04:12 PM CST
JN4OldSchool Offline
"Sean The Terrible" -- The forum Vista rep
 
Join Date: Nov 2005
Posts: 8,727
windows_vistafirefox
Quote:
Originally Posted by bob View Post
They are spread all across the east coast, so I sometimes have to email them the info. This is all copy/paste from Trend Micro's website, btw.

The nice thing with it is that there's an anti-virus tool, but also an anti-spyware tool involved, since most of the crapola today is likely spyware-related. Attack it with this, whatever virus tool your protection has provided, Spybot and Ad-Aware and you've got at least a good chance of success.

However, these days the attacks are much tougher to battle. My belief is that Win7 is a serious necessity if you skipped Vista.
I would agree. It is too bad Vista got off to such a rocky start because the common advice/willingness to hang on to XP is actually a very bad policy.

I did note that the OP says it is Vista that has the virus. My advice would be once you get it cleaned up to find out what you did wrong so it will not happen again. If you do not install it you will not get infected.
Reply With Quote
  #9  
Old 2009-11-03, 04:51 PM CST
Dies Offline
Registered User
 
Join Date: Oct 2006
Posts: 3,948
linuxubuntufirefox
Quote:
Originally Posted by JN4OldSchool View Post
...
If you do not install it you will not get infected.
Not entirely true if you're using Internet Explorer.

Playing with Win7, if I hadn't had the free Microsoft Security Essentials installed, this machine would've already been infected with something. Amazingly enough all the times that a 'drive-by' was tried, they all seem to be attempts to exploit holes in Adobe products.

Oh, for anyone who doesn't already have anti-virus or who's looking for a different one, I prefer this since it seems to not be a hog like most others

http://www.microsoft.com/security_essentials/
Reply With Quote
  #10  
Old 2009-11-03, 04:57 PM CST
kyryder Offline
Registered User
 
Join Date: Mar 2009
Location: /home/In_my_Head
Posts: 313
linuxopera
I have had some success with clamav from a Fedora live cd to remove viruses. The --remove switch has worked for all but one thing that was easily deleted with BCwipe.
Reply With Quote
  #11  
Old 2009-11-03, 04:58 PM CST
bob's Avatar
bob Offline
Administrator
 
Join Date: Jul 2004
Location: Colton, NY; Junction of Heaven & Earth.
Age: 64
Posts: 16,497
linuxfedorafirefox
My oh my, is MS finally giving anti-virus/anti-spam protection without charge? It's about time, IMHO.
__________________
Linux & Beer - That TOTALLY Computes!
Registered Linux User #362651

Don't forget to comment when your problem is solved - others will be searching for solutions too!
Reply With Quote
  #12  
Old 2009-11-03, 05:24 PM CST
JN4OldSchool Offline
"Sean The Terrible" -- The forum Vista rep
 
Join Date: Nov 2005
Posts: 8,727
windows_vistafirefox
I hate IE. Never use it.
Reply With Quote
  #13  
Old 2009-11-03, 05:31 PM CST
stevea's Avatar
stevea Online
Registered User
 
Join Date: Apr 2006
Location: Ohio, USA
Posts: 4,611
linuxfedorafirefox
Want to remove the viruses - find the windows partition and clean it ...

for dev in $(fdisk -l | grep -i ntfs | cut -d' ' -f1) ; do dd if=/dev/zero of=$dev; done



Noobs - DON'T do the above - it's a joke.
__________________
Nothing is so unbelievable that oratory cannot make it acceptable - Cicero

Last edited by stevea; 2009-11-03 at 05:34 PM CST.
Reply With Quote
  #14  
Old 2009-11-04, 10:48 AM CST
GreyWizzard's Avatar
GreyWizzard Offline
Registered User
 
Join Date: May 2005
Location: Oklahoma City, Oklahoma USA
Age: 39
Posts: 305
linuxfedorafirefox
Quote:
Originally Posted by stevea View Post
Want to remove the viruses - find the windows partition and clean it ...

for dev in $(fdisk -l | grep -i ntfs | cut -d' ' -f1) ; do dd if=/dev/zero of=$dev; done



Noobs - DON'T do the above - it's a joke.
OMG!! What happened to my Windoze drive?!?!?

Stevea, you got me into this. How do I get it all back now???

Reply With Quote
  #15  
Old 2009-11-04, 10:51 AM CST
stevea's Avatar
stevea Online
Registered User
 
Join Date: Apr 2006
Location: Ohio, USA
Posts: 4,611
linuxfedorafirefox
Quote:
Originally Posted by GreyWizzard View Post
OMG!! What happened to my Windoze drive?!?!?

Stevea, you got me into this. How do I get it all back now???

Life is a one way trip GreyWizzard. You can never go /home again.
Nor C:\System\Administrator\..\Desktop either
__________________
Nothing is so unbelievable that oratory cannot make it acceptable - Cicero
Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
is it virus? funtomas Security 6 2006-12-20 06:20 AM CST
how to remove icons form main menu while the remove item is grayed out (whoami = root alphonsebrown Software 4 2005-03-24 04:34 PM CST
Request to add a add/remove language in add/remove packages GUI Wong Kwok-hon gmane.linux.redhat.fedora.general 0 2005-02-02 03:13 PM CST
new virus? Dave Stevens gmane.linux.redhat.fedora.general 1 2004-10-13 01:12 PM CDT
New virus? Richard Schmitt gmane.linux.redhat.fedora.general 1 2004-10-13 12:57 PM CDT

Automatic Translations (Powered by Powered by Google):
Afrikaans Albanian Arabic Belarusian Bulgarian Catalan Chinese Croatian Czech Danish Dutch English Estonian Filipino Finnish French Galician German Greek Hebrew Hindi Hungarian Icelandic Indonesian Italian Japanese Korean Latvian Lithuanian Macedonian Malay Maltese Norwegian Persian Polish Portuguese Romanian Russian Serbian Slovak Slovenian Spanish Swahili Swedish Taiwanese Thai Turkish Ukrainian Vietnamese Yiddish

All times are GMT -7. The time now is 06:46 AM CST.

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
Hosting provided by ThePlanet



All trademarks, and forum posts in this site are property of their respective owner(s).

FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact | Founding Members
Designed By Ewdison Then | Powered by vBulletin ©2000-2009, Jelsoft Enterprises Ltd.
FedoraForum is Powered by Open Source Projects and Products
Thanks to NLP-er enjoy automatic translations (vBET)