bmdaustin
Max Output Level: -68 dBFS
- Total Posts : 1114
- Joined: 2004/01/11 21:56:51
- Status: offline
How screwed am I?
So, I've managed to set loose a Trojan on the system HD of my desktop. The "beauty" of this particular virus is that it blocks all executables from running so System Restore isn't an option. I've removed the drive, placed it in a caddy and plugged it into my laptop where I'm running Anti-Malware and AVG Anti-virus with no success as of yet. My questions are: 1) Will installing the W8 Upgrade package solve my problems? It runs from the DVD drive and bypasses the OS, correct? 2) Is the Upgrade package (as opposed to a clean full version install) successful, generally, or will it scramble things further? 3) This is a Dell Inspiron, which has been flawless up until now. Does Dell, or Microsoft, have a way to repair my machine remotely? Is it repairable remotely? I realize some of these question are difficult or impossible to answer, but I'm open to, and appreciate, all attempts on your part. Thanks.
|
fireberd
Max Output Level: -38 dBFS
- Total Posts : 3704
- Joined: 2008/02/25 14:14:28
- Location: Inverness, FL
- Status: offline
Re:How screwed am I?
2013/05/08 07:01:02
(permalink)
If there is no way of removing it with security software the only option is to do a complete "clean" reinstall which involves reformatting the hard drive and reinstalling everything. Since this is a Dell, and if it still has the original OS and hard drive, the Dell "PC Restore" will restore it to the original factory condition and get rid of it, but this is basically a "clean" reinstall. F8 at power on will access the Dell recovery partition. This will erase the hard drive so all data and installed programs will be lost. But, before you do that have you tried starting Windows in safe mode and running Malwarebytes malware software? I've had success in safe mode for removing garbage that could not be removed in a "normal" Windows enviroment a couple of times. I wouldn't connect the drive to another PC, there is a very good possibility of it infecting the other PC, even with security software. Installing the Win 8 upgrade will not help, the virus/malware will still be there. As previously noted only a "clean" install will get rid of it. There are forums that may be able to help. If you are running Windows 7, post the problem on the Windows 7 forum and maybe the security guru's there can get it resolved. http://www.sevenforums.com/
"GCSG Productions" Franklin D-10 Pedal Steel Guitar (primary instrument). Nashville Telecaster, Bass, etc. ASUS ROG Maximus VIII Hero M/B, i7 6700K CPU, 16GB Ram, SSD and conventional hard drives, Win 10 Pro and Win 10 Pro Insider Pre-Release Sonar Platinum/CbB. MOTU 896MK3 Hybrid, Tranzport, X-Touch, JBL LSR308 Monitors, Ozone 5, Studio One 4.1 ISRC Registered Member of Nashville based R.O.P.E. Assn.
|
Jim Roseberry
Max Output Level: 0 dBFS
- Total Posts : 9871
- Joined: 2004/03/23 11:34:51
- Location: Ohio
- Status: offline
Re:How screwed am I?
2013/05/08 11:17:48
(permalink)
Hi Paul, As Fireberd mentioned, you need to do a clean install. Once you're back up and running... take the time to create a backup image file (using True Image or similar). That'll protect you moving into the future. If anything like this happens... you just reload the backup image file... and you're back in business.
|
slartabartfast
Max Output Level: -22.5 dBFS
- Total Posts : 5289
- Joined: 2005/10/30 01:38:34
- Status: offline
Re:How screwed am I?
2013/05/08 14:36:37
(permalink)
You say you have a trojan that will not let you run windows executables. How did you determine that without access to a windows antivirus program? If your computer is just not running, there are a lot of other potential causes. But assuming you are correct, the typical way of cleaning in this circumstance is to boot from a live linux rescue disk that has has the capability to remove windows viruses. There are quite a few of those. One of the best reviewed is from Kaspersky http://support.kaspersky.com/viruses/rescuedisk?ClickID=arrw5pklvzztnp5tvpyk5k9onz5z9zr0srwr Attaching the drive to a different computer, as firebird says, has the potential to spread the infection and presumes that the malware does not have copies on other drives or partitions in the infected computer that can re-seed the drive when it is returned to its mother machine. If you have data on the drive that you can not copy off due to the affect of the infection on windows, a live linux rescue disk may make this possible. Use the other computer to download and burn the rescue disk not to clean the infected hard drive directly. A clean installation is the surest solution. I am not sure how the restore partition in a Dell is armored against infection, but usually re-installation is best done from a known good installation disk. Again, if there are other drives on the computer, they need to be cleaned or the files moved and scanned and the drives formatted before you can consider the installation cured. The best cleaning would be to completely bitwise re-write the drive(s) with the particular hard drive manufacturer's wipe utility, or less certainly with Darik's Nuke and Boot or similar but I assume that would kill your restore partition.
|
jjthomas
Max Output Level: -89 dBFS
- Total Posts : 94
- Joined: 2005/11/02 19:01:20
- Status: offline
Re:How screwed am I?
2013/05/08 17:39:19
(permalink)
|
bmdaustin
Max Output Level: -68 dBFS
- Total Posts : 1114
- Joined: 2004/01/11 21:56:51
- Status: offline
Re:How screwed am I?
2013/05/08 18:16:53
(permalink)
Lots of good and useful info everyone - thanks! The Anti-Malware software identified four Trojans on the drive and removed them. AGV confirmed there were no other issues. However, the virus did leave behind some permanent damage that I can't fix so I will be trying the Dell restore approach. To answer some questions - I found out I had a virus when the AVG window popped up and I misfired on the mouse and accidentally clicked Ignore instead of Delete the virus (or whatever the exact terminology is). Most of the icons on the Desktop disappeared, leaving the default symbols in their place. Double clicking on one of these would briefly open (appears as a flicker) a DOS text box that said something about an error in the command line. That's all I could make out, even with repeated viewings. Interestingly enough, clicking on a data file, I can open the associated app. Click on a doc file and Word will open, for example. I was even able to work on a piece of music in Sibelius, although I can't print. I can Export to PDF however. I've made plenty of mistakes in this process, but I've been able to copy everything (except the Windows directory) from the System drive to a brand new HD so all my data is backed up. I'll reset with the Dell partition and move pertinent data back over. I've also picked up a copy of Norton Ghost that will be installed post haste to set up a back up routine. The good news is that nothing has been lost except time, and that's not totally crucial this week, thank goodness.
|
bmdaustin
Max Output Level: -68 dBFS
- Total Posts : 1114
- Joined: 2004/01/11 21:56:51
- Status: offline
Re:How screwed am I?
2013/05/08 19:43:58
(permalink)
Hey Fireberd - F8 doesn't seem to do anything at all. The system boots straight to Windows. Is there any other way I can get to the Dell partition? Slart________ - I downloaded the Kaspersky ISO but all that gives me is another virus scan. There was mention of repair capability but I didn't see it anywhere. Is there actual OS repair capability or is that a euphemism for having removed the threats? Is there such a thing as W7 OS Repair?
|
bmdaustin
Max Output Level: -68 dBFS
- Total Posts : 1114
- Joined: 2004/01/11 21:56:51
- Status: offline
Re:How screwed am I?
2013/05/08 20:40:30
(permalink)
Fireberd - pilot error on my part. I was able to get in, but no joy once I was there. All archived Restore options were defunkt. No System Restore and no Factory Default. A phone call to Dell Support shed light on the likely culprit. The file association table has apparently been corrupted. Dell is sending a Restore disk.
|
fireberd
Max Output Level: -38 dBFS
- Total Posts : 3704
- Joined: 2008/02/25 14:14:28
- Location: Inverness, FL
- Status: offline
Re:How screwed am I?
2013/05/09 06:35:32
(permalink)
Too bad. The Dell restore will only work if the hard drive's boot record has not been changed. I used to do a lot of forum support on the Dell user forums. I no longer have a Dell PC so I left the forums after 10 years. If you need help getting it going after you get the disc from Dell, the Dell forums are a good source since there are those there familiar with Dell's both hardware and software. http://en.community.dell.com/
"GCSG Productions" Franklin D-10 Pedal Steel Guitar (primary instrument). Nashville Telecaster, Bass, etc. ASUS ROG Maximus VIII Hero M/B, i7 6700K CPU, 16GB Ram, SSD and conventional hard drives, Win 10 Pro and Win 10 Pro Insider Pre-Release Sonar Platinum/CbB. MOTU 896MK3 Hybrid, Tranzport, X-Touch, JBL LSR308 Monitors, Ozone 5, Studio One 4.1 ISRC Registered Member of Nashville based R.O.P.E. Assn.
|
slartabartfast
Max Output Level: -22.5 dBFS
- Total Posts : 5289
- Joined: 2005/10/30 01:38:34
- Status: offline
Re:How screwed am I?
2013/05/09 14:19:58
(permalink)
Is there such a thing as W7 OS Repair? There is, but it is on the W7 installation disk. If you have a restore partition on a Dell, it is likely you did not get a full DVD with the machine.
|