Results 1 to 10 of 10

Thread: Using Linux to remove spyware from Windows partitions.

  1. #1
    Junior Member
    Join Date
    Oct 2004
    Location
    Chesterfield, VA
    Posts
    3

    Using Linux to remove spyware from Windows partitions.

    Has anybody seen any software that would run under the Linux/Knoppix system that could search within a Windows partition for spyware/adware and other malware. I would like it to be able to resolve Windows registry entries as well as the executable files and directories.
    I am also looking for alternatives to virus detection other than ClamAV to remove viruses in a like fashion.
    On a slightly different note, I would also like to remaster Knoppix Insert distro to include the above programs, but have never done a remaster before, can anyone point me towards a good tutorial to do this?

    Thanks,
    Don.

  2. #2
    Senior Member registered user
    Join Date
    Nov 2002
    Posts
    1,353
    You'll probably have a hard time getting advice from most Linux users on this topic simply because spyware isn't a problem under Linux. If you can't use regular Windows spyware removal tools (like Adaware and Spybot) because your Windows machine won't boot, you "might" be able to get these tools to run using Wine. This might be a totally worthless suggestion however. It's the only thing I can think of.

  3. #3
    Junior Member
    Join Date
    Oct 2004
    Location
    Chesterfield, VA
    Posts
    3
    I thought it would be a good thing to use Linux to fix a Windows system. The Windows systems are getting so mucked up they cant even run a remover program anymore.
    Ergo, good PR for the general public about Linux.

  4. #4
    Senior Member registered user
    Join Date
    Feb 2004
    Posts
    949
    Really? I have great success with ad-aware. If I can't delete it normally, i'll boot into safe mode and that fixes it.

    *On topic*
    I'll have to agree with above, the best thing you can try is running them with wine. I would think that they would work.

  5. #5
    Senior Member registered user
    Join Date
    Dec 2003
    Location
    Salt Lake City, UT, U.S.A.
    Posts
    1,338
    Before "getting out" of Windows, I found some excellent "free-ware" for windows, they work great, and either they are "free completely", or you can get a "free version" that wants you to buy the "buy" version, but still doesnt lock up after a "trial" period...

    Spy-Ware -=- Spybot Search and Destroy - free-ware...

    Anti-Virus -=- AVast -=- "Home" version is free-ware, but always tells you that "if you bought the real version, you'd get xxxxxxxx features...". It doesnt lock up or anything, it just advertises for its "paid" version....

    Spybot is excellent, it has "ripped out" tons of junk that gets "added" into IE all the time... Nice thing is, both run "native" in Windows...

  6. #6
    Junior Member
    Join Date
    Oct 2004
    Location
    Chesterfield, VA
    Posts
    3
    Well thanks for the tips, I have been using Ad-aware, Spybot-SD, AVG, F-Prot, Symantec and on and on.. . I do this for a living and all of the spyware, viruses, backdoors, trojans etc have rendered many Windows systems to nothing more than very expensive paper weights. So I have been trying to find new and better ways to clean and fix those windows partitions.

    I have had some luck with the following; Running taget machine with Knoppix 3.6 and Captive-NTFS and Samba. This allows me to network to the target system and run AVG and Ad-Aware on it. But the captive-ntfs stuff is giving me fits about allowing the drive to be Read/Write. (yep I have heard about the writing to ntfs disk problems too)

    Running F-prot right on the target system is kinda nice, but it doesn't fix any virus damage done to the Registry.. (Wine is limited here so far).
    Anyhow, back to it, but it sure is giving me a headache!
    Don

  7. #7
    Junior Member
    Join Date
    Nov 2004
    Posts
    1
    Hi,

    As usual, I am probably too late to comment but here's my two cents:

    The best way I have found to get rid of a mess of spyware is not with knoppix (sorry!) but with BartPE. This is a version of Windows that boots from a CD (surprise!). You can then scan your windows drives for viruses, spyware and anything else you put on your CD. See <http://www.nu2.nu/pebuilder/> for details.

  8. #8
    Senior Member registered user
    Join Date
    Dec 2003
    Location
    Salt Lake City, UT, U.S.A.
    Posts
    1,338
    triso,

    Good suggestion, best thing you can do is to not load the "junk" and have something trying to remove it while it is already loaded...

    A few "bad things" got stuffed into my IE, registry, auto-load, Windows install, and even SpyBot had a time getting rid of them, it required three reboots and SpyBot scans to finally rid the system of them -=- Spybot initially found them, cleaned what it could, required a reboot, then continued where it could further, then required a reboot, then continued cleaning some more, required a final reboot, and then completely rid the system on a last scan of "success"....

    The whole process would have been a single step, if I had been able to boot to a "clean" starting point, and let it go after the "infestation" without it being loaded each time... Good Suggestion

  9. #9
    Senior Member registered user
    Join Date
    Feb 2004
    Posts
    949
    With one really nasty spyware infection, CWS, I had to boot into safemode (with networking) run ad-aware, run hijack this! and then run a virus scanner (housecall)

    adware found 50 things, about 20 I had to remove with hijack this! and housecall found 20 trojans. All from this one thing of spyware.

  10. #10
    Junior Member registered user
    Join Date
    Oct 2004
    Posts
    21
    Maybe you should try booting in safe mode.

Similar Threads

  1. Possible to remove spyware Windows registry files w/Knoppix?
    By adkmom in forum MS Windows & New to Linux
    Replies: 11
    Last Post: 01-30-2005, 04:34 PM
  2. Can't create usable Linux partitions on Windows HD
    By Refugee in forum Hdd Install / Debian / Apt
    Replies: 10
    Last Post: 12-31-2004, 04:21 AM
  3. How rescue Windows Partitions with K3B?
    By HK in forum General Support
    Replies: 4
    Last Post: 11-14-2003, 05:34 PM
  4. How do I remove/add applications to KNOPPIX(well linux)
    By garyng in forum Hdd Install / Debian / Apt
    Replies: 3
    Last Post: 04-02-2003, 07:34 AM
  5. Windows FAT and FAT 32 partitions
    By fransm in forum Hdd Install / Debian / Apt
    Replies: 3
    Last Post: 01-23-2003, 03:32 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


Cisco SG95-16 16-Port Gigabit Switch SG95-16-KR picture

Cisco SG95-16 16-Port Gigabit Switch SG95-16-KR

$47.00



Cisco WS-C3560-48PS-S 48-Port Managed Gigabit PoE Switch picture

Cisco WS-C3560-48PS-S 48-Port Managed Gigabit PoE Switch

$36.40



HP ProCurve 4108gl J4865A Modular Network Switch picture

HP ProCurve 4108gl J4865A Modular Network Switch

$30.00



Cisco Nexus 48-Port 10G SFP+ Switch N9K-9396PX w/ 9K-M12PQ 12-Port 40G QSFP picture

Cisco Nexus 48-Port 10G SFP+ Switch N9K-9396PX w/ 9K-M12PQ 12-Port 40G QSFP

$249.99



New Linksys SE3005 5-port Gigabit Ethernet Switch picture

New Linksys SE3005 5-port Gigabit Ethernet Switch

$18.99



Linksys SE3008 8 Ports Rack Mountable Gigabit Ethernet Switch picture

Linksys SE3008 8 Ports Rack Mountable Gigabit Ethernet Switch

$21.99



HP 2530-48G 48 Port Gigabit Ethernet Network Switch J9775A picture

HP 2530-48G 48 Port Gigabit Ethernet Network Switch J9775A

$30.95



NETGEAR ProSafe GS728TPP 24-Port PoE+ Rackmountable Gigabit Ethernet Switch picture

NETGEAR ProSafe GS728TPP 24-Port PoE+ Rackmountable Gigabit Ethernet Switch

$59.99



HP JG937A Flexnetwork 5130-48G PoE+ 48-Port Gigabit Network Switch picture

HP JG937A Flexnetwork 5130-48G PoE+ 48-Port Gigabit Network Switch

$65.95



HP ProCurve 2530-24G J9776A 24 Port Gigabit Ethernet Managed Network Switch picture

HP ProCurve 2530-24G J9776A 24 Port Gigabit Ethernet Managed Network Switch

$34.99