Results 1 to 10 of 10

Thread: Using Linux to remove spyware from Windows partitions.

  1. #1
    Junior Member
    Join Date
    Oct 2004
    Location
    Chesterfield, VA
    Posts
    3

    Using Linux to remove spyware from Windows partitions.

    Has anybody seen any software that would run under the Linux/Knoppix system that could search within a Windows partition for spyware/adware and other malware. I would like it to be able to resolve Windows registry entries as well as the executable files and directories.
    I am also looking for alternatives to virus detection other than ClamAV to remove viruses in a like fashion.
    On a slightly different note, I would also like to remaster Knoppix Insert distro to include the above programs, but have never done a remaster before, can anyone point me towards a good tutorial to do this?

    Thanks,
    Don.

  2. #2
    Senior Member registered user
    Join Date
    Nov 2002
    Posts
    1,353
    You'll probably have a hard time getting advice from most Linux users on this topic simply because spyware isn't a problem under Linux. If you can't use regular Windows spyware removal tools (like Adaware and Spybot) because your Windows machine won't boot, you "might" be able to get these tools to run using Wine. This might be a totally worthless suggestion however. It's the only thing I can think of.

  3. #3
    Junior Member
    Join Date
    Oct 2004
    Location
    Chesterfield, VA
    Posts
    3
    I thought it would be a good thing to use Linux to fix a Windows system. The Windows systems are getting so mucked up they cant even run a remover program anymore.
    Ergo, good PR for the general public about Linux.

  4. #4
    Senior Member registered user
    Join Date
    Feb 2004
    Posts
    949
    Really? I have great success with ad-aware. If I can't delete it normally, i'll boot into safe mode and that fixes it.

    *On topic*
    I'll have to agree with above, the best thing you can try is running them with wine. I would think that they would work.

  5. #5
    Senior Member registered user
    Join Date
    Dec 2003
    Location
    Salt Lake City, UT, U.S.A.
    Posts
    1,338
    Before "getting out" of Windows, I found some excellent "free-ware" for windows, they work great, and either they are "free completely", or you can get a "free version" that wants you to buy the "buy" version, but still doesnt lock up after a "trial" period...

    Spy-Ware -=- Spybot Search and Destroy - free-ware...

    Anti-Virus -=- AVast -=- "Home" version is free-ware, but always tells you that "if you bought the real version, you'd get xxxxxxxx features...". It doesnt lock up or anything, it just advertises for its "paid" version....

    Spybot is excellent, it has "ripped out" tons of junk that gets "added" into IE all the time... Nice thing is, both run "native" in Windows...

  6. #6
    Junior Member
    Join Date
    Oct 2004
    Location
    Chesterfield, VA
    Posts
    3
    Well thanks for the tips, I have been using Ad-aware, Spybot-SD, AVG, F-Prot, Symantec and on and on.. . I do this for a living and all of the spyware, viruses, backdoors, trojans etc have rendered many Windows systems to nothing more than very expensive paper weights. So I have been trying to find new and better ways to clean and fix those windows partitions.

    I have had some luck with the following; Running taget machine with Knoppix 3.6 and Captive-NTFS and Samba. This allows me to network to the target system and run AVG and Ad-Aware on it. But the captive-ntfs stuff is giving me fits about allowing the drive to be Read/Write. (yep I have heard about the writing to ntfs disk problems too)

    Running F-prot right on the target system is kinda nice, but it doesn't fix any virus damage done to the Registry.. (Wine is limited here so far).
    Anyhow, back to it, but it sure is giving me a headache!
    Don

  7. #7
    Junior Member
    Join Date
    Nov 2004
    Posts
    1
    Hi,

    As usual, I am probably too late to comment but here's my two cents:

    The best way I have found to get rid of a mess of spyware is not with knoppix (sorry!) but with BartPE. This is a version of Windows that boots from a CD (surprise!). You can then scan your windows drives for viruses, spyware and anything else you put on your CD. See <http://www.nu2.nu/pebuilder/> for details.

  8. #8
    Senior Member registered user
    Join Date
    Dec 2003
    Location
    Salt Lake City, UT, U.S.A.
    Posts
    1,338
    triso,

    Good suggestion, best thing you can do is to not load the "junk" and have something trying to remove it while it is already loaded...

    A few "bad things" got stuffed into my IE, registry, auto-load, Windows install, and even SpyBot had a time getting rid of them, it required three reboots and SpyBot scans to finally rid the system of them -=- Spybot initially found them, cleaned what it could, required a reboot, then continued where it could further, then required a reboot, then continued cleaning some more, required a final reboot, and then completely rid the system on a last scan of "success"....

    The whole process would have been a single step, if I had been able to boot to a "clean" starting point, and let it go after the "infestation" without it being loaded each time... Good Suggestion

  9. #9
    Senior Member registered user
    Join Date
    Feb 2004
    Posts
    949
    With one really nasty spyware infection, CWS, I had to boot into safemode (with networking) run ad-aware, run hijack this! and then run a virus scanner (housecall)

    adware found 50 things, about 20 I had to remove with hijack this! and housecall found 20 trojans. All from this one thing of spyware.

  10. #10
    Junior Member registered user
    Join Date
    Oct 2004
    Posts
    21
    Maybe you should try booting in safe mode.

Similar Threads

  1. Possible to remove spyware Windows registry files w/Knoppix?
    By adkmom in forum MS Windows & New to Linux
    Replies: 11
    Last Post: 01-30-2005, 04:34 PM
  2. Can't create usable Linux partitions on Windows HD
    By Refugee in forum Hdd Install / Debian / Apt
    Replies: 10
    Last Post: 12-31-2004, 04:21 AM
  3. How rescue Windows Partitions with K3B?
    By HK in forum General Support
    Replies: 4
    Last Post: 11-14-2003, 05:34 PM
  4. How do I remove/add applications to KNOPPIX(well linux)
    By garyng in forum Hdd Install / Debian / Apt
    Replies: 3
    Last Post: 04-02-2003, 07:34 AM
  5. Windows FAT and FAT 32 partitions
    By fransm in forum Hdd Install / Debian / Apt
    Replies: 3
    Last Post: 01-23-2003, 03:32 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


SFP-10G-LR Compatible 10GBase-LR SFP+ LR Transceiver 10G 1310nm SMF up ot 10km picture

SFP-10G-LR Compatible 10GBase-LR SFP+ LR Transceiver 10G 1310nm SMF up ot 10km

$45.00



Cisco SG110 24 Port Gigabit Ethernet Switch w/ 2 x SFP SG110-24 picture

Cisco SG110 24 Port Gigabit Ethernet Switch w/ 2 x SFP SG110-24

$117.00



Allen-Bradley 1783-SFP1GSX Compatible 1000BASE-SX SFP 850nm 550m Transceiver-895 picture

Allen-Bradley 1783-SFP1GSX Compatible 1000BASE-SX SFP 850nm 550m Transceiver-895

$65.50



J4859D HPE Aruba Compatible 1000BASE-LX SFP 1310nm 10km DOM LC MMF/SMF-0987 picture

J4859D HPE Aruba Compatible 1000BASE-LX SFP 1310nm 10km DOM LC MMF/SMF-0987

$18.00



Genuine Cisco SFP-10G-SR V03 10GBASE-SR SFP+ Transceiver Module 10-2415-03  picture

Genuine Cisco SFP-10G-SR V03 10GBASE-SR SFP+ Transceiver Module 10-2415-03

$8.00



NEW Sealed Cisco SFP-10G-LR 10GBASE-LR SFP+ 1310nm 10km *US Shipping* picture

NEW Sealed Cisco SFP-10G-LR 10GBASE-LR SFP+ 1310nm 10km *US Shipping*

$18.00



Cisco QSFP-40G-SR-BD BiDi Short-reach Transceiver, 1 Year Warranty picture

Cisco QSFP-40G-SR-BD BiDi Short-reach Transceiver, 1 Year Warranty

$17.25



Cisco SFP-10G-LR-S SFP+ 1310nm 10km DOM Transceiver Module 10-3107-01 - 1 Year  picture

Cisco SFP-10G-LR-S SFP+ 1310nm 10km DOM Transceiver Module 10-3107-01 - 1 Year

$41.59



LOT OF 20 Genuine Cisco SFP-10G-SR V03 10GBASE-SR SFP+ Transceiver Module picture

LOT OF 20 Genuine Cisco SFP-10G-SR V03 10GBASE-SR SFP+ Transceiver Module

$89.00



Cisco Meraki MA-SFP-10GB-SR 10G SFP+ SR 850nm 300m LC MMF picture

Cisco Meraki MA-SFP-10GB-SR 10G SFP+ SR 850nm 300m LC MMF

$29.99