Page 1 of 2 12 LastLast
Results 1 to 10 of 17

Thread: Need some help on removing a Bagle worm from windows

  1. #1
    Junior Member
    Join Date
    Jun 2006
    Posts
    9

    Need some help on removing a Bagle worm from windows

    Hey everyone my names Rob I'm new to this forum and to knoppix but am enjoying it so far. Now everything so far has worked I've located the infected file using knoppix but now I was told to go into windows safe mode with command prompt under admin. and del the file but I can't boot to windows at all not even the command prompt any other way to get this file off the hd or can it be removed through knoppix?

  2. #2
    Administrator Site Admin-
    Join Date
    Apr 2003
    Location
    USA
    Posts
    5,441
    If it's an NTFS partition, no. There actually has been a rumor that the new 5.0.1 can write to NTFS "in some cases", whatever that means, but I've yet to see any reports that it works or is safe. If you have NTFS partitions I suggest that you read the rescue faq in the wiki and use Knoppix to make backups of what you need, then install fresh.

    If it's a FAT partition, yes, if you can find the bad file then you can delete it. See answer #6 for details.
    ---
    Verifying of md5 checksum and burning a CD at slow speed are important.

  3. #3
    Junior Member
    Join Date
    Jun 2006
    Posts
    9
    It's a FAT partition and I'm still unclear on the way I'd go about removing the file through knoppix..

  4. #4
    Administrator Site Admin-
    Join Date
    Apr 2003
    Location
    USA
    Posts
    5,441
    use above link information to mount partition with write access, open partition from desktop icon and browse to the file that you hase identified as the infection. delete it.

    Are you saying that you don't know what file is infected? I would have expected whatever identified the infection to tell you that. Or are you saying you are not comfortable navigating through the FAT file system with the Linux tools? Or is it some other issue that I'm missing?

  5. #5
    Junior Member
    Join Date
    Jun 2006
    Posts
    9
    Yea I'm not to comfortable navigationg yet but I was kind of learning as I go, I thought by clicking on the hda1 icon on the kde desktop was just like /mnt from the CLI I didn't see options for deleting the file when I right clicked but I guess I didn't try the del key...is it as simple as that or is there something else

  6. #6
    Junior Member
    Join Date
    Jun 2006
    Posts
    9
    damn I'm an idiot thanks for the support on that Harry, I appreciate getting great support right away I like this forum, the seasoned knoppix users don't rub it in about our new user questions, and thats a classy way to be, I did have one follow up question though..there has been a progress dialog up for a few minutes with no activity and know it looks like the screen might be freezing up..is this normal or do you have any suggestions or comments?

  7. #7
    Administrator Site Admin-
    Join Date
    Apr 2003
    Location
    USA
    Posts
    5,441
    Quote Originally Posted by rwhboston
    ..there has been a progress dialog up for a few minutes with no activity and know it looks like the screen might be freezing up..is this normal or do you have any suggestions or comments?
    not normal. A progress dialog on what? deleting a file? Some application that you are running? booting Knoppix (which sounds like you already have working ok)? What is this dialog saying?
    ---
    Verifying of md5 checksum and burning a CD at slow speed are important.

  8. #8
    Junior Member
    Join Date
    Jun 2006
    Posts
    9
    yea I hit the delete key when the file was highlighted and a progress dialog box popped up at the bottom of the screen with a progress bar that reads 0% then everything freezes up

  9. #9
    Administrator Site Admin-
    Join Date
    Apr 2003
    Location
    USA
    Posts
    5,441
    Well, I jus went through the steps. Here's my experience:

    Coaxed my testbed system to boot the Knoppix 5.0.1 CD. Not sue why it didn't want to this morning; it booted it many times last night without complaint, but it was an effort this morning. But eventually Knoppix booted.

    I looked at all of those nice hda icons on my desktop and picked hda5, knowing it was a logical FAT drive with files ripe for deletion.

    I right clicked on it expecting to use the actions sub-menu to make it writable, but to my surprise version 5.0.1 has changed this menu! So I'll have to update some documentation. Still, I saw the option to make the mount read/write when I did the right click. I tried it, was informed that I had to mount the partition first.

    So I clicked on it, Konquror open and displayed the partition. I confirmed that I could not delete a file (it was still read only access). I right clicked on the hda5 icom and chose to make it read/write. It questioned me about this but then let me do it.

    I picked something that I could afford to delete. Rather than just hit delete I looked at the menu and under Edit I found that Delete was "move to Trash" and Shift-Delete was a true delete. Frankly I would feel better about making a true delete, both since it's a virus that you really want to get rid of and because I question how well Linux impliments the Microsoft trash system, but in the end I decided to do the same delete that you are trying to do, so I just hit the delete key while the sacrificial file was highlighted.

    I did indeed see the progress bar pop up, but it was so quick that if I wasn't looking for it I would have missed it. So I don't know why you are having the problem that you report. Is this infected file huge? Are you deleting more than one file (an entire directoy and sub-directory structure perhaps)? My best guess is that your file system may not be in very good shape, which I'm also inclined to think is the case since you are trying to delete the bad file with Knoppix rather than just using DOS (wihich obviously deletes files on a FAT system quite well).
    ---
    Verifying of md5 checksum and burning a CD at slow speed are important.

  10. #10
    Junior Member
    Join Date
    Jun 2006
    Posts
    9
    I'ts my friends computer and everything about this computer seems bad, file system most of all.. the file was found by clamscan as hiberfil.sys: worm.Bagle.BB-gen I'm not sure if it's the computer that's the problem or the file that's throwing it off

Page 1 of 2 12 LastLast

Similar Threads

  1. Hard disk problem ... or a worm?
    By asearle in forum General Support
    Replies: 3
    Last Post: 08-03-2005, 10:30 AM
  2. removing X completely
    By florin in forum Customising & Remastering
    Replies: 0
    Last Post: 03-07-2005, 02:11 AM
  3. Removing Windows
    By chrisjrn in forum Hdd Install / Debian / Apt
    Replies: 12
    Last Post: 05-07-2004, 06:02 AM
  4. Removing X11
    By technoronin in forum Customising & Remastering
    Replies: 2
    Last Post: 04-19-2004, 01:36 AM
  5. Removing without removing dependencies also
    By eric2 in forum Hdd Install / Debian / Apt
    Replies: 0
    Last Post: 01-25-2004, 11:36 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


A-Tech 8GB DDR3 1600 PC3-12800 Laptop SODIMM 204-Pin Memory RAM PC3L DDR3L 1x 8G picture

A-Tech 8GB DDR3 1600 PC3-12800 Laptop SODIMM 204-Pin Memory RAM PC3L DDR3L 1x 8G

$13.99



Samsung 16GB (2x8GB) DDR4 2400MHz PC4-19200 Desktop RAM Memory M378A1K43CB2-CRC picture

Samsung 16GB (2x8GB) DDR4 2400MHz PC4-19200 Desktop RAM Memory M378A1K43CB2-CRC

$19.95



Samsung 16GB 2Rx4 PC4-2133P DDR4-17000 1.2V RDIMM ECC Registered Server Memory picture

Samsung 16GB 2Rx4 PC4-2133P DDR4-17000 1.2V RDIMM ECC Registered Server Memory

$16.29



HyperX FURY DDR3 8GB 16GB 32GB 1600 MHz PC3-12800 Desktop RAM Memory DIMM 240pin picture

HyperX FURY DDR3 8GB 16GB 32GB 1600 MHz PC3-12800 Desktop RAM Memory DIMM 240pin

$12.90



A-Tech 8GB PC3-12800 Desktop DDR3 1600 MHz Non ECC 240-Pin DIMM Memory RAM 1x 8G picture

A-Tech 8GB PC3-12800 Desktop DDR3 1600 MHz Non ECC 240-Pin DIMM Memory RAM 1x 8G

$13.99



Kingston HyperX FURY DDR3 8GB 16GB 32G 1600 1866 1333 Desktop Memory RAM DIMM picture

Kingston HyperX FURY DDR3 8GB 16GB 32G 1600 1866 1333 Desktop Memory RAM DIMM

$13.25



TeamGroup 16GB PC4 2666 PC4 21300 DDR4 2666MHz 1.2V CL19 Desktop RAM Memory picture

TeamGroup 16GB PC4 2666 PC4 21300 DDR4 2666MHz 1.2V CL19 Desktop RAM Memory

$27.95



HyperX FURY RAM DDR4 16GB 8GB 32GB 4GB 3200 2666 2400 2133 Desktop Memory DIMM picture

HyperX FURY RAM DDR4 16GB 8GB 32GB 4GB 3200 2666 2400 2133 Desktop Memory DIMM

$9.64



A-Tech 256GB 4x 64GB 4Rx4 PC4-19200 ECC Load Reduced LRDIMM Server Memory RAM picture

A-Tech 256GB 4x 64GB 4Rx4 PC4-19200 ECC Load Reduced LRDIMM Server Memory RAM

$287.96



A-Tech 128GB 8x 16GB 2Rx4 PC4-19200R DDR4 2400 ECC REG RDIMM Server Memory RAM picture

A-Tech 128GB 8x 16GB 2Rx4 PC4-19200R DDR4 2400 ECC REG RDIMM Server Memory RAM

$175.92