| Windows 7: virus removal from within safe mode |
01 May 2011
|
#1 | | Windows 7 Home Ultimate 64-Bit, Ubuntu 10.04 Lucid Lynx, Windows XP Chicago |
virus removal from within safe mode I've got a reallybad virus. Laptophas MSE installed and I have malwarebytes intaller on a thumb drive but can't install it because of virus. I've booted into safe mode alternate shell. What are my options from here? Can I run scans from here? Can I install malwarebytes off my thum  bdrive in hed 4un itj | My System Specs |
| OS Windows 7 Home Ultimate 64-Bit, Ubuntu 10.04 Lucid Lynx, Windows XP CPU Pentium i7 @fast Memory 6GB DDR3 @fast Graphics Card ATI Radeon HD 4600 Series (512mb) / ATI TV Wonder 650PCIe Sound Card Integrated Monitor(s) Displays 32" VIZIO HDTV Screen Resolution 1080p @super sharp Keyboard LG Bluetooth Mouse LG Bluetooth Cooling My apartment's AC / Chicago Winters Hard Drives Internal 500GB @7200rpm and not big enough cache
External 500GB @7200rpm and not big enough cache Internet Speed ~21.50Mb/S Down, ~3.5Mb/S Up |
01 May 2011
|
#2 | | Windows 7 Ultimate SP1 (64-bit) Valencia, VE. |
Hello there, eduede!
Let's see, first, you have to boot into Safe Mode with Networking for the malwarebytes to update its database, install it, update it, do a complete system scan, and the rest should be taken care of...
After the scan finishes, select the infected items, delete them, reboot your PC and you could just do another system scan, to double check that the virus is no longer infecting your PC
Cheers. | My System Specs | | System Manufacturer/Model Number Built by Myself OS Windows 7 Ultimate SP1 (64-bit) CPU Intel Core i5-2310 @ 2.90GHz Motherboard MSI PH67A-C43 (B3) Memory Kingston KVR 16GB (4 x 4GB) DDR3 @ 1333MHz Graphics Card PNY XLR8 GTX 560 Ti 1GB GDDR5 Sound Card Realtek HD Audio (ALC 892) Monitor(s) Displays LG W2353V-PF Screen Resolution 1920 x 1080 (HDMI) Keyboard Logitech MK320 Wireless Keyboard Mouse Logitech MK320 Wireless Mouse PSU Thermaltake Toughpower XT 575w Modular 80 PLUS Bronze Case Cooler Master CM Storm Enforcer Cooling Thermaltake Frío, CM MegaFlow 200mm (2), CM 120mm (1) Hard Drives Samsung HD502HJ (500GB), ExcelStor J8080S (80GB) Internet Speed dl: 1024kbps, ul: 512kbps |
01 May 2011
|
#3 | | Windows 7 Ultimate 64 bit |
Try running Rkill, then run Malwarebytes Rkill Note: If your security software warns about Rkill, ignore & allow the download to continue.
Download RKill by Grinler from Here & save it to your Desktop.
Alternate download links: Two Three Four- Double click Rkill to run it
- A command window will open then disappear upon completion, this is normal
- If this does not happen... delete the file, then download & use the next link provided
- If it does not work, repeat the process & attempt to use one of the remaining links until the tool runs
- Do not reboot your machine until asked to do so. If no version of Rkill would run, please let me know
- When finished, Notepad will open with a log file, automatically saved at C:\rkill.log
- Copy/paste the contents of the rkill.log file in your next reply
- Leave Rkill on the Desktop unless instructed otherwise
Quote: Note: If you get an alert that Rkill is infected, ignore it. The alert is a fake warning given by rogue software, trying to "protect" itself from being terminated or removed. If you see such a warning, leave the warning on the screen, then run Rkill again. By not closing the warning, this sometimes allows you to bypass the malware's attempt to protect itself, so that Rkill can perform its routine. | My System Specs | | System Manufacturer/Model Number Dell Studio 15 OS Windows 7 Ultimate 64 bit |
01 May 2011
|
#4 | | Windows 7 Home Ultimate 64-Bit, Ubuntu 10.04 Lucid Lynx, Windows XP Chicago |
well i accidently booted into the Safe Mode minimal (alternate shell) so everything is command line. What are the command line commands for running Malicious Software Removal Tool? | My System Specs | | OS Windows 7 Home Ultimate 64-Bit, Ubuntu 10.04 Lucid Lynx, Windows XP CPU Pentium i7 @fast Memory 6GB DDR3 @fast Graphics Card ATI Radeon HD 4600 Series (512mb) / ATI TV Wonder 650PCIe Sound Card Integrated Monitor(s) Displays 32" VIZIO HDTV Screen Resolution 1080p @super sharp Keyboard LG Bluetooth Mouse LG Bluetooth Cooling My apartment's AC / Chicago Winters Hard Drives Internal 500GB @7200rpm and not big enough cache
External 500GB @7200rpm and not big enough cache Internet Speed ~21.50Mb/S Down, ~3.5Mb/S Up |
01 May 2011
|
#5 | | Windows 7 Ultimate SP1 (64-bit) Valencia, VE. |
I'd suggest reboot again and go into Safe Mode with Networking instead of Safe Mode with Command Line | My System Specs | | System Manufacturer/Model Number Built by Myself OS Windows 7 Ultimate SP1 (64-bit) CPU Intel Core i5-2310 @ 2.90GHz Motherboard MSI PH67A-C43 (B3) Memory Kingston KVR 16GB (4 x 4GB) DDR3 @ 1333MHz Graphics Card PNY XLR8 GTX 560 Ti 1GB GDDR5 Sound Card Realtek HD Audio (ALC 892) Monitor(s) Displays LG W2353V-PF Screen Resolution 1920 x 1080 (HDMI) Keyboard Logitech MK320 Wireless Keyboard Mouse Logitech MK320 Wireless Mouse PSU Thermaltake Toughpower XT 575w Modular 80 PLUS Bronze Case Cooler Master CM Storm Enforcer Cooling Thermaltake Frío, CM MegaFlow 200mm (2), CM 120mm (1) Hard Drives Samsung HD502HJ (500GB), ExcelStor J8080S (80GB) Internet Speed dl: 1024kbps, ul: 512kbps |
01 May 2011
|
#6 | | |
RKill. That's a nice one. Like ComboFix? Will try that out one of these days
Encountered the "can't install Malwarebytes" before and I posted at the MBAM forums about it. They told me to rename the mbam.exe to anything other than mbam.exe. I did that and it worked. Updated manually. Pasted the rules.ref to C:\Program Data\Malwarebytes\Malwarebyte's Anti-Malware\. Just copy the rules.ref from a pc which has MBAM installed.
Or visit Manual Malwarebytes definitions download link
Seems like your problem..read here: MBAM will not run MBAM Command Line Parameters
Alternatives to Safe Mode scanning and removal can be found at this post. You do not need to boot to Safe Mode there just boot to cd or USB and your good to go.
But if you can try RKill that would be great.
Last edited by damien76; 01 May 2011 at 09:04 PM..
Reason: added links
| My System Specs | | OS Win7 Ultimate 32bit CPU P4 2.6Ghz Motherboard Asus p4ux-800 Memory 2.5gb DDR Graphics Card nVidia GEForce fx5500 Sound Card onboard Monitor(s) Displays kingston lcd 17inch wide PSU 600watts Kooler Cooling original case fan + 1 additional side fan Hard Drives WD 320gb sata
Seagate 160gb IDE |
01 May 2011
|
#7 | | Windows 7 Home Premium x64 SP1 Bay Area Peninsula |
You might be better served burning a bootable AV disc (or 2), and cleaning from outside windows completely. FREE Bootable AntiVirus Rescue CDs Download List
Delete all system restore points by turning off SR. If any signs of infection remain after boot scanning, and running additional scans within windows (online scanners are also a good idea: HouseCall - Free Online Virus Scan - Trend Micro USA , Free Online Virus Scan - BitDefender Online Scanner , Panda ActiveScan | Free Online Antivirus | Free Virus Disinfection - Panda Security , Free Virus Scan - Kaspersky Lab ) , a fresh install may be the best idea. A Guy | My System Specs | | OS Windows 7 Home Premium x64 SP1 CPU INTEL Core i5-750 Quad-Core 3.37GHz Motherboard ASUS P7P55D Memory KINGSTON 4GB (2 x 2GB) HyperX PC3-12800 DDR3 1600MHz CL8 Graphics Card MSI N240GT-MD1G/D5 GeForce GT 240 1GB 128-bit GDDR5 Monitor(s) Displays Samsung SyncMaster B2430H 24" Screen Resolution 1920 x 1080 PSU ANTEC TruePower New TP-550, 80 PLUS, 550W Case ANTEC Three Hundred Illusion Cooling COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's Hard Drives Intel X25M Gen2 80GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache Internet Speed 20 + Mbps Antivirus Avast Browser Opera |
02 May 2011
|
#8 | | W7 X-64 RTM,SUSE 11.1, XP PRO SP3 as a VM, VMware ESXi Hafnarfjörður IS |
Hi there
I keep saying to people -- it is UTTERLY NO POINT in using an INFECTED computer to remove any VIRUS -- how can you be sure that the virus removing software itself hasn't been compromised.
Say you were drilling on an Oil Platform and the drill needed sharpening, You wouldn't use a tool which was already worn out to sharpen / renew the bit would you.
Same with Virus removal -- why trust an INFECTED computer to work properly.
The ONLY IMO safe solution is a COMPLETE restore from a KNOWN Virus free backup or a total Windows 7 re-install.
If you have data copy that to an external HDD and run a virus check against the data ON A SEPARATE MACHINE.
AV software is just that -- should protect against getting a virus -- once you have one then ONLY a RESTORE or Re-INSTALL can be guaranteed to be 100% safe.
Forget ANY AV removal software -- once you've BEEN infected it's TOO LATE. You need to catch any virus in Real time then you can take proper action.
MSE does a reasonable job at this once you've got your computer working properly again.
Cheers
jimbo | My System Specs | | System Manufacturer/Model Number Custom built OS W7 X-64 RTM,SUSE 11.1, XP PRO SP3 as a VM, VMware ESXi CPU Q9400 QUAD Motherboard P5QL-CM Memory 8GB Graphics Card On Motherborad Sound Card Realtek HD audio Monitor(s) Displays Apple Cinema display Mouse Toshiba wireless laser Hard Drives 4 X 1TB SATA Internet Speed > 20MB up |
02 May 2011
|
#9 | | windows 7 ultimate x64 SP1 Croatia |
jimbo45,
you are apsolutley wright.
and what if he doesn't have an backup 
in taht case I would downlaod kaspersky administartion kit wich enables you remotly intstalling antivirus and other components and disinfection as well as all other protection tasks from one conmputer (AK server) to another (infected client)
se more at Product Updates --> Kaspersky Administration Kit 8
chears!
sasanet. | My System Specs | | OS windows 7 ultimate x64 SP1 |
02 May 2011
|
#10 | | W7 X-64 RTM,SUSE 11.1, XP PRO SP3 as a VM, VMware ESXi Hafnarfjörður IS |
Hi there
I wish NOBODY would be allowed to use a computer until they learned how important it was to take backups regularly AND ACTUALLY DO IT.
However if he doesn't have a backup then the only solution is to do a complete Windows 7 re-install.
He could still copy DATA files (Music, documents, films, photos etc etc) to an external HDD or whatever before doing the re-install . Even with no backup program these can be copied via Windows explorer. ===> BUT VIRUS SCAN THESE ON A SEPARATE MACHINE before copying back to your computer.
As I said previously after you've re-installed Windows 7 install MSE and then take a BACKUP before installing any software etc. This will give you a decent image to recover from in the future without having to re-install again.
Incidentally keep the OS and applications in ONE partition = Windows 7 partition size typically around 35 - 50 GB depending on what applications are installed. Divide the rest of your disc storage up into various partitions such as DATA, scratch volumes, Multi-media etc etc.
Cheers
jimbo | My System Specs | | System Manufacturer/Model Number Custom built OS W7 X-64 RTM,SUSE 11.1, XP PRO SP3 as a VM, VMware ESXi CPU Q9400 QUAD Motherboard P5QL-CM Memory 8GB Graphics Card On Motherborad Sound Card Realtek HD audio Monitor(s) Displays Apple Cinema display Mouse Toshiba wireless laser Hard Drives 4 X 1TB SATA Internet Speed > 20MB up virus removal from within safe mode problems? All times are GMT -5. The time now is 01:52 AM. | |