Spyware Removal from slave disk

Soldato
Joined
9 May 2005
Posts
4,524
Location
Nottingham
I have a friends laptop that has some nasty spyware on it. I took the disk and put it in a USB caddy so I can scan it from a clean environment, there is no hope trying to remove it if it can freely execute.

I am currently scanning it with AVG but I can't find a spyware removal tool that will allow me to specify a drive to scan, they all want to scan the host system. Does anyone know of a tool that will allow me to do this (adaware Free doesn't allow this nor does Spybot).
 
Soldato
Joined
28 Oct 2002
Posts
3,125
Location
Essex
Spyware Doctor, under a custom scan will also allow you to pick a drive, which is a much better program and will find much more. I tend to find Windows Defender pretty poor.
 
Soldato
OP
Joined
9 May 2005
Posts
4,524
Location
Nottingham
Thanks, I'll give them both a try, I might be able to get rid of it. My opinion though is that once your system gets infected with spyware it's game over.
 
Soldato
Joined
31 Aug 2004
Posts
3,658
Location
Sol System
Nah you can get rid of them all. The best program by far is hijackthis, but you'll need to be running on your mates laptop. If you dont have any luck with the slave drive scans, stick it back in his laptop and run hojackthis. Then just paste the results in www.hijackthis.de to find out where the problems are (need to be carefull not to remove something you shouldn't)
 
Permabanned
Joined
19 Apr 2006
Posts
2,333
Location
West Yorkshire
As said the best chance is to put the hdd back in the original machine then do the following:

download VundoFix.exe to your desktop. http://www.atribune.org/ccount/click.php?id=4

Note: In the event you already have Vundofix, this is a new version that I need you to download.

* Double-click VundoFix.exe to run it.
* You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
* When VundoFix re-opens, click the Scan for Vundo button.
* Once it's done scanning, click the Remove Vundo button.
* You will receive a prompt asking if you want to remove the files, click YES
* Once you click yes, your desktop will go blank as it starts removing Vundo.
* When completed, it will prompt that it will shutdown your computer, click OK.
* Turn your computer back on.


Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears at reboot.

Download ComboFix from http://download.bleepingcomputer.com/sUBs/ComboFix.exe to your Desktop.


* Double click combofix.exe and follow the prompts.


Note: Do not mouseclick combofix's window while its running. That may cause it to stall

Download and scan with SUPERAntiSpyware Free for Home Users http://www.superantispyware.com/

* Double-click SUPERAntiSpyware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here.)
* Under "Configuration and Preferences", click the Preferences button.
* Click the Scanning Control tab.
* Under Scanner Options make sure the following are checked (leave all others unchecked):
o Close browsers before scanning.
o Scan for tracking cookies.
o Terminate memory threats before quarantining.
* Click the "Close" button to leave the control center screen.
* Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under "Complete Scan", choose Perform Complete Scan.
* Click "Next" to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
* Make sure everything has a checkmark next to it and click "Next".
* A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
* If asked if you want to reboot, click "Yes".

* Click Close to exit the program.

Download the latest version of Java, uninstall any old versions you have as old versions are exploitable and need uninstalling.

Install the latest version.

If your still having problems or want someone to double check you clean then make a post over at Techmonkeys.co.uk and they will go through the log for you and give you clear instructions on what to remove.
 
Back
Top Bottom