PDA

View Full Version : Spyware and Virus in XP... Remove in Ubuntu?


sebz2005
January 18th, 2008, 01:57 AM
Hey,
(It's been a while since I've been here...)

I recently got a virus and some spyware installed on my computer.
I've been able to remove some of it, but there's a few that are very persistent. (Virtumonde and Smitfraud-C.)
I've located where the files are hiding but can't attack them. I've tried removing the hard drive and accessing it via another pc, but no luck.

I know that I was once able to remove something similar on my friends computer when he had Ubuntu on a separate partition.

Now, I don't have any spare partitions that I can use to remove them, so would I be able to use my Live CD and delete them?
They're sitting on my SATA drive so the partitions are NTFS. I know that Ubuntu doesn't have support for NTFS at the moment, but I remember reading somewhere that someone was able to get in.

What program do I install in the Live CD mode so I can get in?


Thanks for any help!!

~Seb

lian1238
January 18th, 2008, 02:06 AM
I think Gutsy DOES have out-of-the-box support for NTFS partitions.
Good luck with the viruses. ;)

sebz2005
January 18th, 2008, 02:10 AM
You serious?!
Oh, that'd be awesome!
Thanks!

I'll go check it out right now... I'll be right back.

... Now where did my disc go?

Edit: It's loaded...
Now to mount the Hdd...

Edit 2: Removed all the files... Let's see how this goes now.

lian1238
January 18th, 2008, 02:28 AM
Yes, I'm serious. I'm trying the LiveCD right now. Full access, too! :D

sebz2005
January 18th, 2008, 02:33 AM
Bugger!
It hid itself in copies of programs with a space between the file name and the extention...
It's now back.

lian1238
January 18th, 2008, 02:34 AM
Did you use locate to find the files?

Edit: Sorry, locate doesn't search NTFS..

sebz2005
January 18th, 2008, 02:37 AM
I knew where the originating dll was.
But I know the names of what the other files were.... Just have to go through and get them...

It's like playing mine sweeper, except the bombs change location and some times appear elsewhere.

Edit: Good God!
It loves to hide itself!
Up to 20 files and counting!

Edit 2:
Smitfraud-C. was easy to remove...
Virtumonde isn't.
Trying to remove it now.

Edit 3:
Removed suspected files and have begun downloading latest definition for Pc-cillin to add and later scan in safemode.
(hehehe, it's like a blog!)

lian1238
January 18th, 2008, 07:01 AM
Yup.:)
It'll later help others who get the same problem. Maybe you could name which files you delete to solve it?

kerry_s
January 18th, 2008, 09:22 AM
make sure after you get all cleaned up, use spyware blaster it's a preventer it will stop alot of things from even installing.
http://www.javacoolsoftware.com/spywareblaster.html
it's free