also @ TechSpot: Windows 8 Release Preview leaked, Microsoft may raise OEM prices

TechSpot

Avira Malwarebytes and SuperAntiSpy helped, am I clear?

Discussion in 'Virus and Malware Removal' started by Dadof3, Nov 11, 2009.

Thread Status:
Not open for further replies.
  1. Dadof3 Newcomer, in training

    turned primary hard drive into slave

    I removed the hard drive that I could no longer boot up...put it into an office computer, and it came up as a slave without problem. I backed up the files I needed, and would now like to know....how can I edit the boot files so that I can put the hard drive back into its original Dell box, and run the computer as before? I am concerned that I cannot run combo-fix and specify the slave F drive without potentially infecting the office host computer.

    Are the music files that my son has potentially the carrier, so I should not back those up to the office host computer?
  2. kritius Newcomer, in training

    Only back up what you actually need and then wipe the drive.
  3. Dadof3 Newcomer, in training

    what about drivers

    As this is my sons computer, I dont know where or if, he has all of the necessary drivers...I have several Windows XP unopened discs that came with Dell computers that I have purchased for my family over the years...how would I re-initialize the hard disc (what sequence of events) and what about drivers for Monitor, keyboard, mouse, other cards for say graphics or whatever (printer)....

    You dont think there is any way to search the files and remove the virus manually while it is a slave and then put it back in the original computer it came from? Just trying to save alot of head ache with trying to get it back up and functioning properly without all of the original discs and pre-installed software...

    thanks!!
  4. kritius Newcomer, in training

    While the drive is slaved do an online scan,

    Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

    Make sure that the scanner looks at the slaved drive and then post the log back.
  5. Dadof3 Newcomer, in training

    will it put the other computer at risk?

    I dont have the office computer online yet as I was concerned that the slave drive and being online was a bad combination...just as a gut check here...I am not putting the host computer at risk by logging online with the slave in tact am I?
  6. kritius Newcomer, in training

    You shoudl be ok.
  7. Dadof3 Newcomer, in training

    Kaspersky Log file

    below is from the HTML file that I could not attach (sorry forgot to save it as a text or log file). again, the drive from my sons computer is now the slave in an office computer. We dont know where all the discs are to reformat with all of the drivers and other programs currently formated on the drive. We would like to be able to save its original formating if possible....

    KASPERSKY ONLINE SCANNER 7.0: scan report
    Thursday, December 3, 2009
    Operating system: Microsoft Windows 2000 Professional Service Pack 4 (build 2195)
    Kaspersky Online Scanner version: 7.0.26.13
    Last database update: Thursday, December 03, 2009 10:54:33
    Records in database: 3326104


    Scan settings
    scan using the following database extended
    Scan archives yes
    Scan e-mail databases yes

    Scan area Folder
    F:\

    Scan statistics
    Objects scanned 85055
    Threats found 1
    Infected objects found 1
    Suspicious objects found 0
    Scan duration 05:51:15

    File name Threat Threats count
    F:\WINDOWS\SYSTEM32\ruvaluno.exe Infected: Packed.Win32.Krap.ai 1

    Selected area has been scanned.
  8. kritius Newcomer, in training

    Please download OTM
    • Save it to your desktop.
    • Please double-click OTM to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
    • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

      Code:
      :Processes
      
      :Services
      
      :Reg
      
      :Files
      F:\WINDOWS\SYSTEM32\ruvaluno.exe
      
      :Commands
      [purity]
      [emptytemp]
      [Reboot]
      
    • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
    • Click the red Moveit! button.
    • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    • Close OTM and reboot your PC.
    Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

    Can you put the drive back into the main computer now?
  9. Dadof3 Newcomer, in training

    OTM cannot run

    I downloaded OTM to the desktop, however when I attempted to run it, an error message came up Warning: system restore interface not present and then nothing happened.

    Please advise....This office computer is running Windows 2000. Hope that is not a problem.
  10. kritius Newcomer, in training

    It may well be. I have not tested OTM on a windows 200 machine so I do not know if it works properly.

    I would just replace the drive in the original computer and get a combofix log from it when it is in place.
  11. Dadof3 Newcomer, in training

    drive wont boot as primary drive in original computer

    When it is the primary drive in the origninal computer, it wont boot (not in safe mode either) I get the blue screen with the text telling me I may have a virus....check the drive connections etc etc.
  12. kritius Newcomer, in training

    I would seriously just wipe it then. If it will slave get your son to sit down and decide what he wants to save and then format it.
Thread Status:
Not open for further replies.