<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Has anyone ever fixed malware/spyware thru&#x27; BartPE in Security</title>
<link>http://www.dslreports.com/forum/r15346085</link>
<description></description>
<language>en</language>
<pubDate>Tue, 01 Dec 2009 11:06:54 EDT</pubDate>
<lastBuildDate>Tue, 01 Dec 2009 11:06:54 EDT</lastBuildDate>

<item>
<title>Re: Has anyone ever fixed malware/spyware thru&#x27; Ba</title>
<link>http://www.dslreports.com/forum/remark,15361980</link>
<description><![CDATA[<A HREF="/useremail/u/957735"><b>Goldengamego</b></A> : <div class="bquote"><SMALL>said by  CTS <A HREF="/useremail/u/545312"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Hmm...for some reason I can't seem to build UBCD.  Every time I do so, I get the BartPE folder which contains the contents but if I burn the contents, I don't get a bootable CD.  I know the builder is suppose to build the ISO but it's no where to be found within the folders.<br><br>Maybe I did something wrong?<br> </DIV>&raquo;<A HREF="http://ubcd4win.com/howto.htm" >ubcd4win.com/howto.htm</A><br><br>Have a look at the HOWTO<br><SMALL>--<br>Because Goldengamegod won't fit:p</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15361980</guid>
<pubDate>Mon, 30 Jan 2006 13:33:48 EDT</pubDate>
</item>

<item>
<title>Re: Has anyone ever fixed malware/spyware thru&#x27; Ba</title>
<link>http://www.dslreports.com/forum/remark,15354420</link>
<description><![CDATA[<A HREF="/useremail/u/826261"><b>WiggiE</b></A> : &raquo;<A HREF="http://www.aptv38.dsl.pipex.com/Plugins/updating.htm" >www.aptv38.dsl.pipex.com/Plugins&middot;&middot;&middot;ting.htm</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15354420</guid>
<pubDate>Sun, 29 Jan 2006 11:10:07 EDT</pubDate>
</item>

<item>
<title>Re: Has anyone ever fixed malware/spyware thru&#x27; Ba</title>
<link>http://www.dslreports.com/forum/remark,15354276</link>
<description><![CDATA[<A HREF="/useremail/u/1227122"><b>Profixer</b></A> : CTS... I have a document I wrote a while ago which explains all the steps in making a BartPE bootable CD, and adding registry plugins etc... if you send me your email, I can send that off to you...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15354276</guid>
<pubDate>Sun, 29 Jan 2006 10:38:07 EDT</pubDate>
</item>

<item>
<title>Re: Has anyone ever fixed malware/spyware thru&#x27; Ba</title>
<link>http://www.dslreports.com/forum/remark,15354175</link>
<description><![CDATA[<A HREF="/useremail/u/545312"><b>CTS</b></A> : Hmm...for some reason I can't seem to build UBCD.  Every time I do so, I get the BartPE folder which contains the contents but if I burn the contents, I don't get a bootable CD.  I know the builder is suppose to build the ISO but it's no where to be found within the folders.<br><br>Maybe I did something wrong?<br><SMALL>--<br>Operation Hold `Em"Shuffle Up and Deal"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15354175</guid>
<pubDate>Sun, 29 Jan 2006 10:12:46 EDT</pubDate>
</item>

<item>
<title>Re: Has anyone ever fixed malware/spyware thru&#x27; Ba</title>
<link>http://www.dslreports.com/forum/remark,15353246</link>
<description><![CDATA[<A HREF="/useremail/u/1001074"><b>toadlife</b></A> : Yep. BartPE is great for those nasty self replicating buggers. I wouldn't worry too much about cleaning the registry of the infected system with BartPE. The files are what is important, since registry entries are useless if the code they point to is no longer there.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15353246</guid>
<pubDate>Sun, 29 Jan 2006 02:30:10 EDT</pubDate>
</item>

<item>
<title>Re: Has anyone ever fixed malware/spyware thru&#x27; Ba</title>
<link>http://www.dslreports.com/forum/remark,15352786</link>
<description><![CDATA[<A HREF="/useremail/u/545312"><b>CTS</b></A> : <div class="bquote"><SMALL>said by  fegul <A HREF="/useremail/u/1063283"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>You'd be surprised how much Spysweeper can fix.  I clean up most of the things in PE, the rest is done in safe mode (like the specialized cleaners)<br> </DIV>Interesting... I'll definitely check it out.<br>I actually have a test PC set up and want to test out using UBCD and see how effect it can be.<br><br>Thanks<br><SMALL>--<br>Operation Hold `Em"Shuffle Up and Deal"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15352786</guid>
<pubDate>Sun, 29 Jan 2006 00:33:36 EDT</pubDate>
</item>

<item>
<title>Re: Has anyone ever fixed malware/spyware thru&#x27; Ba</title>
<link>http://www.dslreports.com/forum/remark,15352707</link>
<description><![CDATA[<A HREF="/useremail/u/1063283"><b>fegul</b></A> : You'd be surprised how much Spysweeper can fix.  I clean up most of the things in PE, the rest is done in safe mode (like the specialized cleaners)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15352707</guid>
<pubDate>Sun, 29 Jan 2006 00:18:40 EDT</pubDate>
</item>

<item>
<title>Re: Has anyone ever fixed malware/spyware thru&#x27; Ba</title>
<link>http://www.dslreports.com/forum/remark,15352702</link>
<description><![CDATA[<A HREF="/useremail/u/545312"><b>CTS</b></A> : <div class="bquote"><SMALL>said by  fegul <A HREF="/useremail/u/1063283"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>Using the WUBCD, I usually run the Mwav tool to scan for viruses, then I run Adaware and Spybot to get rid of some of the others.<br><br>Then I run Hijackthis to clear up any other junk.<br><br>Then I run the PC in safe mode and install Spysweeper.  Clean using it, and then run a few mor scans just in case.<br><br>Some UBCD plugins as well as Mwav here; &raquo;<A HREF="http://www.aptv38.dsl.pipex.com/Plugins/pluginlist.htm" >www.aptv38.dsl.pipex.com/Plugins&middot;&middot;&middot;list.htm</A><br> </DIV>Never had a time when you needed a specific fix like l2mfix or the Vundofix to get rid of anything in particular?  Or the tools included in UBCD does the trick?<br><br>Sorry about the many questions, I'm just curious and want to learn. <br><br>Thanks<br><SMALL>--<br>Operation Hold `Em"Shuffle Up and Deal"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15352702</guid>
<pubDate>Sun, 29 Jan 2006 00:17:29 EDT</pubDate>
</item>

<item>
<title>Re: Has anyone ever fixed malware/spyware thru&#x27; Ba</title>
<link>http://www.dslreports.com/forum/remark,15352658</link>
<description><![CDATA[<A HREF="/useremail/u/1063283"><b>fegul</b></A> : Using the WUBCD, I usually run the Mwav tool to scan for viruses, then I run Adaware and Spybot to get rid of some of the others.<br><br>Then I run Hijackthis to clear up any other junk.<br><br>Then I run the PC in safe mode and install Spysweeper.  Clean using it, and then run a few mor scans just in case.<br><br>Some UBCD plugins as well as Mwav here; &raquo;<A HREF="http://www.aptv38.dsl.pipex.com/Plugins/pluginlist.htm" >www.aptv38.dsl.pipex.com/Plugins&middot;&middot;&middot;list.htm</A><br><SMALL>--<br>|<A HREF="http://www.fegul.ethiofamily.com">Networking Help</A>|<A HREF="http://my.opera.com/fegul/">My Blog</A>|<A HREF="http://www.fegul.com/">Fegul.com</A>|</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15352658</guid>
<pubDate>Sun, 29 Jan 2006 00:09:20 EDT</pubDate>
</item>

<item>
<title>Re: Has anyone ever fixed malware/spyware thru&#x27; Ba</title>
<link>http://www.dslreports.com/forum/remark,15352639</link>
<description><![CDATA[<A HREF="/useremail/u/545312"><b>CTS</b></A> : Yeah, that's what I want to try do and see if I can do most of the repairing through a PE and then finish up the job in the actual environment.<br><br>Is there any additional plugins you use that's not included in UBCD?  Also, can anyone do a quick rundown of how they normally fix malware with a PE?  I'm so use to fixing malware through the actual Windows, Safe Mode, etc.<br><br>Thanks<br><SMALL>--<br>Operation Hold `Em"Shuffle Up and Deal"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15352639</guid>
<pubDate>Sun, 29 Jan 2006 00:05:56 EDT</pubDate>
</item>

<item>
<title>Re: Has anyone ever fixed malware/spyware thru&#x27; Ba</title>
<link>http://www.dslreports.com/forum/remark,15348530</link>
<description><![CDATA[<A HREF="/useremail/u/1063283"><b>fegul</b></A> : [BQUOTE=GoldengamegoIt's much easier though to use UBCD4Win (&raquo;<A HREF="http://www.ubcd4win.com" >www.ubcd4win.com</A> )<br> [/BQUOTE<br>x2.  I've used it a lot to remove malware, and it comes in very handy when safe mode still isnt that "safe" :)<br><SMALL>--<br>|<A HREF="http://www.fegul.ethiofamily.com">Networking Help</A>|<A HREF="http://my.opera.com/fegul/">My Blog</A>|<A HREF="http://www.fegul.com/">Fegul.com</A>|</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15348530</guid>
<pubDate>Sat, 28 Jan 2006 11:56:44 EDT</pubDate>
</item>

<item>
<title>Re: Has anyone ever fixed malware/spyware thru&#x27; Ba</title>
<link>http://www.dslreports.com/forum/remark,15348049</link>
<description><![CDATA[<A HREF="/useremail/u/957735"><b>Goldengamego</b></A> : <div class="bquote"><SMALL>said by  CTS <A HREF="/useremail/u/545312"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>I was just wondering if anyone had used BartPE or UBCD to fix malware or spyware and whatnot and if that works?  I know that when using BartPE or UBCD, they have their own registry so in a sense, you can't really fix the Window's infected registry unless you use a plugin that allows remote registry or how does that work?<br><br>Just wanted to hear some opinions on this.<br>Thanks<br> </DIV>It works very well, especially with malware that is capable of protecting itself (rootkits, CWS, etc).<br><br>To answer your question about the registry, regedit.exe has an option under it's file menu called "load hive" which you can use to manually load the hives from an offline system.<br><br>It's much easier though to use UBCD4Win (&raquo;<A HREF="http://www.ubcd4win.com" >www.ubcd4win.com</A> )<br><SMALL>--<br>Because Goldengamegod won't fit:p</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15348049</guid>
<pubDate>Sat, 28 Jan 2006 10:22:18 EDT</pubDate>
</item>

<item>
<title>Re: Has anyone ever fixed malware/spyware thru&#x27; Ba</title>
<link>http://www.dslreports.com/forum/remark,15347609</link>
<description><![CDATA[<A HREF="/useremail/u/590688"><b>psloss</b></A> : Yes; if I have physical access to the computer (a real console session), it's the fastest way to regain control of the computer away from "commercial" malware.  (Malware that is not targeting specific individuals.)<br><br>Since the first step in removal is to stop the software from running, BartPE or WinPE or a Knoppix CD accomplishes that step on startup.<br><br>The next step is to prevent future operation and while it is harder to see the offline Registry hives without using something like RegEditPE, you can delete the files themselves first.  For example, with a kernel driver, deleting the executable is just as effective as removing the SCM entry from the currently selected control set.<br><br>So given a UBCD "distro" or a Knoppix CD with the ability to drive an anti-virus scan (either online or off), you could scan/clean all the disk volumes (hard drives) on the computer first, and then boot back into the infected OS and run additional scans to clean Registry and other related data files.<br><br><SMALL>This is something (BartPE compatibility) I really want to add to our embryonic scanner.</SMALL><br><br>Philip Sloss<br><SMALL>--<br>Feedback? e-mail: stuff@lupwa.org</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15347609</guid>
<pubDate>Sat, 28 Jan 2006 08:43:18 EDT</pubDate>
</item>

<item>
<title>Re: Has anyone ever fixed malware/spyware thru&#x27; Ba</title>
<link>http://www.dslreports.com/forum/remark,15347320</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : &raquo;<A HREF="http://windowsxp.mvps.org/peboot.htm" >windowsxp.mvps.org/peboot.htm</A><br>&raquo;<A HREF="http://www.911cd.net/forums//index.php?showtopic=8715" >www.911cd.net/forums//index.php?&middot;&middot;&middot;pic=8715</A><br><br>never used this, but seems like it could be useful:<br><br>&raquo;<A HREF="http://ezpcfix.net/html/docs.html" >ezpcfix.net/html/docs.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15347320</guid>
<pubDate>Sat, 28 Jan 2006 05:44:19 EDT</pubDate>
</item>

<item>
<title>Has anyone ever fixed malware/spyware thru&#x27; BartPE</title>
<link>http://www.dslreports.com/forum/remark,15346085</link>
<description><![CDATA[<A HREF="/useremail/u/545312"><b>CTS</b></A> : I was just wondering if anyone had used BartPE or UBCD to fix malware or spyware and whatnot and if that works?  I know that when using BartPE or UBCD, they have their own registry so in a sense, you can't really fix the Window's infected registry unless you use a plugin that allows remote registry or how does that work?<br><br>Just wanted to hear some opinions on this.<br>Thanks<br><SMALL>--<br>Operation Hold `Em"Shuffle Up and Deal"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,15346085</guid>
<pubDate>Fri, 27 Jan 2006 23:26:28 EDT</pubDate>
</item>

</channel>
</rss>
