ComputerForum.com ComputerForum.com  

Go Back   Computer Forum > Computer Software > Computer Security

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
Old 12-15-2006, 11:12 AM   #1 (permalink)
banned
 
Join Date: Aug 2006
Posts: 4,711
Default Malware Removal Tutorial

I noticed that the Malware tutorial is severely out of date, so I thought I would make my own. You can add or counter as you deem fit.

For some background, I've been doing malware removal since 1994. I used to have my own extensive collection of virii (ok, for the "outsiders" it's viruses. lol) and distributed them via dialup BBS. They were capable of wiping out BIOS', formatting harddrives, etc. As such I have a fairly indepth knowledge of what these things are capable of. I have been doing spyware removal since it was first introduced. 90% of my current business is residential clients that are infected with up to 12,000 instances of malware.

With that said.

The tools needed to fight these threats are ever changing. As the creators become more devious, they render older tools obsolete. It is a highly competitive market. Whereas Norton used to hold the crown for virus removal, they are now for the larger part ineffective against today's threats. Etc.

There is a simple procedure to remove threats. Following the following steps precisely will greatly improve your chances of success and will dramatically decrease the amount of effort you expend.

1) In normal mode download Prevx1.

http://www.prevx.com/

Install it. Use the online updater to install the latest signature files.

In normal mode run a FULL system scan.

Remove any threats that it finds.

2) Download and install Ewido.

http://www.ewido.net/

Install it. Use the online updater to install the latest definitions.

Reboot into Safe Mode with Networking

Run a FULL system scan.

Remove any threats that it finds.

3) While in Safe Mode with Networking, download SmitFraudFix.

http://siri.urz.free.fr/Fix/SmitfraudFix.exe

Execute the tool.

4) While in Safe Mode with Networking download Autoruns.

http://www.microsoft.com/technet/sys.../Autoruns.mspx

Run it

Click on Options.

Select Include Empty Locations

Select Verify Code Signatures

Select Hide Microsoft Entries

Click through the tabs and select the things that shouldn't be there. To verify that they shouldn't be there, enter the name of the file into Google and check the descriptions on various security sites such as Liutilities and BleepingComputer.

When in doubt, do NOT delete it, rather post the item here for scrutiny.

5) While in Safe Mode with Networking, do an online virusscan.

http://www.pandasoftware.com/products/activescan

Ensure that all threats have been removed.

6) Finally, should problems still remain, download HijackThis

http://www.spywareinfo.com/~merijn/programs.php

Do a scan and save the log.

Post the log here for analysis.



Following these steps will provide a thorough cleaning of your machine. The HJT log will point out any remaining threats that can be assessed and cleaned on a case by case basis.

To protect yourself against further infections, ensure that you have Avast! which monitors your computer on numerous fronts, including webpages, Prevx1 which includes real time monitoring, and Spybot S&D Teatimer which will protect your Registry from unauthorized modifications.

Good luck and happy computing.
SirKenin is offline   Reply With Quote


Old 12-15-2006, 11:08 PM   #2 (permalink)
Platinum Member
 
Join Date: Dec 2004
Location: My House
Posts: 866
Default

nice and simple good work!
jbrown456 is offline   Reply With Quote
Old 12-15-2006, 11:36 PM   #3 (permalink)
banned
 
Join Date: Aug 2006
Posts: 4,711
Default

Thank you kind sir.

It would be good if they made it a sticky to save everyone a lot of time and frustration.
SirKenin is offline   Reply With Quote
Old 12-15-2006, 11:41 PM   #4 (permalink)
Platinum Member
 
Join Date: Dec 2004
Location: My House
Posts: 866
Default

Quote:
Originally Posted by SirKenin View Post
It would be good if they made it a sticky to save everyone a lot of time and frustration.
Agreed.
jbrown456 is offline   Reply With Quote
Old 12-16-2006, 12:53 AM   #5 (permalink)
Diamond Member
 
Emperor_nero's Avatar
 
Join Date: Sep 2006
Location: 127.0.0.1
Posts: 2,315
Default

That was really good! I hope to get into computer security as a profession so I enjoy reading other people’s ways of malware removal.
__________________
I play Rugby, and no its not like it's sissy cousin with the pads.

Emperor_nero is offline   Reply With Quote


Old 12-16-2006, 12:55 AM   #6 (permalink)
hpi
banned
 
Join Date: Dec 2006
Location: Montreal, Quebec
Posts: 1,515
Default

Very informative write up. Thanks.

Now a question: When I go into safe mode I can't go on internet?
hpi is offline   Reply With Quote
Old 12-16-2006, 01:24 AM   #7 (permalink)
Diamond Member
 
Verve's Avatar
 
Join Date: Sep 2005
Location: Tampa Bay, Florida
Age: 19
Posts: 2,503
Default

You need to go to Safemode with Networking, depending on the machine it may be worded differently.
__________________
Formerly Starwarsman
HP DV6885 Special Edition
Core2Duo T8100 @ 2.1 GHz
3GB DDR2 Ram
250GB SATA HDD
Geforce 8400m GS
Vista Home Premium SP1

The Masterplan
Verve is offline   Reply With Quote
Old 12-16-2006, 04:34 AM   #8 (permalink)
Platinum Member
 
jasonz's Avatar
 
Join Date: Oct 2006
Location: college station, tx
Age: 22
Posts: 715
Default

Prevx1-I downloaded this when you posted about it last time. 1. It is always orange and says that i am running an unknown program, but i dont know what it is and all the running processes are accepted. 2. Since, it seems like every program takes longer to open now.
jasonz is offline   Reply With Quote
Old 12-16-2006, 04:51 AM   #9 (permalink)
banned
 
Join Date: Aug 2006
Posts: 4,711
Default

That's why I posted two. One is to catch what the other misses. Follow the remainder of the steps and we'll catch the culprit. But start a new thread about it so that everyone can help and search for it later.
SirKenin is offline   Reply With Quote
Old 12-16-2006, 12:19 PM   #10 (permalink)
Administrator
 
apj101's Avatar
 
Join Date: Apr 2005
Location: London
Age: 27
Posts: 10,119
Default

Quote:
virii (ok, for the "outsiders" it's viruses. lol)
the offical plural of virus is viruses, in both biological and computer terms

i belive the best thing to do would be the integrate the best bits of this with the offical sticky. This way we can have a one shop stop
__________________
TechZine
What did one snow man say to the other?
can you smell carrot?
The fight is won or lost far away from witnesses - behind the lines, in the gym, and out there on the road, long before I dance under those lights.

How you do anything, is how you do everything!

Nauru our homeland, the land we dearly love
apj101 is offline   Reply With Quote
Reply

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Excellent spyware removal tool SirKenin Computer Security 9 10-04-2006 04:02 AM
hijackthis log spkenn5 Computer Security 11 07-08-2006 07:34 PM
wireless connection fails after spyware removal mikekelly Laptop and Smartphones 5 08-27-2005 07:37 PM
Malware Removal Tools Cache Computer Security 3 06-15-2005 12:57 AM


All times are GMT +1. The time now is 08:37 PM.


Powered by: vBulletin Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0 ©2009, Crawlability, Inc.