Malware Removal Tutorial

SirKenin

banned
I noticed that the Malware tutorial is severely out of date, so I thought I would make my own. You can add or counter as you deem fit.

For some background, I've been doing malware removal since 1994. I used to have my own extensive collection of virii (ok, for the "outsiders" it's viruses. lol) and distributed them via dialup BBS. They were capable of wiping out BIOS', formatting harddrives, etc. As such I have a fairly indepth knowledge of what these things are capable of. I have been doing spyware removal since it was first introduced. 90% of my current business is residential clients that are infected with up to 12,000 instances of malware.

With that said.

The tools needed to fight these threats are ever changing. As the creators become more devious, they render older tools obsolete. It is a highly competitive market. Whereas Norton used to hold the crown for virus removal, they are now for the larger part ineffective against today's threats. Etc.

There is a simple procedure to remove threats. Following the following steps precisely will greatly improve your chances of success and will dramatically decrease the amount of effort you expend.

1) In normal mode download Prevx1.

http://www.prevx.com/

Install it. Use the online updater to install the latest signature files.

In normal mode run a FULL system scan.

Remove any threats that it finds.

2) Download and install Ewido.

http://www.ewido.net/

Install it. Use the online updater to install the latest definitions.

Reboot into Safe Mode with Networking

Run a FULL system scan.

Remove any threats that it finds.

3) While in Safe Mode with Networking, download SmitFraudFix.

http://siri.urz.free.fr/Fix/SmitfraudFix.exe

Execute the tool.

4) While in Safe Mode with Networking download Autoruns.

http://www.microsoft.com/technet/sysinternals/utilities/Autoruns.mspx

Run it

Click on Options.

Select Include Empty Locations

Select Verify Code Signatures

Select Hide Microsoft Entries

Click through the tabs and select the things that shouldn't be there. To verify that they shouldn't be there, enter the name of the file into Google and check the descriptions on various security sites such as Liutilities and BleepingComputer.

When in doubt, do NOT delete it, rather post the item here for scrutiny.

5) While in Safe Mode with Networking, do an online virusscan.

http://www.pandasoftware.com/products/activescan

Ensure that all threats have been removed.

6) Finally, should problems still remain, download HijackThis

http://www.spywareinfo.com/~merijn/programs.php

Do a scan and save the log.

Post the log here for analysis.



Following these steps will provide a thorough cleaning of your machine. The HJT log will point out any remaining threats that can be assessed and cleaned on a case by case basis.

To protect yourself against further infections, ensure that you have Avast! which monitors your computer on numerous fronts, including webpages, Prevx1 which includes real time monitoring, and Spybot S&D Teatimer which will protect your Registry from unauthorized modifications.

Good luck and happy computing. :)
 
That was really good! :) I hope to get into computer security as a profession so I enjoy reading other people’s ways of malware removal. :)
 
Very informative write up. Thanks.

Now a question: When I go into safe mode I can't go on internet?
 
You need to go to Safemode with Networking, depending on the machine it may be worded differently.
 
Prevx1-I downloaded this when you posted about it last time. 1. It is always orange and says that i am running an unknown program, but i dont know what it is and all the running processes are accepted. 2. Since, it seems like every program takes longer to open now.
 
That's why I posted two. One is to catch what the other misses. Follow the remainder of the steps and we'll catch the culprit. But start a new thread about it so that everyone can help and search for it later.
 
virii (ok, for the "outsiders" it's viruses. lol)
the offical plural of virus is viruses, in both biological and computer terms ;)

i belive the best thing to do would be the integrate the best bits of this with the offical sticky. This way we can have a one shop stop
 
the offical plural of virus is viruses, in both biological and computer terms ;)

i belive the best thing to do would be the integrate the best bits of this with the offical sticky. This way we can have a one shop stop

Officially you're right.. But in hacker circles it's "virii". I believe you can find something to that effect on Wikipedia if I'm not mistaken.

Merging the threads is probably a really good idea actually.
 
No slack. :D If you really want me to point out the flaws in your "tutorial", I will. I'll just link to the thread where you worked on my comp. :D
 
Funny, you're the only one I've helped in here that had problems... And you're the only one that's openly demonstrated issues with me (and my wife for that matter). Coincidence? I doubt it.

Just merge the threads, will ya? Many people will benefit and that was the whole point. Keep your personal beefs out of this. For King and Country.
 
They wont be merged, they will be intergrated as buzz see's fit.

Integrated, merged, whichever works the best. As long as credit is given where credit is due it matters not.. Just so long as the info is made available to everyone I'm cool with it.

I dont think he is

Heh.. I'm not going to get started... But I have links, including posts of his that were deleted for being overtly offensive. I never bluff. Not even at poker (and I still made 324k at Poker Stars. lol). :P
 
i cant always tell when your lying....how? you post something

pokerstarsay7.jpg



;)


The first thing you should learn about me is that I never lie. Honesty is the most important virtue that I demand, above all else.
 
Back
Top