Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Friday, January 16, 2015

How to Check for Spyware, Malware Infection

This article will present various ways to check whether your PC is infected by malware, virus and other nasties. Firstly, here is a recollection of other related posts in this blog, so I will show the link here instead of writing the same material again. The new material will be after that.

How to Check for Botnets

Security - Protection against Botnets

Windows Server 2008 - Firewall, Antivirus, AntiSpyware

Security Software Review, Discounts and Special Deals

Links to Smartphone Mobile Security Software

Malware: Windows Enterprise Defender and Windows Diagnostics

Online Scan - PC tools

Online Scan - Websites

Online Scanning websites and links for virus, malware, spyware

Online Scan - AntiVirus

Now for some new stuff. Some tools that can be downloaded and used are:


Google and download: TDSSKiller
- Start tdsskiller - Run as Administrator.
- Click on Change parameters.
- Check all options except "Loaded modules" and click OK.
- Then click on Start scan.
- When threats are found, choose the Skip option for all of them, instead of deleting.
- To open the log file, click on Report. Or it can be found in :\TDSSKiller.<version_date_time>_log.txt


Google and download: Farbar Recovery Scan Tool.
- Start FRST - Run as Administator.
- Select the option Addition.txt as well as others selected by default. Press the Scan button.
- FRST will create two logs - FRST.txt and Addition.txt - in the same directory the tool was run from.

Some list of tools and other advice can be found on:
https://www.makeuseof.com/tag/download-operation-cleanup-complete-malware-removal-guide/

Thursday, January 19, 2012

How To Clean Up Windows

This article prevents some ideas of how to clean up your computer which has the Windows Operating System. The clean up here does to refer to any kind of virus or spyware removal. Instead, this article focuses on how to get rid of the junk that we or Windows itself accumulates on your computer throughout the years.

1. Scan using antivirus.
Although this article is not about removing virus but on the cleaning of junk files, one of the first step is to simply do a virus scan - just in case. Some useful articles are:
- using online virus scanners: http://xtechnotes.blogspot.com/2008/07/antivirus-online-scan.html
- discounted antivirus software http://xtechnotes.blogspot.com/2012/01/security-software-discounts-and-special.html
- news on security http://xtechnotes.blogspot.com/2011/08/news-security.html
- how to secure your computer: http://xtechnotes.blogspot.com/2010/03/how-to-secure-your-computer.html

2. Remove all unwanted programs.
Find a list of all your installed programs by going to Control Panel - Add or Remove Programs.
Decide which programs you do not need and uninstall them.
- some uninstaller software: http://xtechnotes.blogspot.com/2011/07/links-to-free-software.html

3. Find what is running in the background
Windows services are programs that run in the background after starting up themselves when the computer is switched on. Many will not tell you they are running. To find a list of these "services", go to Control Panel - Administrative Tools - Services.
Find those services which you know is definitely not needed, whether they are from Windows or not. There is no clear way to identify which service you don't want - they will come from experience. Basically just look at the name of the services - a weird name does not mean it is not needed. Sometimes look for a service with a simple name which you definitely know is not required. Example: If your computer has no wireless connection, then look for service with the name wireless and Disable it.

4. Clean the Registry
WARNING: If anything goes wrong at this step, very often this will make your whole computer unable to start and you may lose everything.
This step should be done by experienced users only.
Some tools to check are: CCleaner and TweakNow RegCleaner. (see http://xtechnotes.blogspot.com/2011/07/links-to-free-software.html )

5. Are all your files compressed?
Some computers may have come out of the box, configured to compress all your files by default. In Windows Explorer, if your files has filenames appearing in colour, then it may be compressed. To switch off this option, in Windows Explorer, right click on the folder and select Properties. Then uncheck any box for compression, for that file, folder or the entire drive.

6. Check updates
Ensure all updates including Windows Update and other antivirus updates are up to date.

7. Avoid re-installing Windows
Only reinstall Windows as a very last resort.

8. Cleaning Temporary Files
Ref: http://forum.wegotserved.com/index.php/tutorials/article/72-keeping-your-system-partition-cleaned-up-on-a-schedule/

C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\*.*
c:\temp\*.*
c:\windows\kb*.log
c:\windows\temp\*.*

- delete windows update uninstall files
dir c:\windows\$nt*

- delete Internet Explorer update uninstall files
dir c:\windows\ie8updates






..... any more ideas are appreciated ....

Saturday, March 26, 2011

Malware: Windows Enterprise Defender and Windows Diagnostics

A recent PC malware virus I solved had the Windows Enterprise Defender and Windows Diagnostics.

This is a well known malware (Google it!) where the PC suddenly pops up a dialog that looks like it is scanning your PC and finds many virus or spyware. In fact, the idea is to scare people into clicking on something, whether to buy or to let more malware into the computer. There are many search found on this from Google (see References below) but here is what worked for me.

Disconnect from Internet - No LAN, No WAN.

Any software mentioned below is actually downloaded on another PC, burned into DVD and then used on the infected PC. To be safe I even avoided hooking any USB key or USB portable drive to the infected PC. The main idea is that: nothing goes in or out of the infected PC while you are trying to cure it.

Install WinPatrol 2011

Install Malware Bytes 1.5.0, then run and scan. Remove anything suspicious it can find.

Install free version of Avira Antivirus. Before run and scan, go to
http://www.avira.com/en/support-vdf-update-info and download the relevant updates for Avira Antivirus.
Then open Avira, go to Update menu and do Manual Update.
It will ask where the file is, you should point it to the update file which you manually downloaded from above.
After the Avira update, run several types of scan, such as scan all drives and Complete System Scan.
Remove anything which Avira found suspicious.

If you are unable to scan in any way, Reboot Windows in safe mode and run the scans if possible.

Install the following software just to double check that there are no more surprises:
- Kaspersky Virus Removal Tool 2010
- Prevx Free 3.0
- TDSS Killer (also from Kaspersky)
- IObit 360
- Spybot Search and Destroy.

I found that I did not had to manually change any registry settings so far.
The following registry entries stated in 2-spyware site below are not on my computer:
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\WindowsEDefender.DocHostUIHandler
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes "URL" => "http://search-gala.com/?&uid=7&q={searchTerms}"
HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes "URL"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "[xSP_2:61a6083b6194a2314e3dd54cf9615e36_7]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "876902803"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Windows Enterprise Defender"



References:
http://www.2-spyware.com/remove-windows-enterprise-defender.html
Seems to have very good instructions to remove Windows Enterprise Defender.


http://www.bleepingcomputer.com/forums/topic385402.html
Many searches point to this site. I have read this but have not actually tried the methods suggested there. The first step involve TDSS Rootkit Removal Tool. The second step involved ComboFix. The reason I did not even start following this advice is that the ComboFix tool which they suggest to use, appears to be produced or hosted by the same website bleepingcomputer. Apart from a potential conflict of interest, something just made me be careful of using a software ComboFix, recommended by a blog that is from the same company as the blog.

The TDSSKiller.exe from Kaspersky may be worth a look.


http://answers.yahoo.com/question/index?qid=20110320101354AAZ6G8Y