Recommended Posts

Ok, I'm fixing a pc for a friend. When I turned on the computer I was blocked out by some dumb message about copyrights and wanting to pay $200. Finally was able remove some of the files, delete from start up, etc. installed spy bot search and destroy, ran the scan and removed all entries. Used the pc on and off for a few days. No issues. Gave the pc back... Within 2 days...it's back. Is there a better freeware scanner/remover for this. I'm at my wits end with this.

Link to comment
https://www.neowin.net/forum/topic/1120426-need-help-removing-virusmalware/
Share on other sites

1. Boot in safemode

2. Empty ALL temp folders, including user temp folders, not just windows

3. Reset IE, checking the box to delete everything

4. Open regedit:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

and

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Delete any suspicious looking entries

Also delete anything in HKEY_CURRENT_USER\Software and HKEY_LOCAL_MACHINE\SOFTWARE that look malware related

Open MSCONFIG and disable anything that looks suspicious in there too

----------

Reboot in normal mode, and run a full scan with a fully updated malwarebytes

You have already scanned with spybot but do it again anyway

Another good thing is installing Avast Free, and do a "Boot Time Scan" this will be able to remove malware that can not be killed inside of windows

Download and run a scan with "Hijack This" remove any suspicious entries in there too

Scan a couple of times with all the above programs until they all return a clean result

If you still have a problem after all that, wipe > reinstall windows

  • Like 3

What exactly would be considered suspicious? I'd assume they would label anything that would set off red flags..

Well just anything you don't recognise as being installed on the machine as a genuine app, a lot of malware will have registry keys with weird symbols, such as !"?$%^&*&()_) or the name of the fake AV that pops up

Normally pretty easy to spot, the first 2 keys I mentioned are what windows calls to startup with windows, so if you don't want anything starting up with windows, delete those keys, and in MSCONFIG

Latest version is 2.04....It doesn't work properly with 64bit oses. It also doesn't dig as deep as otl.

Compare a hjt log with a otl log.

sample otl log

http://www.bleepingc...opic313328.html

sample hjt log

http://www.techsuppo...down-14837.html

which do you think is more thorough and can help you better find the cause?

Latest version is 2.04....It doesn't work properly with 64bit oses. It also doesn't dig as deep as otl.

Compare a hjt log with a otl log.

Ok, never used OTL, still HijackThis is a decent app, using both would be better than not using HJT, never had a problem with HJT and 64bit OSs though

read about hjt and 64 bit, while this isn't necessarily a problem people unfamiliar with it will go to disable critical processes and screw their computers up more. I don't recommend running this as a novice, nor do I recommend running it over the internet being that people can be tempted to try to fix it themselves causing more issues. bottom line, it doesn't work well with 64 bit oses and otl produces the similar findings as hjt with many more pieces to the os puzzle (more files, more reg entries, more points of infection, etc). Running otl with a good rootkit detection software, like gmer, will allow you, the tech, to actually find something useful and be able to repair the computer.

http://www.experts-e...it-Systems.html

That being said, it may take a few hours to go through and verify a otl report.

read about hjt and 64 bit

http://www.experts-e...it-Systems.html

Well that doesn't render HJT useless on 64bit systems, we're not looking for missing file entries, we're looking for malware entries, make no difference if HJT can't find 64bit files

And more to the point, I don't know many 64bit versions of malware

Well that doesn't render HJT useless on 64bit systems, we're not looking for missing file entries, we're looking for malware entries, make no difference if HJT can't find 64bit files

And more to the point, I don't know many 64bit versions of malware

not exactly useful either. if it is not useful, it is useless IMO.

you could do what others said and waste your time, or do what will be the easiest. Download a 10 meg file mawarebytes.com from here (filehippo link) on to a usb key. Boot into safe mode, install, run a scan, let it remove it. Done. If you want to do it the hard way, follow the other posts above.

Secret....malware bytes doesn't remove everything. Their root kit detection piece is still in beta last time I checked. Malware bytes is not the end all be all.

I have been around a lot of malware, and I can tell you with 100% certainty that malware bytes doesn't remove all of it. Just a good portion. I run a min of three different removal utilities mwb being one of them when cleaning computers. Mwb isnt the first thing i run, it is the last. I do know its limitations.

Secret....malware bytes doesn't remove everything. Their root kit detection piece is still in beta last time I checked. Malware bytes is not the end all be all.

I have been around a lot of malware, and I can tell you with 100% certainty that malware bytes doesn't remove all of it. Just a good portion. I run a min of three different removal utilities mwb being one of them when cleaning computers. I do know its limitations.

after servicing a couple thousand machines over the last couple years , i have had a 100% success ratio with malwarebytes when scanning in safe mode. Could you give me an example of malware that it can't remove? I would like to download it and see for myself.

note: i LOVE getting new stuff to test virus removal techniques. being serious.

Pick any root kit. The Remote Desktop attack 6months ago it couldn't detect (MSE was the first that did). Had problems finding, file name was close to a windows file name and I kept overlooking it.

I have been doing manual virus removal since late 90s. I have thousands over you. Hell, the hospital I was working at had a whole site infection over 10000 computers and hundreds of servers. Nightmare.

Pick any root kit. The Remote Desktop attack 6months ago it couldn't detect (MSE was the first that did). Had problems finding, file name was close to a windows file name and I kept overlooking it.

I have been doing manual virus removal since late 90s. I have thousands over you. Hell, the hospital I was working at had a whole site infection over 10000 computers and hundreds of servers. Nightmare.

could you give me even just 1 name of a rootkit that you could not remove with it? the worst one in your mind/experiance

you could do what others said and waste your time, or do what will be the easiest. Download a 10 meg file mawarebytes.com from here (filehippo link) on to a usb key. Boot into safe mode, install, run a scan, let it remove it. Done. If you want to do it the hard way, follow the other posts above.

This. Why make the removal process difficult?

could you give me even just 1 name of a rootkit that you could not remove with it? the worst one in your mind/experiance

Is it that hard to google root kit names, like I said pick one any one. Pull any one out of a google search. Malware bytes is 100% ineffective against any root kit. It doesn't have the scan engine for it, therefore it can't detect or repair against this type of infection. Google redirect is one.

Here you go read through and you will see that the user running malware bytes has no effect against it. http://www.bleepingcomputer.com/forums/topic434638.html

Huh? How is it not useful ?

What do you have against HJT ? It works, what more do you want ?

I don't like doing things twice and skimming through information I have been through before.

Is it that hard to google root kit names, like I said pick one any one. Pull any one out of a google search. Malware bytes is 100% ineffective against any root kit. It doesn't have the scan engine for it, therefore it can't detect or repair against this type of infection. Google redirect is one. Here you go read through and you will see that the user running malware bytes has no effect against it. http://www.bleepingcomputer.com/forums/topic434638.html I don't like doing things twice and skimming through information I have been through before.

Ok, well each to their own, lets not hijackthis thread with our differences ;)

Is it that hard to google root kit names, like I said pick one any one. Pull any one out of a google search. Google redirect is one.

Surprised you could not give one from your own extensive experiences and instead saying Google one. I am having no luck finding an .exe for the google redirect to infect myself with. Google is full of solution links and no actual download links (of course and expected). Do you know where i can get the .exe file? Or maybe a website that does give the infection?

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • You're absolutely right! No reason in hell these should be on the road!
    • They aren't going to want to. Most would just go with the 17 Pro and save money. Why would they want to spend $300 for basically the same thing? It's not worth it if there are hardly any changes from year to year.
    • 24H2 rolled out to the Release Preview Channel in early June 2024, so this coming a bit later in the Experimental Channel (formerly Dev) doesn't really say much more than earlier H2 releases that came out in October. I am not sure what the thinking is here by putting it in Experimental, one would think that the 26H2 stamp means features are locked down and it's now bug tested until October? I don't even pretend to understand Microsoft's strategy for Windows Insider Program though
    • Nothing Ear (a) and CMF Buds Pro 2 with active noise cancellation drop to lowest price ever by Fiza Ali With Prime Day 2026 scheduled to run from Tuesday 23 to Friday 26 June, Amazon has already begun rolling out early access offers ahead of the main event. Particularly, Nothing Ear (a) and CMF Buds Pro 2 wireless earbuds have dropped to their lowest price ever with limited Prime deal offering 33% and 24% discounts, respectively. Nothing Ear (a) are equipped with 11mm dynamic drivers featuring a PM1 + TPU diaphragm. For noise control, the earbuds offer active noise cancellation (ANC) of up to 45dB across frequencies reaching 5,000Hz. The smart ANC algorithm adapts to surrounding noise levels, while a Transparency Mode allows users to remain aware of their environment when needed. Connectivity is handled via Bluetooth 5.3, with support for AAC, SBC, and LDAC audio codecs. Additional features include IP54-rated earbuds for dust and splash resistance, paired with an IPX2-rated charging case. Furthermore, users also benefit from pinch controls, in-ear detection, Google Fast Pair, Microsoft Swift Pair, dual-device connectivity, and a low-latency mode designed for gaming and video playback. The Nothing X app unlocks a range of customisation options, including a personalised equaliser, bass enhancement, control remapping, ear tip fit testing, firmware updates, dual-device management, a Find My Earbuds feature, and low-latency mode settings. When it comes to the battery, the earbuds house a 46mAh lithium-ion battery, while the charging case contains a 500mAh cell. With ANC disabled, users can expect up to 9.5 hours of playback from the earbuds and up to 42.5 hours in total with the charging case. With ANC enabled, battery life is rated at up to 5.5 hours per charge and up to 24.5 hours combined with the case. Finally, fast charging is also supported that should provide up to 10 hours of playback from a 10-minute charge with ANC turned off. Nothing Ear (a) Wireless Earbuds (Black): $53.20 (Amazon US) - 33% The CMF Buds Pro 2 feature a dual-driver audio system consisting of an 11mm bass driver and a 6mm micro-planar tweeter. The earbuds use PU (polyurethane) and PET (polyethylene terephthalate) titanium-coated diaphragms and are tuned by Nothing to deliver balanced audio performance. They further support active noise cancellation of up to 50dB across a frequency range of up to 5,000Hz, and noise control features include a Smart ANC algorithm, Adaptive ANC, Transparency Mode, and Clear Voice Technology 2.0. For calls, the CMF Buds Pro 2 use a total of six microphones and feature an environmental noise-cancelling algorithm, Clear Voice Technology 3.0, and Wind Noise Reduction 3.0 that should improve voice clarity during conversations. Furthermore, when it comes to the connectivity, it is provided through Bluetooth 5.4. Additional features include an IP55 rating for dust and water resistance, Google Fast Pair, Microsoft Swift Pair, in-ear detection, a low-latency mode, and a Find My Earbuds function. Moreover, through the Nothing X app for Android and iOS, users can access custom EQ settings, a bass enhancement algorithm, customisable controls, Find My Earbuds, low-latency mode, dual-device connectivity, an ear tip fit test, and firmware updates. The earbuds contain a 60mAh rechargeable lithium-ion battery, while the charging case houses a 460mAh battery. A full charge of the earbuds and case via USB-C should take approximately 85 minutes, while the earbuds alone should be fully recharged in the case in around 60 minutes. Battery life is rated at up to 11 hours of playback on a single charge and up to 43 hours with the charging case when ANC is turned off. With ANC enabled, playback time is reduced to up to 6.5 hours on the earbuds and up to 26 hours with the charging case. Talk time is rated at up to 6 hours on the earbuds and 25 hours with the case with ANC disabled, or up to 4.8 hours and 18.6 hours, respectively, with ANC enabled. CMF Buds Pro 2 Wireless Earbuds (Dark Grey): $37.05 (Amazon US) - 24% Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
  • Recent Achievements

    • Collaborator
      ryansurfer98 went up a rank
      Collaborator
    • Week One Done
      Eurosoft10 earned a badge
      Week One Done
    • One Month Later
      Eurosoft10 earned a badge
      One Month Later
    • One Year In
      Skeet Campbell earned a badge
      One Year In
    • One Month Later
      Sharbel earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      542
    2. 2
      +Edouard
      186
    3. 3
      Michael Scrip
      77
    4. 4
      PsYcHoKiLLa
      76
    5. 5
      Steven P.
      71
  • Tell a friend

    Love Neowin? Tell a friend!