Malware infection question


Recommended Posts

Usually when I have somebody come up to me with a computer that has Malware on it, I simply re install everything for them. Say what you want abotu it, but it is much faster to re-install than spend potentially days fixing the computer and making sure it is right before they go back to their banking.

So my question is this, I usually do a format, and re-install. Will a Windows 8 Clean Install Upgrade get rid of infections? I only ask because it still does make a Windows.Old folder if I remember. Couldn't the malware be in there when it is all done?

Lastly, has there been any word as to the $40 Windows 8 upgrade and installing it on a fresh drive? When I installed it, I needed Windows 7 fully installed before in order to get 8 to activate.

Link to comment
https://www.neowin.net/forum/topic/1120900-malware-infection-question/
Share on other sites

You should be able to format the HDD with the upgrade media, yes. At least I could with mine...

Ah I gotcha. So I think what I am understanding right is that I DO need to have some previous Windows version installed, but when I boot with the Windows 8 media, I can format it there just like Windows 7? That is probably why it did not work for me, nothing was on the drive when I tried.

3 hours, if it takes longer than 3 hours you are doing it wrong or they have a million files or so or a computer built in 1990.

I spend a few hours cleaning it, if it comes back within a week, which rarely does, I wipe and rebuild. You need new techniques.

On to your question, if you don't delete the partition and reformat the infection can still be in the boot sector. In the past, when doing a clean install from a upgrade disk you would just need to put in your old os media (xp, vista, etc).

Ah I gotcha. So I think what I am understanding right is that I DO need to have some previous Windows version installed, but when I boot with the Windows 8 media, I can format it there just like Windows 7? That is probably why it did not work for me, nothing was on the drive when I tried.

I also have 3 HDD's in my machine, which could have triggered the option to pop up. :p

3 hours, if it takes longer than 3 hours you are doing it wrong or they have a million files or so or a computer built in 1990.

I spend a few hours cleaning it, if it comes back within a week, which rarely does, I wipe and rebuild. You need new techniques. If you don't format, the infection can still be in the boot sector.

I seem to notice more and more that people's solution to a computer that doesn't work or is infected seems to be "step 1: format the machine." It's bizarre, for me a format has always been the final option, not the first. I would have lots of unhappy customers if I kept taking their laptop away and wiping it. :laugh:

I seem to notice more and more that people's solution to a computer that doesn't work or is infected seems to be "step 1: format the machine." It's bizarre, for me a format has always been the final option, not the first. I would have lots of unhappy customers if I kept taking their laptop away and wiping it. :laugh:

No one would trust me to do squat and word of mouth would be nil. Have to keep people happy, have to be fast, and have to keep data integrity. They want their computer back in a working state with all of their apps and files in tact.

I seem to notice more and more that people's solution to a computer that doesn't work or is infected seems to be "step 1: format the machine." It's bizarre, for me a format has always been the final option, not the first. I would have lots of unhappy customers if I kept taking their laptop away and wiping it. :laugh:

Format and reinstall is the only way to be 100% sure the malware is gone. I swear by this and its always my first option. Also you will have less repeats when this happens. Customers are alot careful due to the format and reinstall.
Format and reinstall is the only way to be 100% sure the malware is gone. I swear by this and its always my first option. Also you will have less repeats when this happens. Customers are alot careful due to the format and reinstall.

Sorry, I disagree. As sc302 said, all wiping their machine will do is send them to someone else next time who will attempt to preserve their data and settings. If someone on my team suggested formatting a machine as the first step, I'd have them removed from my team.

See we like our customers and like referrals. Referrals is free money. I spent 0 advertising dollars to get them in my door. I formatted once and cost a client and a minimum of 10 of their friends. I explained what was needed and she was not happy then when she picked up her computer she wasn't happy that I didn't have everything back to the way it was when she gave it to me. To get her out the door I had to eat it. Never has it happened again. Most people appreciate the effort and understand that if it needs to come back within a week that they should have a backup performed (I charge extra for the backup) but will wipe and rebuild their computer with any software they provide at no additional cost.

Again, that doesn't happen often. Once last year was the last I can remember.

Sorry, I disagree. As sc302 said, all wiping their machine will do is send them to someone else next time who will attempt to preserve their data and settings. If someone on my team suggested formatting a machine as the first step, I'd have them removed from my team.

I'm with you on this one, I used to just wipe and reinstall, but once I was trained up in a repair shop on how to remove malware thoroughly, formatting is only the very last option if all else fails.

I became pretty good at killing malware that more often than not, once I had done all my manual steps, scanners such as malwarebytes wouldn't find any leftovers for things like Antivirus 2010 fake AVs etc

I'm on both sides of this

1) If I was infected with malware (which I have never been) I would restore from a good image. after the malware was removed I would not use the installation in its current state. I would never again trust it.

2) None of us can be 100% sure we got everything it's impossible. Having said that when i'm done I am pretty confident the infection is gone. Rarely do I reformat and very rarely do I get any systems immediately back.

3) 3 hours can be about right. Hell a full scan with malwarebytes is usually 40 mins. I also do an external scan with kaspersky rescue from outside of windows. That can be another 40 mins or longer. I usually remove all temp and internet temp files (usually with ccleaner) to make the scans go as fast as possible.

4) If I had to format and reinstall I don't see my customers saying bad things about. It's not they would loose all their data.

3) 3 hours can be about right. Hell a full scan with malwarebytes is usually 40 mins. I also do an external scan with kaspersky rescue from outside of windows. That can be another 40 mins or longer. I usually remove all temp and internet temp files to make the scans go as fast as possible.

I always run CCleaner before Malwarebytes, works a treat to get all the junk cleared out before you scan for infection. Those two go together like peanut butter and jelly ;)

I always run CCleaner before Malwarebytes, works a treat to get all the junk cleared out before you scan for infection. Those two go together like peanut butter and jelly ;)

Correct, if you don't remove those internet temp files first 1 scan can EASILY! TAKE 2 hour - 3 hours. Yesterday I removed someones internet temp files, they had over 100,000 Internet temp files.

Correct, if you don't remove those internet temp files first 1 scan can EASILY! TAKE 2 hour - 3 hours. Yesterday I removed someones internet temp files, they had over 100,000 Internet temp files.

I once saw it remove over 15GB of temp files. I was floored...

I once saw it remove over 15GB of temp files. I was floored...

I sometimes use ccleaner, but sometimes I remove the internet temp files by hand and then rerun ccleaner for the rest of the files. ccleaner takes FOREVER to remove what takes far less time doing it by hand. As far as the reinstalls go, before I format I also backup their software registry Hive. I then run that through a product key finder and it extracts a lot of their product keys which allows me to reinstall some of their stuff for them, like office, norton and such.

I'm on both sides of this

1) If I was infected with malware (which I have never been) I would restore from a good image. after the malware was removed I would not use the installation in its current state. I would never again trust it.

2) None of us can be 100% sure we got everything it's impossible. Having said that when i'm done I am pretty confident the infection is gone. Rarely do I reformat and very rarely do I get any systems immediately back.

3) 3 hours can be about right. Hell a full scan with malwarebytes is usually 40 mins. I also do an external scan with kaspersky rescue from outside of windows. That can be another 40 mins or longer. I usually remove all temp and internet temp files (usually with ccleaner) to make the scans go as fast as possible.

4) If I had to format and reinstall I don't see my customers saying bad things about. It's not they would loose all their data.

Just to put something out there.

If you actually know what you are doing, then yes you can be 100% certain it is gone. If you send a customer a machine where you are only pretty certain it is gone, then that's really bad.

That is just inviting all sorts of headaches, especially if you didn't get it and they have their identity stolen.

If you cannot take the time to be certain you have eliminated the threat then send them to someone else or close shop.

Man, I really am getting more like Ramsay as time goes on...

Just to put something out there.

If you actually know what you are doing, then yes you can be 100% certain it is gone. If you send a customer a machine where you are only pretty certain it is gone, then that's really bad.

That is just inviting all sorts of headaches, especially if you didn't get it and they have their identity stolen.

If you cannot take the time to be certain you have eliminated the threat then send them to someone else or close shop.

Man, I really am getting more like Ramsay as time goes on...

If you want to go through every registry key and reverse engineer every file on the hard drive be my guest. What I'm saying is using the tools that I use, they tell me the system is clean. The issue they came in with is no longer there. I inspect the system and known malware locations, and running processes, host files, .... nobody can be 100% sure.

The last scan of many I do, is an external system scan with a kaspersky rescue disc, just to make sure I do the best I can to find infections that are trying to hide from the running OS.

I never had an issue with a customer being mad because of a format and reinstall. I have had issues where one of our other technicians tried to clean a system and return it to a customer only to have them come back again. I would sooner say in the position I am in I would get more angry people with the removal than I would the clean install. If the customer has data they must keep I boot them to something where they can back up the files to an external they provide. Once that is done then I blast away the system. Either way the risk of ID theft and such is too great to let the customer just leave with a simple removal.

If you want to go through every registry key and reverse engineer every file on the hard drive be my guest. What I'm saying is using the tools that I use, they tell me the system is clean. The issue they came in with is no longer there. I inspect the system and known malware locations, and running processes, host files, .... nobody can be 100% sure.

Yes exactly, if I tell my clients that do their banking and sensitive information that I could spend 3 or more hours fixing it, or spend the same amount of time re-installing. Most of them prefer re-installing.

It is much faster for me to install fresh and install their programs, than it is to try to mess with it. This is why I format, not because I am too stupid to clean it. But when people bank and have their tax stuff on there, you better be damn sure they prefer to wipe it.

I have my methods, you have yours. This post was not to get on me for my format choice. In my experience, it is much faster, and after I do a format I make a disk image and give it to them if they need it.

If you want to go through every registry key and reverse engineer every file on the hard drive be my guest. What I'm saying is using the tools that I use, they tell me the system is clean. The issue they came in with is no longer there. I inspect the system and known malware locations, and running processes, host files, .... nobody can be 100% sure.

The last scan of many I do, is an external system scan with a kaspersky rescue disc, just to make sure I do the best I can to find infections that are trying to hide from the running OS.

Doing that is not necessary to ensure the system is clean.

You can be certain and if you're not confident in your work being 100% accurate it has no business going back to a customer.

Going back to the Ramsay point. If you work in a restaurant are going to serve food you think isn't spoiled or food that you know isn't spoiled?

If it is the former the then I don't want you in my kitchen. :p

If you want to go through every registry key and reverse engineer every file on the hard drive be my guest. What I'm saying is using the tools that I use, they tell me the system is clean. The issue they came in with is no longer there. I inspect the system and known malware locations, and running processes, host files, .... no body can be 100% sure.

I so agree...one has to remember also you can not spent many hours or even days on a machine if you are in business , you are paid for volume of machines you put thru and your roi (return on investment) diminishes each hour you work on a machine. For the sake of discussion let's say you charge $200 (or something eqivilent in your currency) to fix it, 4 hours to reload it $50 an hour, 8 hours to find and kill malware $25 an hour and you have worked twice as hard

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Likely nothing will be done in corporate America, there have been countless Tesla self-driving incidents. Then again, there have also been countless human operated incidents. It's literally daily news here in Canada, to the extent that it's now odd if we get a day where a collision doesn't get announced on the radio throughout the day...
    • SKG Hand Massager with Heat OS500 hands on by Steven Parker I was offered the chance to test out the SKG Hand Massager with Heat OS500, and full disclosure, they let me keep it regardless of my findings. Anyway, I jumped at the chance due to my long hours sitting at my desk, mousing around. Apologies for the knife cut across the top of the box; that was my doing, being a bit too heavy-handed with opening up the outer packaging. First up, what's in the box: SKG Hand Massager with Heat OS500 1x Type-C charging cable User Manual 1-Year Warranty (card) In short, everything you need to get started. According to the official Amazon listing, here are the key features: Full-Hand Air Compression: OS500 wraps your fingers, palm, and wrist with multi-chamber air compression for a complete hand relaxation experience. The extended massage chamber helps cover more of the hand and wrist area than standard palm-only hand massagers Palm Kneading with 6 Modes & 6 Intensities: Built-in palm kneading rollers add a hands-on massage feel, while 6 preset modes and 6 pressure levels let you choose the comfort level that fits your day—from gentle relaxation to a firmer full-hand massage 3 Heat Levels with Cooling Fan: Choose from 104°F, 113°F or 122°F warmth to suit different seasons and comfort preferences. The built-in cooling fan helps reduce stuffiness during heated sessions, keeping your hand feeling fresh and comfortable Easy Visual Display & Smart Timer: The digital image display clearly shows massage area, mode, intensity, heat level, and remaining time at a glance. Select 10, 15, or 20-minute sessions for quick office breaks, evening relaxation, or everyday hand care Rechargeable, Cordless & Comfortable: A 3000mAh battery supports over 90 minutes of full-function use on a full charge, with convenient USB-C charging. The soft inner lining, smooth ABS/PU finish, and premium black-gold design make OS500 ideal for home, office, or gifting With all that out of the way, here are my own findings. I gave it a try on both left and right hands, and as you can maybe see from the above YouTube Short, (sorry for the shaky video), my whole hand fits in, but my wrist barely enters the Hand Massager. I was able to push through a bit more with my fingertips extending out the other end to get a bit of massaging on the start of my wrist. Usage For some reason, there is a strap that is very difficult to fasten to my wrist with one hand. I am not sure what function it has, and it isn't mentioned in the user manual. The only thing I could find was in the product images that claimed "wrist precision". Unlike the Bob and Brad Hand Massager, this device does not massage the wrist anyway, even though a "wrist mode" is mentioned, which must be for smaller hands than I have, as it is mainly intended for the hand and fingers. In addition, for its steeper price, there are no disposable gloves provided in the box, which is a bit of an issue considering the internal cover (which appears to be elasticated nylon) cannot be removed for washing; so you are left with only one choice: always thoroughly wash your hands before using it. I can imagine this thing getting a bit grimy after a period of use, and that is a bit of a shame. With that said, the buttons on the device, from left to right, do the following: Heat button: 3-level heat control at 104°F, 113°F, or 122°F Mode button: Auto mode Circular mode Soothing mode Relax mode Palm and fingers mode Palm and wrist mode Intensity button: from (First-time users) 15Ka, 25Ka, 35Ka, 45Ka, 55Ka, 60Ka (Intensive relief) Knead button: on or off (6 pressure levels) Power button: Long-press to turn on or off Cooling button: turn on or off the cooling fan Also, in the product imagery, it states there are 36 "custom modes," but nowhere is it listed what these modes are. I can only imagine that they mean a combination of all of the above settings in different intensity levels. The device itself seems to rely on a single "kneading" mechanism located at the palm area of the hand, which spins when in use, and the other massage features are mainly utilized through the air sacs, increasing and decreasing at various levels on the hand and fingers. I am not sure it offered too much relief for someone who is typing and operating a mouse for hours at a time; further testing may be required. It does feel nice, though. Finally, you may be wondering how this fits into the scope of a tech website? Well, let me tell you something: sometimes I sit for up to 15 hours working on Neowin, and although I take breaks in between, it takes a toll on my body. I think in the immediate absence of a partner to apply relief, a good massager like this Hand Massager can shed the strains of the day in just a couple of 15-minute bursts. On the official website, this has an MSRP of $99.99, but luckily for our readers, it is selling at $10 off for just $89.99 right now on Amazon. SKG Hand Massager with Heat OS500 for $89.99 (with $10 off coupon), $99.99 MSRP For me, this gets a thumbs hands(?) down. However, it could be improved by making it so that the protective covering could be removed and thrown into the washing machine, or get yourself some disposable gloves to use with it. As an Amazon Associate, we earn from qualifying purchases.
    • Thanks for the info, but I'm still not sure if I need this....
    • We check out the SKG PS700 Neck Massager by Steven Parker I was offered the chance to test out the SKG PS700 Neck Massager, and full disclosure, they let me keep it regardless of my findings. Anyway, I jumped at the chance due to my long hours sitting at my desk; I figured it could offer some neck pain relief. What's in the box: SKG PS700-2 Neck Massager Rechargeable Battery (inside massager) Type-C USB cable User Manual Quick Start guide 1-Year Warranty In short, everything you need to get started. According to the official listing, here are the key features: Biomimetic Kneading & High Torque Motor: Designed with innovative biomimetic kneading heads that perfectly simulate the touch of human hands. Powered by a high-torque motor, this massager delivers powerful and precise deep tissue relief to effectively target stiff neck muscles and release built-up tension Soothing Heat & Integrated Sound Relaxation: Experience the ultimate Relaxationation with our dual-action approach. The soothing heat function gently warms your neck, while the built-in sound Relaxation provides calming audio tracks, helping you achieve a state of mindfulness and mental tranquility during your physical massage Cordless Convenience & Travel-Ready & Father's Day Gifts: Crafted for maximum portability and ease of use. Its lightweight, cordless design allows you to enjoy a premium massage anywhere without the hassle of tangled wires-whether you're taking a quick break at your desk or winding down at home Versatile Relief for Home & Office: An essential wellness companion for office workers, gamers, frequent travelers, or anyone looking to integrate mindfulness into their daily routine. It seamlessly fits into your lifestyle, providing instant neck relief whenever and wherever you need it Safe & Premium Materials: Manufactured with high-quality, skin-friendly materials to ensure a safe and comfortable experience without irritation. SKG backs this device with dedicated customer service, making it a thoughtful tech-health gift for family and friends App & Bluetooth Music Control: Connect via Bluetooth to control your massage settings through the dedicated app and enjoy your favorite music during your massage session for a fully customizable and immersive relaxation experience Red Light Warmth Technology: Features advanced red light warmth technology that penetrates deep into neck muscles to enhance blood circulation and provide soothing comfort while relieving muscle tension and stiffness Design With all that out of the way, here are my own findings. SKG does not say what materials are used to make the neck massager. However, on the product website, it mentions "soft-touch silicone" with what looks like PU leather cushioning, with the rest being mostly made up of plastics. On the inside of the massager, there are two "biomimetic kneading heads" that are motorized for the different styles of massage, which are not actually listed at all in the paper user manual, but the standard included modes are: De-stress mode, Mediation mode, Relax mode, Shiatsu mode. The massager looks quite premium and is actually very comfortable to wear. This massager is small and light enough to go anywhere, as it doesn't get in the way of anything, so I was able to use it in the chair while writing this review. Unlike the back massager, SKG does not warn in the user guide not to use it for more than 30 minutes a day (or two 15-minute sessions). However, there is a long laundry list of important safeguards to consider before and during the use of the device, and it is warned that the neck massager is not waterproof. It also includes a 1,400mAh battery with a rated power of 14W and input of 5V, which is the standard for up to USB 3.0 power (although the Amperage is not mentioned at all). SKG does not say how long it takes to charge, but a quick calculation at 2A (if that is what it is) would mean it would take roughly 1.5 hrs to charge from empty. In any case, the light around the button changes from orange to green on a full charge. In addition, it is not possible to use the device while it is charging. On the right of the neck massager is the On/Off and modes button, which also acts as a joystick. You can operate all the modes directly from the power button, as well as the app, which I'll get into a bit later: Push up: Short press to adjust Heat levels On/Off button: long press Mode Switching: Short press (while in operation) ➕ Push left: increase Music volume ➖ push right: decrease Music volume Push down: Short-press to turn Music on or off The massager defaults to De-stress mode, and it is not stated anywhere if the neck massager has overheat protection. This time around, regarding heat, the only detail I could find is that it has "triple action soothing heat." The temperature stages are not listed anywhere in the paper manual, Amazon listing, or official website. The heat levels can be adjusted through the app or directly on the device using the joystick button. Usage There's also the SKG Health app, which makes using the massager far easier than feeling around for the button on the side of your neck. If the app is stopped, you are required to log in with a verification code over email, which I am not too pleased with, as this means it will only work that way for however long SKG decides to support it through said app. However, I was not able to get the app to connect to the OS500, which I have reported back to my contact. Bluetooth appeared to be working on the neck massager as it became available to pair with my phone, but the SKG app failed to discover it. Before I forget, there's also a switch next to the USB charging port to deactivate and activate the Voice Prompt, which, when enabled, audibly tells the user when switching intensities, modes, or connecting to the app and informs when the massages start and are completed. That said, on to my likes and dislikes, which are listed below. What I didn't like Unable to connect the Neck Massager to the app Use through the mobile app relies on continued support from SKG What I liked Can be used without the app Cordless use Light and comfortable to wear Heat is also quite comfortable Where to buy: According to the official website, this has an MSRP of $249.99, but is currently $50 (on Amazon). To sweeten the deal a bit more, there's also an in-page coupon that knocks a further $20 off the price. SKG PS700-2 Neck Massager for $179.99 on Amazon (was $199.99) Apply the in-page $20 off coupon for the final price of $179.99 Just like the back massager, this gets a confused thumbs up (due to the cost). However, I cannot rate it through app usage as it failed to connect. As an Amazon Associate, we earn from qualifying purchases.
    • This Samsung T7 external SSD deal lasts less than a day by Sayan Sen Recently we had covered some nice deals of internal NVMe SSDs which include the 4TB TeamGroup G50 for only $400, the WD_BLACK SN7100 2TB for just $243, as well as the Samsung 990 PRO 1TB for $370. If however you require an external SSD for portability and quick data transfers and have a budget of less than $200 the Samsung T7 1TB model is currently on a limited time deal at just $190, it's lowest price in nearly three months. The deal ends today so you better hurry if you need one (purchase link below). The T7 weighs in at just 72 grams meaning it should be fairly easy to carry around helping in the portability department. Via its USB 3.2 Gen 2 interface the T7 promises sequential read speeds of up to 1050 MB/s and writes of 1000 MB/s. It is also fairly robust with a drop protection of up to 2 meters, though bear in mind that this is not waterproof. For that you will have to choose the rugged T7 Shield. The technical specifications of the Samsung T7 1TB are given in the table below: Specification Value Model Code (1TB) MU-PC1T0T / MU-PC1T0H Interface USB 3.2 Gen 2 (10 Gbps) Dimensions (W × H × D) 85 × 57 × 8 mm Weight 72 g Sequential Read Speed Up to 1,050 MB/s Sequential Write Speed Up to 1,000 MB/s Drop Resistance Up to 2 m (6.6 ft) Encryption AES 256-bit hardware encryption Operating Temperature 0°C to 60°C Non-Operating Temperature -40°C to 85°C Humidity 5% to 95% (non-condensing) Shock Resistance 1,500 G, duration 0.5 ms, 3-axis (non-operating) Vibration Resistance 20–2,000 Hz, 20 G (non-operating) Get it at the link below: Samsung T7 Portable SSD, 1TB External Solid State Drive, MU-PC1T0T/AM, Gray: $189.98 (Sold and Shipped by Amazon US) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
  • Recent Achievements

    • Dedicated
      Almohandis earned a badge
      Dedicated
    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
    • First Post
      DrWankel earned a badge
      First Post
    • Reacting Well
      DrWankel earned a badge
      Reacting Well
    • Week One Done
      Supreme Spray LV earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      505
    2. 2
      +Edouard
      184
    3. 3
      PsYcHoKiLLa
      85
    4. 4
      Michael Scrip
      78
    5. 5
      Steven P.
      76
  • Tell a friend

    Love Neowin? Tell a friend!