Recommended Posts

Ok, I'm fixing a pc for a friend. When I turned on the computer I was blocked out by some dumb message about copyrights and wanting to pay $200. Finally was able remove some of the files, delete from start up, etc. installed spy bot search and destroy, ran the scan and removed all entries. Used the pc on and off for a few days. No issues. Gave the pc back... Within 2 days...it's back. Is there a better freeware scanner/remover for this. I'm at my wits end with this.

Link to comment
https://www.neowin.net/forum/topic/1120426-need-help-removing-virusmalware/
Share on other sites

1. Boot in safemode

2. Empty ALL temp folders, including user temp folders, not just windows

3. Reset IE, checking the box to delete everything

4. Open regedit:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

and

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Delete any suspicious looking entries

Also delete anything in HKEY_CURRENT_USER\Software and HKEY_LOCAL_MACHINE\SOFTWARE that look malware related

Open MSCONFIG and disable anything that looks suspicious in there too

----------

Reboot in normal mode, and run a full scan with a fully updated malwarebytes

You have already scanned with spybot but do it again anyway

Another good thing is installing Avast Free, and do a "Boot Time Scan" this will be able to remove malware that can not be killed inside of windows

Download and run a scan with "Hijack This" remove any suspicious entries in there too

Scan a couple of times with all the above programs until they all return a clean result

If you still have a problem after all that, wipe > reinstall windows

  • Like 3

What exactly would be considered suspicious? I'd assume they would label anything that would set off red flags..

Well just anything you don't recognise as being installed on the machine as a genuine app, a lot of malware will have registry keys with weird symbols, such as !"?$%^&*&()_) or the name of the fake AV that pops up

Normally pretty easy to spot, the first 2 keys I mentioned are what windows calls to startup with windows, so if you don't want anything starting up with windows, delete those keys, and in MSCONFIG

Latest version is 2.04....It doesn't work properly with 64bit oses. It also doesn't dig as deep as otl.

Compare a hjt log with a otl log.

sample otl log

http://www.bleepingc...opic313328.html

sample hjt log

http://www.techsuppo...down-14837.html

which do you think is more thorough and can help you better find the cause?

Latest version is 2.04....It doesn't work properly with 64bit oses. It also doesn't dig as deep as otl.

Compare a hjt log with a otl log.

Ok, never used OTL, still HijackThis is a decent app, using both would be better than not using HJT, never had a problem with HJT and 64bit OSs though

read about hjt and 64 bit, while this isn't necessarily a problem people unfamiliar with it will go to disable critical processes and screw their computers up more. I don't recommend running this as a novice, nor do I recommend running it over the internet being that people can be tempted to try to fix it themselves causing more issues. bottom line, it doesn't work well with 64 bit oses and otl produces the similar findings as hjt with many more pieces to the os puzzle (more files, more reg entries, more points of infection, etc). Running otl with a good rootkit detection software, like gmer, will allow you, the tech, to actually find something useful and be able to repair the computer.

http://www.experts-e...it-Systems.html

That being said, it may take a few hours to go through and verify a otl report.

read about hjt and 64 bit

http://www.experts-e...it-Systems.html

Well that doesn't render HJT useless on 64bit systems, we're not looking for missing file entries, we're looking for malware entries, make no difference if HJT can't find 64bit files

And more to the point, I don't know many 64bit versions of malware

Well that doesn't render HJT useless on 64bit systems, we're not looking for missing file entries, we're looking for malware entries, make no difference if HJT can't find 64bit files

And more to the point, I don't know many 64bit versions of malware

not exactly useful either. if it is not useful, it is useless IMO.

you could do what others said and waste your time, or do what will be the easiest. Download a 10 meg file mawarebytes.com from here (filehippo link) on to a usb key. Boot into safe mode, install, run a scan, let it remove it. Done. If you want to do it the hard way, follow the other posts above.

Secret....malware bytes doesn't remove everything. Their root kit detection piece is still in beta last time I checked. Malware bytes is not the end all be all.

I have been around a lot of malware, and I can tell you with 100% certainty that malware bytes doesn't remove all of it. Just a good portion. I run a min of three different removal utilities mwb being one of them when cleaning computers. Mwb isnt the first thing i run, it is the last. I do know its limitations.

Secret....malware bytes doesn't remove everything. Their root kit detection piece is still in beta last time I checked. Malware bytes is not the end all be all.

I have been around a lot of malware, and I can tell you with 100% certainty that malware bytes doesn't remove all of it. Just a good portion. I run a min of three different removal utilities mwb being one of them when cleaning computers. I do know its limitations.

after servicing a couple thousand machines over the last couple years , i have had a 100% success ratio with malwarebytes when scanning in safe mode. Could you give me an example of malware that it can't remove? I would like to download it and see for myself.

note: i LOVE getting new stuff to test virus removal techniques. being serious.

Pick any root kit. The Remote Desktop attack 6months ago it couldn't detect (MSE was the first that did). Had problems finding, file name was close to a windows file name and I kept overlooking it.

I have been doing manual virus removal since late 90s. I have thousands over you. Hell, the hospital I was working at had a whole site infection over 10000 computers and hundreds of servers. Nightmare.

Pick any root kit. The Remote Desktop attack 6months ago it couldn't detect (MSE was the first that did). Had problems finding, file name was close to a windows file name and I kept overlooking it.

I have been doing manual virus removal since late 90s. I have thousands over you. Hell, the hospital I was working at had a whole site infection over 10000 computers and hundreds of servers. Nightmare.

could you give me even just 1 name of a rootkit that you could not remove with it? the worst one in your mind/experiance

you could do what others said and waste your time, or do what will be the easiest. Download a 10 meg file mawarebytes.com from here (filehippo link) on to a usb key. Boot into safe mode, install, run a scan, let it remove it. Done. If you want to do it the hard way, follow the other posts above.

This. Why make the removal process difficult?

could you give me even just 1 name of a rootkit that you could not remove with it? the worst one in your mind/experiance

Is it that hard to google root kit names, like I said pick one any one. Pull any one out of a google search. Malware bytes is 100% ineffective against any root kit. It doesn't have the scan engine for it, therefore it can't detect or repair against this type of infection. Google redirect is one.

Here you go read through and you will see that the user running malware bytes has no effect against it. http://www.bleepingcomputer.com/forums/topic434638.html

Huh? How is it not useful ?

What do you have against HJT ? It works, what more do you want ?

I don't like doing things twice and skimming through information I have been through before.

Is it that hard to google root kit names, like I said pick one any one. Pull any one out of a google search. Malware bytes is 100% ineffective against any root kit. It doesn't have the scan engine for it, therefore it can't detect or repair against this type of infection. Google redirect is one. Here you go read through and you will see that the user running malware bytes has no effect against it. http://www.bleepingcomputer.com/forums/topic434638.html I don't like doing things twice and skimming through information I have been through before.

Ok, well each to their own, lets not hijackthis thread with our differences ;)

Is it that hard to google root kit names, like I said pick one any one. Pull any one out of a google search. Google redirect is one.

Surprised you could not give one from your own extensive experiences and instead saying Google one. I am having no luck finding an .exe for the google redirect to infect myself with. Google is full of solution links and no actual download links (of course and expected). Do you know where i can get the .exe file? Or maybe a website that does give the infection?

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • YouTube has finally brought back its DMs feature, but only in these countries by David Uzondu Late last year, YouTube started testing a "new" way to share videos directly with friends, without having to leave the app. Now, the video giant has announced that is now rolling out a revamped direct messaging inbox, which lets you share videos, Shorts, and live streams and have conversations about them, directly on YouTube. The platform limits this feature to 18+ users who are signed in to a verified channel and use the latest mobile app version. Direct messaging on YouTube first became a thing back in 2017 inside the mobile app (later renamed to "Messages"), where users could chat one-on-one and share clips directly, but all that came to an end on September 18, 2019, when Google decided to shut it down after giving users a month to download a .zip file archive of their past chats. No one really knows why YouTube killed the feature, but users were encouraged to migrate to the public Comments section, on Community tab posts, and via YouTube Stories. The previous incarnation suffered from moderation challenges, prompting Google to implement stricter safety guidelines and age verifications for this new iteration. Here's a list of the countries where the re-launched feature is currently available, though note that Brand Accounts do not have access to it, at least for now: Countries American Samoa Austria Belgium Brazil Bulgaria Croatia Cyprus Czech Republic Denmark Estonia Finland France Germany Greece Guam Hungary Iceland Ireland Italy Latvia Liechtenstein Lithuania Luxembourg Malta Netherlands Northern Mariana Islands Norway Poland Portugal Puerto Rico Romania Singapore Slovakia Slovenia Spain Sweden Switzerland U.S. Virgin Islands United Kingdom United States Before you can use the feature, you first have to send an invite link to your contact. Invite links expire exactly seven days after you create them. If the person on the other end accepts the invite, you can exchange videos directly and text back and forth inside the app. To delete a message, just long-press on the message and tap unsend to remove it for both users. You can also delete entire conversations by long-pressing the thread and selecting delete, but the other person will continue to see the chat history on their end. To make sure everything remains safe, YouTube monitors these messages to ensure they follow Community Guidelines.
    • The problem of course is simply that government does not always know best. My point is that agency is taken away from the EU consumer in these cases. I'm sorry, but I do not believe that governments (politicians) are inherently good, and "looking out for me." Primarily they look to themselves and their own personal desires first, foremost, and always. When the EU or the DOJ fines these companies, claiming to "represent the welfare of the consumer," how much of these billion-dollar judgments are handed to the consumers they claim to represent? Not even a dollar, as I've seen. Yet the EUC lawyers who are paid to sit around and dream up these suits make huge commissions on the fines the EUC adjudicates, which is an ironclad fact I hope everyone is aware of. It's also rank corruption, of course, but that's another topic. Last, when the EU inflicts these judgments, or the DOJ, take your pick, the costs are bundled right along in the cost of the goods and services these companies provide the consumers they are "looking out for." If you are someone who believes his government is his savior then you have my condolences. I think Apple is right here, because the whole scheme of consumer choice is that consumers pick and choose among the products companies offer. Microsoft Windows is more compatible with third party software and hardware than any desktop OS on Earth, which is my sole reason for choosing it. Just because the EUC forces companies do certain things it knows the companies do not want to do, "or else", has no bearing on consumer benefit. This Siri thing is almost idiotic it's so infantile. But this is what the EUC does when the EU in Brussels becomes cash-strapped and needs a big infusion of cash. Some people get upset by "big companies" but it's the opposite when governments dwarf the size and scope of these companies, which is so obvious it hurts.... I mean you can't honestly believe that forcing Apple to do things with Siri it has its own reasons to decline is something that "opens up" Apple, do you? Say it aint' so...
    • Looks like many years since the request was made, a directory tree view finally may be added. https://github.com/files-community/Files/pull/18537
    • Is it still super slow or has it improved on that area?
    • There's this from last year https://gist.github.com/threat...364659a8887841aa43deca4efd9 but nothing about a buffer overflow that MS somehow can't code against. No matter what, it makes sense to take a "protected by default" approach.
  • Recent Achievements

    • One Month Later
      sjbousquet earned a badge
      One Month Later
    • Week One Done
      sjbousquet earned a badge
      Week One Done
    • First Post
      DragonOfMercy earned a badge
      First Post
    • First Post
      bella52 earned a badge
      First Post
    • Reacting Well
      Techinmay earned a badge
      Reacting Well
  • Popular Contributors

    1. 1
      +primortal
      501
    2. 2
      PsYcHoKiLLa
      213
    3. 3
      +Edouard
      156
    4. 4
      Steven P.
      84
    5. 5
      FloatingFatMan
      72
  • Tell a friend

    Love Neowin? Tell a friend!