View Full Version : what are good portable tools for malware cleaning?
Brocke
May 3rd, 2010, 06:35 PM
topic^
im not asking whats best but just give me idea of what are handy to have that are portable tools.
thank you all.
Brummelchen
May 3rd, 2010, 06:58 PM
none!
Help: I Got Hacked. Now What Do I Do?
http://technet.microsoft.com/de-de/library/cc512587%28en-us%29.aspx
-{ Quote: "# You can’t clean a compromised system by patching it. Patching only removes the
vulnerability. Upon getting into your system, the attacker probably ensured that there
were several other ways to get back in.
# You can’t clean a compromised system by removing the back doors. You can never
guarantee that you found all the back doors the attacker put in. The fact that you can’t
find any more may only mean you don’t know where to look, or that the system is so
compromised that what you are seeing is not actually what is there.
# You can’t clean a compromised system by using some “vulnerability remover.” Let’s say
you had a system hit by Blaster. A number of vendors (including Microsoft) published
vulnerability removers for Blaster. Can you trust a system that had Blaster after the tool
is run? I wouldn’t. If the system was vulnerable to Blaster, it was also vulnerable to a number
of other attacks. Can you guarantee that none of those have been run against it?
I didn’t think so." }-
JerryM
May 3rd, 2010, 10:51 PM
-{ Quote: "none!
Help: I Got Hacked. Now What Do I Do?
http://technet.microsoft.com/de-de/library/cc512587%28en-us%29.aspx" }-
So what is to be done?
Regards,
Jerry
G1111
May 4th, 2010, 02:02 AM
-{ Quote: "topic^
im not asking whats best but just give me idea of what are handy to have that are portable tools.
thank you all." }-
Emsisoft (a-squared) Emergency USB Stick http://www.emsisoft.com/en/software/stick/
SUPERAntiSpyware portable scanner http://www.superantispyware.com/portablescanner.html
I believe you can use Dr. Web CureIt http://www.freedrweb.com/cureit/?lng=en
more can be found here: http://www.techsupportalert.com/content/probably-best-free-security-list-world.htm (Portable antivirus/antimalware: (can be used eg. with a Windows boot cd)
Brocke
May 4th, 2010, 02:13 AM
-{ Quote: "Emsisoft (a-squared) Emergency USB Stick http://www.emsisoft.com/en/software/stick/
SUPERAntiSpyware portable scanner http://www.superantispyware.com/portablescanner.html
I believe you can use Dr. Web CureIt http://www.freedrweb.com/cureit/?lng=en
more can be found here: http://www.techsupportalert.com/content/probably-best-free-security-list-world.htm (Portable antivirus/antimalware: (can be used eg. with a Windows boot cd)" }-
thank you
ALiasEX
May 4th, 2010, 02:52 AM
The only other one I can think of, at the moment, is Hitman Pro.
Brocke
May 4th, 2010, 03:23 AM
does that have alot of FP tho?
doktornotor
May 4th, 2010, 03:38 AM
-{ Quote: "So what is to be done?
" }-
You go and restore a known good OS backup. Failing to have one, you do a fresh reinstall.
Though, we already have (IMHO) exact same topic here (http://www.wilderssecurity.com/showthread.php?t=271644).
Brocke
May 4th, 2010, 03:47 AM
where the Malwarebytes portable? i cant find it.
doktornotor
May 4th, 2010, 03:55 AM
-{ Quote: "where the Malwarebytes portable? i cant find it." }-
I don't think there's any portable official one anywhere, and attempts on making it portable clearly suggest it's not meant to be portable at all (http://forums.comodo.com/anti_virusmalware_productsother_security_products/portable_malwarebytes_antimalware_superantispyware_howto-t36843.0.html;wap2=).
Would suggest using Hitman Pro instead if you need portable.
arjunned
May 4th, 2010, 04:34 AM
-{ Quote: "
Would suggest using Hitman Pro instead if you need portable." }-
Yup. I second. :thumb:
Always do scan with Hitman Pro on my friends Pc's who complain of malware infection. :)
MBAM & Dr. Web CureIt are what i scan with after.
Brocke
May 4th, 2010, 04:36 AM
does hitman pro is that free and does it remove?
i see that it has to be paid? is why i ask.
ALiasEX
May 4th, 2010, 04:44 AM
Free to scan, 30 day trial for removal. You can activate the trial on as many computers as needed.
doktornotor
May 4th, 2010, 04:45 AM
-{ Quote: "does hitman pro is that free and does it remove?
" }-
You can activate a 30days license if it finds anything and then it will clean. So, for going around various boxes and cleaning them, that works perfectly fine.
3GUSER
May 4th, 2010, 04:53 AM
-{ Quote: "does hitman pro is that free and does it remove?
i see that it has to be paid? is why i ask." }-
It has some good rootkit cleaning capabilities . Just some other utilities it can find patched system files and restore the original ones from clean Windows copies - automatically.
The one I bring and often use when I visit clients are:
ComboFix
Microsoft's Autoruns
Malwarebytes' AntiMalware
Hitman Pro
Norton Power Eraser
Also : TheAvenger , Unlocker and many registry fixies or scripts for fixing this or that (that has previously been corrupted by malware attack).
raven211
May 4th, 2010, 10:33 AM
-{ Quote: "It has some good rootkit cleaning capabilities . Just some other utilities it can find patched system files and restore the original ones from clean Windows copies - automatically.
The one I bring and often use when I visit clients are:
ComboFix
Microsoft's Autoruns
Malwarebytes' AntiMalware
Hitman Pro
Norton Power Eraser
Also : TheAvenger , Unlocker and many registry fixies or scripts for fixing this or that (that has previously been corrupted by malware attack)." }-
Good list, I would use something very similar. :D
andyman35
May 4th, 2010, 10:35 AM
AVZ is another excellent portable tool.;)
http://www.softpedia.com/get/Antivirus/AVZ-Antiviral-Toolkit.shtml
ALiasEX
May 4th, 2010, 10:55 AM
Spybot - Search & Destroy©® (http://portableapps.com/node/710)
Brummelchen
May 4th, 2010, 01:32 PM
-{ Quote: "So what is to be done?
Regards,
Jerry" }-
the only solution is an image or backup or re-install from scratch.
forget the other *** answers here, they never really dealt with malware.
im not sure they ever thought about it nor they read the ms article.
otherwise the introducing question should be revised or extended!
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums