Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 15th, 2008, 01:36 PM
TheKid7's Avatar
TheKid7 TheKid7 is offline
Very Frequent Poster
 
Join Date: Jul 2006
Posts: 2,458
Default Malware Toolbox

On rare occasions someone will ask me to check out their PC because it is running slow, etc. If you were to clean malware from an infected PC what would be your choice of tools and what would be the recommended order of tool use?

Currently I plan to use (Not necessarily in this order): MBAM, SuperAntiSpyware Free, AVIRA System Rescue CD, CureIt, TMHouseCall (Online), NOD32 (Online), a2free.

Thank you.
  #2  
Old July 15th, 2008, 01:40 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: Malware Toolbox

Quote:
Originally Posted by TheKid7
On rare occasions someone will ask me to check out their PC because it is running slow, etc. If you were to clean malware from an infected PC what would be your choice of tools and what would be the recommended order of tool use?

Currently I plan to use (Not necessarily in this order): MBAM, SuperAntiSpyware Free, AVIRA System Rescue CD, CureIt, TMHouseCall (Online), NOD32 (Online), a2free.

Thank you.

i will say spybot search and destroy,adaware,avira antivirus and some others i dont remenber at the moment.
note:spybot SD is always undergraded but it help me clean computers very good,it has some sharp teeth
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #3  
Old July 15th, 2008, 02:29 PM
lodore lodore is offline
Incredibly Massive Poster
 
Join Date: Jun 2006
Posts: 8,876
Default Re: Malware Toolbox

Quote:
Originally Posted by TheKid7
On rare occasions someone will ask me to check out their PC because it is running slow, etc. If you were to clean malware from an infected PC what would be your choice of tools and what would be the recommended order of tool use?

Currently I plan to use (Not necessarily in this order): MBAM, SuperAntiSpyware Free, AVIRA System Rescue CD, CureIt, TMHouseCall (Online), NOD32 (Online), a2free.

Thank you.
Hello TheKid7,
quite a nice range of tools.
you can replace trend micro house call with sysclean link
never been a fan of online scanners mainly since they dont always remove themselfs and mostly use activeX.
i would add f-secure rescue cd to the setup. link
the drweb rescue cd will be out of beta soon. the main advantage of the drweb rescue cd is the bultin updator.
__________________
useful tools:cure it SAS Hitman Pro mbam KL Eset windows defender offline Sophos

Last edited by lodore : July 15th, 2008 at 02:42 PM.
  #4  
Old July 15th, 2008, 02:50 PM
Ilya Rabinovich Ilya Rabinovich is offline
Developer
 
Join Date: Sep 2005
Posts: 1,516
Default Re: Malware Toolbox

Quote:
Originally Posted by TheKid7
If you were to clean malware from an infected PC what would be your choice of tools and what would be the recommended order of tool use?
I use AVZ. www.z-oleg.com
__________________
DefenseWall HIPS developer. www.softsphere.com
  #5  
Old July 15th, 2008, 02:59 PM
bellgamin's Avatar
bellgamin bellgamin is offline
Very Frequent Poster
 
Join Date: Aug 2002
Location: Hawaii
Posts: 5,202
Default Re: Malware Toolbox

Quote:
Originally Posted by Ilya Rabinovich
I use AVZ. www.z-oleg.com
Ilya is an expert. Ergo, I recommend you go with his suggestion.

I have heard VERY good things about AVZ here at Wilders.

If you want to do a Wilders search -- you can't search for words of less than 4 characters. Therefore, do a Google search with the following entry...

"avz site:www.wilderssecurity.com" -- w/o the quotations.
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender
  #6  
Old July 15th, 2008, 03:03 PM
LoneWolf's Avatar
LoneWolf LoneWolf is online now
Massive Poster
 
Join Date: Jan 2006
Posts: 3,130
Default Re: Malware Toolbox

AVZ Antiviral Toolkit English Translation
__________________
May you fly straight to heaven - but if you go to Hades - may Lethe run with Guinness
  #7  
Old July 15th, 2008, 03:08 PM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,279
Default Re: Malware Toolbox

Quote:
Originally Posted by bellgamin
If you want to do a Wilders search -- you can't search for words of less than 4 characters
Only because it is a somewhat unknown\overlooked search feature of our forums do I offer the below.

In our FAQ there is Searching the forum easier that then has this thread.

AVZ search results utilizing the Google search box.
  #8  
Old July 15th, 2008, 04:48 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Malware Toolbox

Thekid7 here's a good antimalware toolbox (have a look and learn these tools they are quite easy to use and understand with use and they are all free)... Autoruns, ProcessExplorer and Process Monitor, TCPView and RootkitRevealer from Sysinternals. Then eventually substitute Rootkit Revealer with Rootkit Unhooker/IceSword or RootRepeal.

AVZ is very good all-in-one
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #9  
Old July 15th, 2008, 08:17 PM
MrBrian MrBrian is offline
Very Frequent Poster
 
Join Date: Feb 2008
Posts: 2,925
Default Re: Malware Toolbox

Kaspersky AVPTool
ESET SysInspector
System Repair Engineer
HijackThis

I'd recommend to move some of the anti-spyware programs to the latter part of your list, or off altogether. See http://www.wilderssecurity.com/showp...8&postcount=28 and http://www.wilderssecurity.com/showp...7&postcount=31 for the reason why. If you do use anti-spyware programs, use those that excel at cleaning.
  #10  
Old July 15th, 2008, 08:37 PM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,517
Default Re: Malware Toolbox

Another vote for AVZ along with SAS, MBAM, Cureit, Runscanner...

If you come across any flash autorun.inf infections then Flash Disinfector may be able to help.
  #11  
Old July 15th, 2008, 08:45 PM
MrBrian MrBrian is offline
Very Frequent Poster
 
Join Date: Feb 2008
Posts: 2,925
Default Re: Malware Toolbox

Perhaps run sfc /scannow, which is already present in Windows.
  #12  
Old July 15th, 2008, 11:11 PM
MrBrian MrBrian is offline
Very Frequent Poster
 
Join Date: Feb 2008
Posts: 2,925
Default Re: Malware Toolbox

Computer Repair Utility Kit and/or PC Repair System - portable versions of repair programs
Ultimate Boot CD for DOS
Ultimate Boot CD for Windows
  #13  
Old July 15th, 2008, 11:52 PM
EliteKiller's Avatar
EliteKiller EliteKiller is offline
Very Frequent Poster
 
Join Date: Jan 2007
Location: TX
Posts: 1,123
Default Re: Malware Toolbox

rogueremoval kit
  #14  
Old July 15th, 2008, 11:53 PM
HURST's Avatar
HURST HURST is offline
Very Frequent Poster
 
Join Date: Jul 2007
Posts: 1,420
Default Re: Malware Toolbox

Avira RescueCD
MBAM
HiJackThis
RogueRemoval Kit
RRT
xpsecconsole
CureIt
AVZ
AVP Tool
SAS
Autoruns
Process Explorer
RKU
__________________
I SandboxIE
  #15  
Old July 16th, 2008, 01:07 AM
EASTER's Avatar
EASTER EASTER is offline
Massive Poster
 
Join Date: Jul 2007
Location: U.S.A. (South)
Posts: 4,504
Default Re: Malware Toolbox

Quote:
Originally Posted by Ilya Rabinovich
I use AVZ. www.z-oleg.com

Likewise, indeed a very in-depth searcher and remover but i found for the very most extreme cases ERD COMMANDER cd invaluable! Working along somewhat similar lines as BART PE & Win PE, you can approach a heavily infested disk indirectly with this CD, in effect loading that system inside ERD totally immobilized, and yank out the toughest static-cling placed on it as well as remove deeply embedded registry issues and such.

I always tote that CD with me along with excellent apps mentioned just in case the system can't boot and such.

I seen in dual partition systems where malware has even deleted one of the partitions, so in a case of that nature, and provided the partition hasn't been written over too badly, PARTED MAGIC cd with TESTDISK usually can find and restore it again by writing it back.

EASTER
__________________
★AX 64 Time Machine★
★Shadow Defender★| EQSecure v4.0 Beta3 |#Sandboxie 4.08 beta# |FirstDefense-ISR|★FileChangeAlarm★ |Linux Mint 14
Maxthon 3.3.6 | X Iron 17.0 | Chromium 19.0 | CometBird 11

Microsoft Windows 8 64bit (UEFI/GPT) Secure Boot
  #16  
Old July 16th, 2008, 01:59 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,409
Default Re: Malware Toolbox

Quote:
Originally Posted by MrBrian
Kaspersky AVPTool
Does it has same signatures as KAV itself?
__________________

Ubuntu 12.10
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #17  
Old July 16th, 2008, 07:57 AM
Someone Someone is offline
Very Frequent Poster
 
Join Date: Jan 2008
Posts: 1,106
Default Re: Malware Toolbox

Quote:
Originally Posted by aigle
Does it has same signatures as KAV itself?

Hi

I think it has the KAV v7 database.
  #18  
Old July 16th, 2008, 09:01 AM
lodore lodore is offline
Incredibly Massive Poster
 
Join Date: Jun 2006
Posts: 8,876
Default Re: Malware Toolbox

i wasa thinking about creating a bartpe cd for cleaning infected computers for other people. but havent had any success with my oem windows xp cd.
ive also tryed creating a vistape cd using winbuilder but cant seem to add more than the basic without errors.
btw i would surgest running superantispyware free first. that is normally enough for the computers i have dealt with.
__________________
useful tools:cure it SAS Hitman Pro mbam KL Eset windows defender offline Sophos
  #19  
Old July 16th, 2008, 10:00 AM
Shankle Shankle is offline
Frequent Poster
 
Join Date: May 2006
Posts: 454
Default Re: Malware Toolbox

I look at all these answers and find no consistancy. This would drive a Puter novice crazy. I use none of the programs listed and I NEVER have problems with my Puter.
I guess it comes down to what you start with and what you are familiar with. Then there is cost and ratings. I would think that a combined package like ESS would give more value and less Puter hastle than buying a multitude of separate security packages.
Just my humble opinion.
  #20  
Old July 16th, 2008, 10:49 AM
HURST's Avatar
HURST HURST is offline
Very Frequent Poster
 
Join Date: Jul 2007
Posts: 1,420
Default Re: Malware Toolbox

Quote:
I look at all these answers and find no consistancy. This would drive a Puter novice crazy. I use none of the programs listed and I NEVER have problems with my Puter.
I guess it comes down to what you start with and what you are familiar with. Then there is cost and ratings. I would think that a combined package like ESS would give more value and less Puter hastle than buying a multitude of separate security packages.
Just my humble opinion.

I think most of us are writing what we use to CLEAN infected computers, not to protect our own.
On my own PC I don't even use scanners anymore.
__________________
I SandboxIE
  #21  
Old July 16th, 2008, 11:30 AM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: Malware Toolbox

Quote:
Originally Posted by HURST
I think most of us are writing what we use to CLEAN infected computers, not to protect our own.
On my own PC I don't even use scanners anymore.

HURTS is correct there cause prevention is always better than the cure and if we are very preventive we sholdnt be talking about what we use to or for cleaning up our pcs.thas my 5 bucks
note:for developers and adventurers testers that take the risk of testing thats another story .

and also i dont use scaners too.
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #22  
Old July 16th, 2008, 11:33 AM
nosirrah nosirrah is offline
Malware Fighter
 
Join Date: Aug 2006
Location: Cummington MA USA
Posts: 477
Default Re: Malware Toolbox

If you want to be 100% sure you need non blacklist tools .

I still do some home user IT from time to time and have my malware tools down to these :

RKU
GMER
IceSword
Autoruns
RunScanner
ProcessExplorer
HJT
sigverif (part of windows)
VistaPE

There is nothing wrong with using a blacklist scanner type tool to scrape a chunk off the top but after you need to dig deeper .
__________________
Bruce Harrison
Malwarebytes Lead Researcher
  #23  
Old July 16th, 2008, 07:35 PM
MrBrian MrBrian is offline
Very Frequent Poster
 
Join Date: Feb 2008
Posts: 2,925
Default Re: Malware Toolbox

Quote:
Originally Posted by HURST
Avira RescueCD
MBAM
HiJackThis
RogueRemoval Kit
RRT
xpsecconsole
CureIt
AVZ
AVP Tool
SAS
Autoruns
Process Explorer
RKU

RRT = ?
  #24  
Old July 16th, 2008, 08:00 PM
Pseudo's Avatar
Pseudo Pseudo is offline
Regular Poster
 
Join Date: May 2008
Posts: 193
Default Re: Malware Toolbox

Quote:
Originally Posted by MrBrian
RRT = ?
Remove Restrictions Tool?
  #25  
Old July 16th, 2008, 09:10 PM
HURST's Avatar
HURST HURST is offline
Very Frequent Poster
 
Join Date: Jul 2007
Posts: 1,420
Default Re: Malware Toolbox

Quote:
Remove Restrictions Tool?

__________________
I SandboxIE
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:36 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums