Page 1 of 1

What virus stuff to use and what order?

Posted: Wed Nov 23, 2011 3:40 pm
by thewolfe
I have a friend's computer that is getting the BSOD. Haven't been able to duplicate it yet.

I want to ck for viruses.

I use:
Malwarebytes
Anti-virus - AVG, Comodo, MS Security Ess...
msert(Saftey_scanner_64bt)
mssstool64(MS_SystemSweeper)

What should I use (other suggestions) and in what order?

Running Win7 64 bit

Re: What virus stuff to use and what order?

Posted: Thu Nov 24, 2011 1:55 am
by TigerRaptor
Well for one avoid installing random anti-virus software. You also don't need MSE since you have Microsoft System Sweeper. Comodo also has a standalone called Comodo Cleaning Essentials

If Malwarebytes and the others didn't reveal any thing. It would be safe to assume the BSOD is caused by something else.

Re: What virus stuff to use and what order?

Posted: Thu Nov 24, 2011 9:57 am
by thewolfe
Thanks, I ran MB and found 3 items only and then ran MS Sweeper and found "Backdoor:Win32/Fynloski.A " & "HackTool:Win32/Keygen"

Found that the computer had a bootlegged copy of Win7.

Re: What virus stuff to use and what order?

Posted: Thu Nov 24, 2011 1:48 pm
by captain_twinkie
You could use Bluescreenview to dissect the BSODs

http://www.nirsoft.net/utils/blue_screen_view.html

Re: What virus stuff to use and what order?

Posted: Thu Nov 24, 2011 2:09 pm
by thewolfe
That's interesting. I've downloaded it into my bag of goodies.

Re: What virus stuff to use and what order?

Posted: Mon Nov 28, 2011 9:08 pm
by BUBBALOU
Removal 

I have this routine down to a science on more than 1000 business pc's

Grab these programs on a clean pc and place on a blank thumb drive that might get infected

Step 1

Cleanup!  4.52. ( deletes all the temp files on the pc where the malware / virus hide themselves to reinfect ) 

Install and run this first, this also clears the massive temp areas accumulated that every virus/ malware scanner will inspect , this will cut your scan by 95%

Aka - "taking out the trash"


Step 2 : the following 2 programs must be renamed to something other than their default name - most virus/malware memory resident programs have a blacklist to delete these programs on Sight!

Step 2a

Combofix.exe (bleepingcomputer.com)

Rename to cf.exe ( or cf112711 the date downloaded )

Best to reboot and run this in safe mode.. May ask to reboot if root kits are installed.  Leave the pc alone while this runs,  once it exports it's text file to your screen after its normal run and reboot (2nd if root kits where removed)

Aka : kill the rats/pests

Step 3

Mbam_xxxx.exe (malwarebytes.org)

Rename to mb.exe ( or date mb112711.exe )

Since prior you ran combofix any proxy altering nasties will not redirect malwarebytes to an alternate site with a bogus program update. 

Install and run, update.... Use only the quick scan within 10 minutes running you should be done and clean..  If you feel the need you can run a full scan afterwards with mbam if there were more than 10 positives

Aka : cleaning up the rat turds


Skip any step and something as simple as the screen saver kicking in can re-infect your pc....(part of the turd group of trickery)

ENJOY

Note: if the user has mortgage/financial software installed check the date/time format in the system settings and write it down , combofix will return it to the default and you will need to restore it for those programs

[ Post made via iPhone ] Image

Re: What virus stuff to use and what order?

Posted: Tue Nov 29, 2011 1:20 pm
by thewolfe
Nice job BUBBALOU!