P
(PeteCresswell)
While trying to fix up somebody's aging laptop, it has finally
dawned on me that a virus scanner running under XP cannot always
find all malware. Root kits, Alureon.... Cybot-BC... Bamital-AU
and so-on-and-so-forth.
I routinely image a build with an eye to restoring said image
if/when things go South.... but, of course, it's important that
the image be of a good, uninfected system.....
To that end, here's what I come up with as a procedure for
maximizing the chances of a good image, using Avast as the
anti-virus utility:
---------------------------------------------------------------
1) Tell Avast to write a log of scan results
(the log seems to default to
C:\Documents and Settings\All Users\Application Data\Alwil
Software\Avast5\Report\aswboot.txt).
2) Run an Avast Boot-time scan.
3) Inspect the resulting log, just for good measure.
4) If infections are found/supposedly remedied, run
the boot scan again, looking for a clean log.
5) Run a disk disc check to make sure there are no
bad sectors (I use "HdTune").
6) Run ChkDsk C: just for good measure.
7) Image the supposedly-clean system
dawned on me that a virus scanner running under XP cannot always
find all malware. Root kits, Alureon.... Cybot-BC... Bamital-AU
and so-on-and-so-forth.
I routinely image a build with an eye to restoring said image
if/when things go South.... but, of course, it's important that
the image be of a good, uninfected system.....
To that end, here's what I come up with as a procedure for
maximizing the chances of a good image, using Avast as the
anti-virus utility:
---------------------------------------------------------------
1) Tell Avast to write a log of scan results
(the log seems to default to
C:\Documents and Settings\All Users\Application Data\Alwil
Software\Avast5\Report\aswboot.txt).
2) Run an Avast Boot-time scan.
3) Inspect the resulting log, just for good measure.
4) If infections are found/supposedly remedied, run
the boot scan again, looking for a clean log.
5) Run a disk disc check to make sure there are no
bad sectors (I use "HdTune").
6) Run ChkDsk C: just for good measure.
7) Image the supposedly-clean system