Cleaning tips

T

TonyWa

Having just fixed a friend's machine that was riddled
with viruses courtesy AOL 9 (virus protection I don't
think) I thought I'd share some of my experiences.

1. I wish I'd had the MS Spyware Beta at the beginning
rather than at the end, I'm very pleased with it indeed
but...
2. Other entries in this newsgroup confirm my belief that
a badly-infected machine needs more than one product to
fix.
3. Obviously Spybot and Adaware are great tools, as is
SpyWareBlaster. This free combo, along with AVG Free, has
successfully kept my 5 family member PCs free of trouble
for 2 to 3 years.
4. The problem is fixing PCs that have already been
multiply-infected; you run the tools, they clean it up,
but the next time you get on the network they are back -
IBIS, Huntbar and various DownloadWare nasties
especially - because of hidden things they miss.
5. Having 2 similar OS machines side by side, one clean
the other not is very useful. Just make sure that when
the dirty machine is on the local LAN the other machines
are switched off! This allows you to bring up Task
Manager for both machines and compare; you can them see
possible bad processes - keep the bad PC off the LAN so
that the good machine can search the Net for info on
suspect processes; kill them (if possible, some spawn
children immediately,) after pinpointing them with HiJack
this, then delete with Highjack this - a great tool.
6. Also keep Control Panel/Add/Remove Programs and
Explorer windows up and running to delete bad directories
and programs as you locate them. Maybe it was
superstitious of me, but the triple hit - explorer
delete, program remove, Hijack This fix - helped get rid
of some Trojans nothing else would cure.
7. Check out Hijack This groups on the Internet, too,
when you search for bad viruses, they are most helpful in
deciding what's bad and what's not.
8. Cccleaner is a GREAT free download for cleaning up
temp folders, recycle bin etc
9. Try other scanners, too, by checking the antispyware
forums - they are usually free, they only want you to pay
for cleanup, if you like them buy the product or fix
yourself as I did (I wanted the experience).
10. For some Trojans that my scanners couldn't fix I
found downloads targeted to individual viruses/trojans at
the Symantec site. The McAfee site has some useful free
tools, too.
11. Safe Mode is invaluable for badly-infected machines.
(Reboot and hit the F8 key multiple times during reboot).
12. Allow plenty of time - this isn't a good business
proposition except for PCs that cannot be retsored or
reformatted. The fix took me 12 hours. I could do it now
in about 2 or 3, with what I've learned.
 
B

Bill Sanderson

Good tips--thanks. Don't underrate any of the providers. In removing
aurora/nail.exe/TODO the most important clue I got came from Trend Micros
online scanner--

http://housecall.trendmicro.com

It was able to spot the main executable--I had two pieces of the puzzle, but
without that third piece I couldn't clean successfully. This one wasn't
cleanable in safe mode--hitbox might have done the job, I chose to use the
recovery console instead.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top