• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

malwarebytes vs superantispyware

YeOldeStonecat

[H]F Junkie
Joined
Jul 19, 2004
Messages
11,330
I may add this site to my bookmarks....they have some comparison testing of some of the malware cleaning apps.
This test was done with 1000 samples of malware about 1 week old
http://malwareresearchgroup.com/forum/viewtopic.php?f=23&t=309

I've been a huge fan of malwarebytes lately, I used to use SuperAntispyware a while ago...but noticed MWB seems to be much more effective.

Of course, if you have the time when cleaning an infected rig...taking the old shotgun effect of using a bunch of removal tools is still best IMO, as some will find things others missed.

That forum does seem to love an app called Hitman Pro...may have to take a look at that one, haven't tried it.
Hitman Pro is a cloud based cleaning program, and it combines several engines....AntiVir, NOD32, A-Squared, GData, and Prevx. And it does cost money, although there is a trial.
 
Lately I have been using both of them plus combofix when needed and nod's online scan.

For a while I was using just MWB and NOD, but with the latest round of nasties, that was letting a few things through.
 
Ccleaner in each profile.
Run Hijackthis.
Disable System Restore.
Run Combofix.
Run full Malwarebytes scan.
Run full SAS scan.
Scan with NAV if they have it installed, if not, install MSE and scan with that.
Reenable System Restore.
Install Windows Updates.
Make sure everything is working properly, opening, internet connections are fine, etc.
If everything looks and feels OK, it's good to go.

That's just the general removal. On top of that, a blow out with an air compressor, visually inspect for caps, etc, and test the HDD and RAM. Call it good to go. Some removals are trickier, but for the most part, that order works pretty damn good.
 
This thread was really just for an eye opener to the site that compares various products. We have a thread sticked atop this forum for the purpose of malware cleaning techniques.
 
Stonecat, I've used Hitman pro a lot, and while it IS a paid product for removal, scans are always free. The trial starts 30 days from your first removal, not from first install, so that's always a plus.
 
Ccleaner in each profile.
Run Hijackthis.
Disable System Restore.
Run Combofix.
Run full Malwarebytes scan.
Run full SAS scan.
Scan with NAV if they have it installed, if not, install MSE and scan with that.
Reenable System Restore.
Install Windows Updates.
Make sure everything is working properly, opening, internet connections are fine, etc.
If everything looks and feels OK, it's good to go.

That's just the general removal. On top of that, a blow out with an air compressor, visually inspect for caps, etc, and test the HDD and RAM. Call it good to go. Some removals are trickier, but for the most part, that order works pretty damn good.

Its easier to just image and backup than go through those steps
 
Haven't had to use much else other than NOD and MBAM. A couple weeks ago I came across a pc with Anti-Virus Soft and had to manually remove it.
http://www.2-spyware.com/remove-antivirus-soft.html
Neither of the above mentioned would remove it at the time.

A majority of this crap can be avoided by keeping adobe flash, and reader/acrobat up to date which is becoming more frequent lately than windows updates.
 
Temper is a good temp cleaner that can be ran in 1 profile and cleans all profiles temp files. Ccleaner has to be ran in each profile. Mbam rox. I also use combofix, spybot s&d, microsoft malicious software removal tool, and MSE more and more.
 
Used to love Spybot Search and Destroy, particularly for all the extra tools it comes with. MWB has risen to the top of my list recently just for effectiveness. I'd like to see how AdAware and Spybot stack up...
 
I've found that most of the new Vundo.Trojan variants completely block MBAM. For some reason they aren't blocking SAS. So, lately, I've been running the first scan with SAS and that seems to clean it up to the point where I can install MBAM and run that to clean up the left overs. Afterward I'll run a rootkit scanner and ESET or Sophos or Symantec, whatever the client has. Then another round of CCleaner for good measure. :D
 
First off interesting site, I'll have to take a longer look at it later.

I've found that most of the new Vundo.Trojan variants completely block MBAM. For some reason they aren't blocking SAS. So, lately, I've been running the first scan with SAS and that seems to clean it up to the point where I can install MBAM and run that to clean up the left overs. Afterward I'll run a rootkit scanner and ESET or Sophos or Symantec, whatever the client has. Then another round of CCleaner for good measure. :D

Yea I've seen this as well. MBAM seems to be doing one of the better jobs though.

I've been seeing more malware replacing the userinit process. If you let superantispware or malewarebytes remove it the machine will just log you off right after you try to login. Have to either pull the drive and open the registry using another computer or if it is on a domain connect to the registry using another machine and fix it that way.
 
i guess i'm never really comfortable letting someone bank on a computer that has had a virus

QFT times a million.

That's what I tell anyone (really just limited to close friends and family anymore- I don't do cleanups as my full-on job anymore THANK GOD). "I'd never trust it again". Who knows what other malware it might've downloaded that's new to signatures or whatnot....



But I dropped SAS a year or so ago. MBAM simply rocks. CCleaner+MBam get most of the crap, for anything more difficult than that- honestly- reinstall is the only way I go. Because again- I don't trust it.


I had my second XP machine that I've seen, that corrupted EXEs in the OS. IE, MBam could install, but it wouldn't run. Something so currupted like that- I'll never trust. By the time I spend figuring out what the issue is and how to fix it, I could've installed Windows again by then. I backed up his docs, installed Win7 with MSE... Good to go.
 
QFT times a million.

That's what I tell anyone (really just limited to close friends and family anymore- I don't do cleanups as my full-on job anymore THANK GOD). "I'd never trust it again". Who knows what other malware it might've downloaded that's new to signatures or whatnot....



But I dropped SAS a year or so ago. MBAM simply rocks. CCleaner+MBam get most of the crap, for anything more difficult than that- honestly- reinstall is the only way I go. Because again- I don't trust it.


I had my second XP machine that I've seen, that corrupted EXEs in the OS. IE, MBam could install, but it wouldn't run. Something so currupted like that- I'll never trust. By the time I spend figuring out what the issue is and how to fix it, I could've installed Windows again by then. I backed up his docs, installed Win7 with MSE... Good to go.

I've been getting user32.dll replaced and then the whole system is gone. If MBAM actually runs, then I assume the virus wasn't really that bad. I also prefer Antivir rescue cd, and then run a windows repair to replace the damaged windows files. I think people are crazy to be cleaning virus inside of windows. It would be nice to have a bootable version of mbam.
 
Back
Top