• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Treating infected computers

a_kraker99

Weaksauce
Joined
Aug 12, 2008
Messages
85
So I have a friends computer that I believe is pretty heavily infected and I need to run some anti-malware scans on it.
How do most of you go about doing this when the anti-malware programs are not already installed on the infected computer? I don't want to risk connecting it to my network or use a USB thumb drive that might get infected.
Am I being a little too paranoid or is there a way that I can protect my USB drive from any auto run worms that could infect it?
 
if you're that paranoid about it the only way you're going to feel better about it is to reformat it...

also malwarebytes installs in safe mode... usually just do that... via network
 
If it is infected, the registry permissions are probably also royally screwed on it as well.

You may be able to get it clean, but certain stuff may not work properly anymore.

Dr.Web has a free standalone scanner that you don't have to install. They update it pretty much every day.
 
I have a clean system I throw the drive in and do the cleaning from there.

I've never had an issue, but I'm careful about it.
 
Protect your USB drive? WTF?

Unless you store your own data on the USB drive, you should be formatting it after the clean. If you don't have an extra USB drive, buy a $5-10 thumb drive from any Walmart and transfer the incredibly small malware removal tools that way.

Load antimalware tools onto the USB drive, get them on his computer, format drive afterwards. The end. Either that or just download the tools onto his machine from his house or wherever he normally connects it (if you can get it booted, of course, and in Safe Mode preferably).

I've been cleaning systems for about 10 years and have not encountered a worm sophisticated enough to infect the removable media I use for transferring files to the target machine (though many bootloaders have disabled them -_-). If you're really that worried about infecting your other systems, then like someone else said before, do a clean wipe on the HDD ==> reinstall OS after backing up any irreplaceable data and move on.
 
Last edited:
I have a clean system I throw the drive in and do the cleaning from there.

I've never had an issue, but I'm careful about it.

That is what I have done in the past as well but after taking a class on network security in college they made me a bit more paranoid about worms. I am going got try out the USB immunizer from bitdefender.
 
Unplug it from any network... Wipe the hdd.... Nuke the site from orbit... Reinstall... Run antimalware programs.

If you're confident it is infected, it may have rootkits that might survive a simple hdd wipe.
 
Unplug it from any network... Wipe the hdd.... Nuke the site from orbit... Reinstall... Run antimalware programs.

If you're confident it is infected, it may have rootkits that might survive a simple hdd wipe.

Anything's possible, but if you're seriously that worried about survival after cleanwipe (3+ passes unless small size or SSD, otherwise takes far too long) then replacing the hardware would cost less than the time and work involved in cleaning the original HDD.
 
I'm not that worried, just curious about how to safely get the required programs on his computer without infecting my stuff.
 
That is what I have done in the past as well but after taking a class on network security in college they made me a bit more paranoid about worms. I am going got try out the USB immunizer from bitdefender.
I wouldn't worry too much about it, honestly. Just don't go running apps off of the suspect drive, you should be fine.

I started doing this because a lot of the malware out there was blocking the installation and execution of things like malware bytes and the popular online scanners. So I'd try to install something, and the malware would corrupt the installation before I could run the program. In some cases, it would corrupt the installation so badly that I couldn't uninstall it, or reinstall it after manually uninstalling it.

So now a days, I just throw it in a host machine, grab an image, clean it, put it back in the main computer and test it out. Works for most of the malware issues I've come across.
 
There are several anti-virus tools that you can burn to a CD\DVD and use to boot the system, then scan the computer. You can also burn the install programs to a CD\DVD and install from the disk, and as long as the disk is finalized, there shouldn't be anyway for the infected PC to infect the disk. And if you're really paranoid about it, you can just trash the CD anyway (they're cheap).
 
bootable cd or usb drive, typically ubcd4win. Clean as much as possible there and rewrite a clean MBR (I've seen a few of those over the past year or 2, after going out of favor for a decade or more), then scan with hitman pro and tdsskiller when booted back into windows.
 
If its something particularly nasty:

I unplug the system from the network/internet.

Run IE and Java Cache script that cleans out all history and cache.
Run Autoruns... google it and try to figure out what it is.
Run malwarebytes
Run onboard AV in strongest mode.
Run Spybot Search and Destroy for its BHO and Active X manager
Run F-Secure online AV
Run Kasperksy offline scanner in strongest mode
Run Autoruns again.
Review details... google results

Use specialized tools if required. Combofix...etc...
 
If it is really infected you have a few things to look forward to:
Windows Update, as well as its supporting services may be missing entirely.
Antivirus software may not install at all, or have their download pages blocked by the malware.

If you encounter either of those symptoms you need to reformat entirely as the computer has a rootkit that has made itself a part of windows itself.

Anything else can usually be taken care of using the info in the post above mine.
 
I've had good luck with Tweaking Windows Repair All in One. http://www.tweaking.com/

After you clean the computer, run the tool. Its not 100% but it works for a lot of machines. Typical things to look out for are missing services, Windows Defender errors, website redirects, and unable to install new antivirus.
 
If it is really infected you have a few things to look forward to:
Windows Update, as well as its supporting services may be missing entirely.
Antivirus software may not install at all, or have their download pages blocked by the malware.

If you encounter either of those symptoms you need to reformat entirely as the computer has a rootkit that has made itself a part of windows itself.

Anything else can usually be taken care of using the info in the post above mine.

You don't have to reformat/reinstall, but it's generally easier to (and better to, imo), yes. If your buddy/customer doesn't need any data off of it, WIPE ==> REINSTALL I say. Saves you and him a helluva lot of worry and time.
 
Either run a LiveCD or boot the computer in Safe Mode with Networking which will usually keep you from being cross-contaminated across your network since the malicious apps shouldn't start up in safe mode.
 
Let me add.. it also depends on how dug in a user is into the machine. If it were a program manager... I can image their machine, install their software and move their profile in 2 hours.

If its a developer...well that's a 10-13 hour setup with around 40+ programs and piles of customization.


The four top key points are:

  • Don't open suspicious e-mail and attachments from people you don't know.
  • Leave your damn AV enabled. (Developers with local admin rights!!!)
  • Never disable UAC.
  • If you user IE, always run IE in protected mode.
 
Moreso than any of those is training necessary for the EU to identify potential phishing/malware sites. Many of the customers I've dealt with in the past two years have become victim to fake sites through Google search results and nothing else, a trend which has been on the rise for some time (and more successful for scammers than email, due to AV software being less aware of them and more concerned with email/old methods of infection).
 
Back
Top