Virus recovery tools & techniques

Most of us are not "computer people" so post your technical questions and comments here. If you have computer or Internet expertise, share it here.

Moderators: carlson1, Keith B

Post Reply

Topic author
45ACP
Junior Member
Posts in topic: 2
Posts: 43
Joined: Thu Aug 16, 2007 8:54 pm
Location: Austin
Contact:

Virus recovery tools & techniques

#1

Post by 45ACP »

I wrote this article to share what I learned as a result of having to deal with a computer virus recently. Basically, my familiarity with virus recovery tools and techniques has been forcibly upgraded.

It has been a long time, perhaps more than 5 years, since I have had to deal with a virus infestation in our household. We had been using Grisoft AVG Free for anti-virus, Javacool SpywareBlaster to prevent spyware, and Lavasoft Ad-Aware to detect and remove any spyware/adware that made it past SpywareBlaster. I was fanatical about keeping all of those programs updated, and this has worked very well for us.

However, this past Saturday it became apparent that my wife’s desktop computer had become infected with a browser hijacker. AVG antivirus has active website scanning enabled, so my wife had received a pop-up warning from the program that there was malware on a website she visited recently, but it appeared that the program had contained the threat.

Apparently it was one of the newer Trojans, and made it past our AVG antivirus software. Browser windows started popping up, pestering her with ads. This thing disabled Windows Update, reset her browser Privacy setting to Low (Allow All Cookies), disabled the updater for AVG antivirus and Ad-Aware, and made it impossible to reach desired websites – the browser was constantly redirecting. Experience and research further indicated that malware was being actively invited in on an ongoing basis and that a key logger might have been employed, necessitating a reset of all passwords.

I’m going to spare you all the details of the many steps I took, involving many hours over three plus days, to resolve the issue and fast forward to lessons learned and hopefully someone can benefit from this incident.

However, I assume no responsibility for your data or your computer security; this article is for informational purposes only, and you should do your own homework and come to your own conclusions. As always, you should back up your valuable data regularly. And should you become aware of a virus or malware infection on the source computer, scan all back-up data carefully before using in any way.

Lessons learned

- AVG Free did not prevent, detect, or remove this infection (seriously, no one’s perfect, and I imagine it must be hard to keep up with all the new viruses that are constantly coming out)
- Ad-Aware could not remove this infection
- Bitdefender and Kaspersky antivirus both get high reviews from a variety of sources, but I cannot recommend Kaspersky because it refused to install when it detected traces of the previously-installed AVG – Kaspersky would not work for me when I really needed it to, so I’ve gone with bitdefender, and I’m happy with it so far
- it’s better to be prepared than to have to scramble for a solution
- what removed the infection for me was a combination of Malwarebytes' Anti-Malware and Simply Super Software Trojan Remover
- keep your hard drive defragmented, and buy the fastest hard drives you can afford – having to scan your entire hard for viruses is a time-consuming process



Disaster recovery preparation

After a lot of trial and error, here’s the virus disaster recovery kit I came up with:

- a CD with the BartPE ISO burned onto it, and
- a USB thumb drive full of malware removal tools

Although it wasn’t useful for this purpose, I also recommend having a copy of Ultimate Boot CD laying around for computer emergencies: http://www.ultimatebootcd.com/

Bart's Preinstalled Environment (BartPE) bootable live windows CD/DVD: http://www.nu2.nu/pebuilder/

BartPE is a CD bootable environment that has some Windows functionality. Basically it allows you to bypass your infected hard drive and run Windows executable programs from the thumb drive. You will need your Windows install CD to create the ISO as it uses Windows system files.

Theoretically you could create plug-ins to include your favorite programs with the BartPE ISO, but I found this wasn’t as easy as it looked or sounded. Although there are a number of sites offering BartPE plug-ins for antivirus/antispyware, all the ones I found were so old as to be practically useless.

That doesn’t matter; the basic BartPE ISO is all you need to boot to an environment from CD that allows you to run the virus removal tools from the USB thumb drive. It’s easier to keep adding updated antivirus tools to a thumb drive anyway – download the latest one every month.

The moment you suspect your computer has become infected with a virus, worm, Trojan, or any other kind of malware you should unplug it from the network immediately. Pop in the BartPE CD, shut it down and leave it off for 30 seconds, plug in the USB thumb drive and restart it, making sure that the CD drive is ahead of the hard drive in the BIOS boot sequence.

Start by running these standalone programs – these do not require installation; they can run in BartPE from the thumb drive:

Trend Micro CWShredder: http://us.trendmicro.com/us/products/pe ... WShredder/
McAfee Avert Stinger: http://vil.nai.com/VIL/stinger/
avast! Virus Cleaner: http://www.avast.com/eng/avast-virus-cleaner.html
SmitFraudFix: http://siri.urz.free.fr/Fix/SmitfraudFix_En.php
Trend Micro Sysclean: http://www.trendmicro.com/download/dcs.asp (DOS executable)

If you know exactly which virus has infected your computer and if you have another computer you can use, you can go to one of these sites and download the specific removal tool for that virus:

Kaspersky Virus Removal Tools: http://www.kaspersky.com/removaltools
Symantec Virus Removal Tools: http://www.symantec.com/business/securi ... ltools.jsp

Once your computer is clean enough to restart in Safe Mode, you can install and run these programs:

bitdefender: http://www.bitdefender.com/ - excellent!
Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php - excellent!
Simply Super Software Trojan Remover: http://www.simplysup.com/ - excellent!

Here are some anti-virus reviews:

http://antivirus-software.topchoicereviews.com/
http://www.pcworld.com/article/124475/t ... tware.html
http://www.malwarehelp.org/malware_remo ... nload.html
http://www.2009softwarereviews.com/Defa ... warereview
http://anti-virus-software-review.toptenreviews.com/

I hope this helps, and I welcome any feedback. Thanks!
NRA Certified Firearms Instructor: Pistol, Rifle, Shotgun, Personal Protection in the Home, Home Firearm Safety
NRA Certified Range Safety Officer
NRA & GOA Life Member

KBCraig
Banned
Posts in topic: 1
Posts: 5251
Joined: Fri May 06, 2005 3:32 am
Location: Texarkana

Re: Virus recovery tools & techniques

#2

Post by KBCraig »

45ACP wrote:Lessons learned...
Never use any operating system out of Redmond?
:biggrinjester:

Topic author
45ACP
Junior Member
Posts in topic: 2
Posts: 43
Joined: Thu Aug 16, 2007 8:54 pm
Location: Austin
Contact:

Re: Virus recovery tools & techniques

#3

Post by 45ACP »

Never use any operating system out of Redmond?
45ACP wrote:Lessons learned...
Never use any operating system out of Redmond?
:biggrinjester:
Wow, that didn't take long...

Yes, I know, I know, but that isn't always an easy or convenient option. My wife has enough projects on her plate without having do all the research and learning required to start all over with another OS.

Believe me, I _like_ the idea of switching to Linux, and I have at least half-a-dozen flavors of it that I play around with using Sun Virtual Box (it's free, easy to use, and awesome - check it out!), but the sad fact is I have a reasonably high level of proficiency with Windows, and I don't with LInux, so when I need to get something done NOW, guess what I'm going to use?

Plus all my games are written for Windows. A man's gotta have a hobby.
NRA Certified Firearms Instructor: Pistol, Rifle, Shotgun, Personal Protection in the Home, Home Firearm Safety
NRA Certified Range Safety Officer
NRA & GOA Life Member
User avatar

TexasComputerDude
Senior Member
Posts in topic: 4
Posts: 964
Joined: Thu May 01, 2008 4:47 pm
Location: Lufkin, TX
Contact:

Re: Virus recovery tools & techniques

#4

Post by TexasComputerDude »

lesson learned: always give proper training to anyone who touches your pc lol.
Glock 30 - main ccw
User avatar

Excaliber
Moderator
Posts in topic: 2
Posts: 6198
Joined: Tue May 27, 2008 9:59 pm
Location: DFW Metro

Re: Virus recovery tools & techniques

#5

Post by Excaliber »

Another option:

Make monthly full drive backup images, which take only a few minutes to create.

I keep the system and programs on one drive, and data on another so I can back up and restore them separately.

If all else fails, restore the latest image and lose only a few weeks of data at most. In my experience, this is usually affordable and beats spending 3 days or so hacking at the thing and hoping to get it back to normal.
Excaliber

"An unarmed man can only flee from evil, and evil is not overcome by fleeing from it." - Jeff Cooper
I am not a lawyer. Nothing in any of my posts should be construed as legal or professional advice.
User avatar

TexasComputerDude
Senior Member
Posts in topic: 4
Posts: 964
Joined: Thu May 01, 2008 4:47 pm
Location: Lufkin, TX
Contact:

Re: Virus recovery tools & techniques

#6

Post by TexasComputerDude »

Excalibur is wise. and coincidentally my baby is named Excalibur (my laptop)
Glock 30 - main ccw
User avatar

TexasComputerDude
Senior Member
Posts in topic: 4
Posts: 964
Joined: Thu May 01, 2008 4:47 pm
Location: Lufkin, TX
Contact:

Re: Virus recovery tools & techniques

#7

Post by TexasComputerDude »

we got us a gaggle of computer nerds on this here gun forum. whoodaa thunk it.
Glock 30 - main ccw
User avatar

The Annoyed Man
Senior Member
Posts in topic: 1
Posts: 26852
Joined: Wed Jan 16, 2008 12:59 pm
Location: North Richland Hills, Texas
Contact:

Re: Virus recovery tools & techniques

#8

Post by The Annoyed Man »

My Macs both do a full backup to an external drive every hour.
“Hard times create strong men. Strong men create good times. Good times create weak men. And, weak men create hard times.”

― G. Michael Hopf, "Those Who Remain"

#TINVOWOOT
User avatar

Excaliber
Moderator
Posts in topic: 2
Posts: 6198
Joined: Tue May 27, 2008 9:59 pm
Location: DFW Metro

Re: Virus recovery tools & techniques

#9

Post by Excaliber »

TexasComputerDude wrote:Excalibur is wise. and coincidentally my baby is named Excalibur (my laptop)
I'm honored! ;-)
Excaliber

"An unarmed man can only flee from evil, and evil is not overcome by fleeing from it." - Jeff Cooper
I am not a lawyer. Nothing in any of my posts should be construed as legal or professional advice.
User avatar

TexasComputerDude
Senior Member
Posts in topic: 4
Posts: 964
Joined: Thu May 01, 2008 4:47 pm
Location: Lufkin, TX
Contact:

Re: Virus recovery tools & techniques

#10

Post by TexasComputerDude »

The Annoyed Man wrote:My Macs both do a full backup to an external drive every hour.
lol isn't that a little extreme? or do you do like corporate work or something lol. sarcasm tag?
Glock 30 - main ccw
User avatar

boomerang
Senior Member
Posts in topic: 1
Posts: 2629
Joined: Thu Sep 13, 2007 11:06 pm
Contact:

Re: Virus recovery tools & techniques

#11

Post by boomerang »

I heard about the hard drive failures in Apple laptops but I didn't know it was that bad. :shock:
"Ees gun! Ees not safe!"
Post Reply

Return to “Technical Tips, Questions & Discussions (Computers & Internet)”