Windows Vista Forums
Vista Forums Home Join Vista Forums Windows 7 Forum Vista Tutorials Tags
Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks.

Go Back   Vista Forums > Vista Forums > System Security

Vista - Virus Removal Techniques

Reply
 
Old 03-29-2009   #1 (permalink)


Windows Server 2008, Windows Vista Enterprise, Windows 7 Ultimate (all x64)
 
 

Virus Removal Techniques

During my days working as an in-store PC tech at Circuit City, these were techniques I developed for cleaning heavily infected computers.
This is what I did if the client's computer won't boot, freezes during startup, or constantly crashes.
1. Remove hard drive and connect it to a clean, anti-virus protected computer.
a. Run a virus scan on infected drive
b. Physically delete known virus files/folders
c. Run a checkdsk to correct any file system errors, which was done though command prompt> chkdsk /r
2. Reinstall hard drive in client computer
a. Boot computer into safe mode
b. Used CCleaner & MSCONFIG to disable any viruses/malware from starting during boot
c. Run an antispyware program such as AdAware or Spysweeper (run portably through flash drive)
d. Scan for viruses with client's AV program, if present
3. Reboot client computer normally
a. Run CCLeaner to delete temporary files, cookies, etc
b. Defrag client's computer, I used Auslogics Disk Defragmenter (on flash drive)
c. Check for internet connectivity then update client's AV program, if it hadn't already.
d. Scan for viruses with client's AV program to ensure computer is cleaned

And if all failed, or the OS was damaged too much, then we reinstalled/recovered the OS


Last edited by merkat106; 03-29-2009 at 03:02 AM.. Reason: add
My System SpecsSystem Spec
Old 03-29-2009   #2 (permalink)


Windows 7 RTM 64-bit
 
 

Re: Virus Removal Techniques

Awesome ..
My System SpecsSystem Spec
Old 05-13-2009   #3 (permalink)


Vista Ultimate X64 SP2
 
 

Re: Virus Removal Techniques

Quote  Quote: Originally Posted by merkat106 View Post
During my days working as an in-store PC tech at Circuit City, these were techniques I developed for cleaning heavily infected computers.
This is what I did if the client's computer won't boot, freezes during startup, or constantly crashes.
1. Remove hard drive and connect it to a clean, anti-virus protected computer.
a. Run a virus scan on infected drive
b. Physically delete known virus files/folders
c. Run a checkdsk to correct any file system errors, which was done though command prompt> chkdsk /r
2. Reinstall hard drive in client computer
a. Boot computer into safe mode
b. Used CCleaner & MSCONFIG to disable any viruses/malware from starting during boot
c. Run an antispyware program such as AdAware or Spysweeper (run portably through flash drive)
d. Scan for viruses with client's AV program, if present
3. Reboot client computer normally
a. Run CCLeaner to delete temporary files, cookies, etc
b. Defrag client's computer, I used Auslogics Disk Defragmenter (on flash drive)
c. Check for internet connectivity then update client's AV program, if it hadn't already.
d. Scan for viruses with client's AV program to ensure computer is cleaned

And if all failed, or the OS was damaged too much, then we reinstalled/recovered the OS
No system File integrity checks from within the RE enviroment?
sfc /scannow

There is a free diagnostic tool for Windows (sysInspector). its color coded, [green good/red bad]. Do not use HJT in x64 Windows as it is not compatable, and will result is "missing" file errors.

For antivirus/antispyware, I would use a 3-star certified product (most have free trials). Most "client" software is ineffective (i.e., that is why they are infected with malware. [Trend Micro/CyberDefender/Vipre/AVG for example]) Polymorphic malware usually requires a specialty scanner/cleaner like Malwarebytes once it is able to establish a foothold.
both spysweeper and ad-aware offer standard scanning and cleaning at best. I would Use Defender and NOD32 4 which is a 3-star Advanced++ in both Hueristic and On-Demand scanning, and is able to utilize a bootable recovery disk for cleaning, and set Defender to notify about running programs that make system changes as this will allow you to block the change, and prevent the program from running.
Using a reg cleaner on a system is not the best of ideas in dealing with malware, as most Malware will just re-install itself. Most reg cleaners/Optimizers cannot distinguish between legitimate and unwanted programs, and more often than not will cause Windows/program corruption necessitating a Windows re-install, but out of all, CCleaner will probably be the safer bet-as long as you know the function of the entries it wants to "clean', and use oversight. Deleting/blocking cookies, and deleting temp files can be done through the Control Panel setting.

Last edited by rive0108; 05-13-2009 at 04:08 PM..
My System SpecsSystem Spec
Old 05-22-2009   #4 (permalink)


Vista Home Basic 32bit
 
 

Re: Virus Removal Techniques

Quote  Quote: Originally Posted by merkat106 View Post
During my days working as an in-store PC tech at Circuit City, these were techniques I developed for cleaning heavily infected computers.
This is what I did if the client's computer won't boot, freezes during startup, or constantly crashes.
1. Remove hard drive and connect it to a clean, anti-virus protected computer.
a. Run a virus scan on infected drive
b. Physically delete known virus files/folders
c. Run a checkdsk to correct any file system errors, which was done though command prompt> chkdsk /r
2. Reinstall hard drive in client computer
a. Boot computer into safe mode
b. Used CCleaner & MSCONFIG to disable any viruses/malware from starting during boot
c. Run an antispyware program such as AdAware or Spysweeper (run portably through flash drive)
d. Scan for viruses with client's AV program, if present
3. Reboot client computer normally
a. Run CCLeaner to delete temporary files, cookies, etc
b. Defrag client's computer, I used Auslogics Disk Defragmenter (on flash drive)
c. Check for internet connectivity then update client's AV program, if it hadn't already.
d. Scan for viruses with client's AV program to ensure computer is cleaned

And if all failed, or the OS was damaged too much, then we reinstalled/recovered the OS
---where I bought this laptop, they sold me a 'reset-cd' also, and said that IT would reset my computer to its factory-new format 'if' I ever got a virus or whenever i just felt like resetting my pc to new again---so,is this not the easiest route for me, or anyone else?---
thank you for any info
peace
My System SpecsSystem Spec
Old 06-01-2009   #5 (permalink)


Windows Vista™ Home Premium
 
 

Re: Virus Removal Techniques

Hey Merkat106,
You should talk to Brink or dmex or any system administrator about writing a tutorial about this. I love the post, very helpful and interesting..
Just shoot them a quick email and ask them. I would love to see this in there. It would be very helpful....

Let me know,
Ben

Quote  Quote: Originally Posted by merkat106 View Post
During my days working as an in-store PC tech at Circuit City, these were techniques I developed for cleaning heavily infected computers.
This is what I did if the client's computer won't boot, freezes during startup, or constantly crashes.
1. Remove hard drive and connect it to a clean, anti-virus protected computer.
a. Run a virus scan on infected drive
b. Physically delete known virus files/folders
c. Run a checkdsk to correct any file system errors, which was done though command prompt> chkdsk /r
2. Reinstall hard drive in client computer
a. Boot computer into safe mode
b. Used CCleaner & MSCONFIG to disable any viruses/malware from starting during boot
c. Run an antispyware program such as AdAware or Spysweeper (run portably through flash drive)
d. Scan for viruses with client's AV program, if present
3. Reboot client computer normally
a. Run CCLeaner to delete temporary files, cookies, etc
b. Defrag client's computer, I used Auslogics Disk Defragmenter (on flash drive)
c. Check for internet connectivity then update client's AV program, if it hadn't already.
d. Scan for viruses with client's AV program to ensure computer is cleaned

And if all failed, or the OS was damaged too much, then we reinstalled/recovered the OS
My System SpecsSystem Spec
Reply

Thread Tools


Similar Threads
Thread Forum
Kaspersky® Virus Removal Tool System Security
trojan virus removal help? System Security
Virus Removal 2008 Spyware .NET General
Problems since virus removal Vista performance & maintenance
removal of win32:trojan-gen. virus Vista security


Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46