Manual cleaning routines:
nowadays malware are more complicated and not all cleaning routines success perfectly and sometimes it dont work
at all,so when your pc got infected you should be patient,and cooperator with the people who want to help you so what
to do:
A.anti malware:
there are a plenty of good anti malware tools and cleaners like:
1.Malware byte anti malware:code name mbam is a good tool for detecting and cleaning malware"file infectors not
included"
2.Super anti spyware:another good tool for detecting and removing malwares,code name sas.it has an advantge over
mbam that it a separate “system and browser repairs”
3.Dr.web cure it!:my favourite tool for totally get rid of file infectors like sality,alman,…and other malwares.its
cleaning routines are so poweful,and its advantge over mbam and sas that it can handle viruses
after cleaning may some files of registry keys still in the system so you should repair them by system cleaners and
fixer
B.System cleaners:
1.ccleaner:a good freeware to clean junk files,registry errors.It has also a uninstaller"some or a lot of spyware has an
uninstall entry so removing by uninstaller is more easier"
2.dial a fix:good powerful tool for xp users can fix policies and had a good arsenal of fixes.
3.glary utilities:another good tool.and there is hunderds of freeware to do such mission.
may you have got a rootkit,so you should check for rootkits:
C.Anti rootkits:
1.avast! anti rootkit:simple anti rootkit,it has some false positives in registry,and system restore folder,any way we need
the log created by it not its removal"sorry alwil"
2.Panda anti rootkit:another simple UI anti rootkit"it is good but last time i run it i got an olly debug window tell me that
an Access violation occur,but dont worry my pc is a freak for anti malware"
3.Radix antirootkit:a very helpful tool generate a few FP and its clean is wonderful,it compains ease of use and power
of another advanced tools like GMER,or RKU.
4.GMER:advanced tool so use it to analyze the system then give the report to a professional then follow his guides"my
favorite anti rootkit"
5.RKU:another good analyzer but like gmer dont take decision if you dont know about what you do
6.rootkit revealer:good tool to analyze files and registry keys that hide from your eyes.
enogh anti rootkits
CAUTION:RUNNING MORE ONE ANTI ROOTKIT IN THE SAME TIME MAY CAUSE PROBLEMS INCLUDING
BSoDs
Manual analyzing cleaning
Sometimes YOU NEED to analyze the system and clean it by your self because the anti malware dont catch or cant
remove the malware"we are not going to teach you here how to analyze malware but will give you some basics so the
word"analyzing malware" is a big section and you should know you are going to learn THE BASICS,i.e:what you
need,like the mobile phone player it is good but the pc media player is better,but for the mobile a small media player is
so good,you know about what i am talking…i wish.
A.Processes managers:we will use it to know the malware processes and to kill it
1.procexp:the best task manager i had ever seen give you a very good image of what running with high lighting and it is
co-operate with his brother autoruns to catch malware"highlighting explore the packed processes running so you
should suspect it first"because the professional in making viruses protect their viruses by packing it"in the photo you
see hijack free is a packed process"packed with upx1.01 MB,after unpacking 2.75MB and it is programmed with
Borland Delphi"
2.APT"Advanced Process Termination":good in one thing killing process,you will use it to kill malware processes.
3.GMER:yep again we will use GMER but the processes section,expand tabs and go Processes,here is the magic
until now no one program stand against the termination of GMER,firewalls and anti viruses
like:comodo,avast,avira,outpost,eset,…so the malware will terminated for ever by GMER because it will not
contain a powerful self-defense as power as anti virus,so bye bye .
B.Overall system analyzer:it can give you an overall view of your system
1.Eset Sysinspector:ESET SysInspector is an application that thoroughly inspects your computer and displays
gathered data in a comprehensive way. Information like installed drivers and applications, network connections or
important registry entries can help you to investigate suspicious system behavior be it due to software or hardware
incompatibility or malware infection.////thats why they say"the geeks in robot man company eset",and i like to analyze its
log more than HJT.but you need to upload files to an uploading website since we cant upload zip files into the forum.
2.autoruns:the best tool in the world to determine the startups,and it can work with procexp.easy thing to work with it
after some tweaking:from options menu check"hide Microsoft and windows entries"then check "verify code
signatures",the unverified entries thet come from unknown publisher may be suspect and need to be investigated.we
will use autoruns to disable the malware start up entries after terminate it"so it not re-enable it self after terminating"
3.Hijack this:simple tool to do simple logs"really i hate them",and no updates for the current version and some malware
can now hide from it.
4.a2HijackFree:good tool give you an overall look for your processes,ports,autoruns,services,and some other places
where the malwares can hide.it has a good removal ability.
5.freeFixer:nice tool that polonus tell me about it"thanks polonus",work on it for some hours but it is good"even its GUI
not so good"
6.superhacker system analyzer:code name"NSA",I WIIL rename it to my love name after it done it still in developing
phase,scan for startups,then make a list of unverified entries,then scan HDD for files that has attribute of"hidden and
system"then compare the two lists,and give you a third list contain the file name ,its company,packed or not,and its
import/export table"it contain no resource sections since it drive me crazy to program it,any help welcome".i will
present it here in avast forum,it will be free software"free&open source"hey i use python for that,and i still in making
handler for registry reading and log saving.
C.files and registry removals:
1.unlocker:very good tool to delete malwares files sice it will remove it on the next start up if it dont remove now
2.FileASSASSIN:nice file deleter,it lack the riht click menu,so i prefer unlocker
3.RegASSASSIN:a tool to remove registry keys&values.
D.another tool&conclusion:
api guard a handy tool to run suspicious files without hurting your system"if your av dont catch a virus in a suspect file
you can run it from api guard"
My conclusion:anti malware nowadays are so good but always there are weak points so here those tools come,if you
have a problem with your infected pc make new topic and we will help you.if all fail i volunteer to make a remover for
your case by uploading the virus into upload website i will analyze it for you and make a cleaner"if there is no clenaer
available in the net,why?i am sure my program will be good but it will not be tested like the other tools and it will be
programmed in a windows xp,may you use vista or win 98".
a very big thanks from me to the best malware fighter i have ever seen “polonus”.
refrences:
www.freedrweb.com/cureit/?lng=en
www.malwarebytes.org/mbam.php
www.superantispyware.com/
www.ccleaner.com/
www.glaryutilities.com/
download.cnet.com/Panda-Anti-Rootkit/3000-8022_4-10717196.html
www.gmer.net/
technet.microsoft.com/en-us/…/bb897445.aspx
technet.microsoft.com/en-us/…/bb896653.aspx
www.diamondcs.com.au/advancedseries/apt.php
www.eset.com/download/sysinspector.php
technet.microsoft.com/en-us/…/bb963902.aspx
www.hijackfree.com/en/hijackfree/
www.freefixer.com/
ccollomb.free.fr/unlocker/
I PREFER GOOGLING
http://wiki.lunarsoft.net/wiki/PC_Security